<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cisco ASA FireWall</title>
	<atom:link href="http://ciscoasa.org.ua/feed/" rel="self" type="application/rss+xml" />
	<link>http://ciscoasa.org.ua</link>
	<description>Cisco ASA FireWall</description>
	<lastBuildDate>Mon, 15 Mar 2010 10:24:42 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Chapter 12: Case Studies</title>
		<link>http://ciscoasa.org.ua/2010/03/chapter-12-case-studies/</link>
		<comments>http://ciscoasa.org.ua/2010/03/chapter-12-case-studies/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 10:24:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[anomalies]]></category>
		<category><![CDATA[gaps]]></category>
		<category><![CDATA[incident response team]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[plug and play]]></category>
		<category><![CDATA[security incident]]></category>
		<category><![CDATA[security policy]]></category>

		<guid isPermaLink="false">http://ciscoasa.org.ua/?p=269</guid>
		<description><![CDATA[

Having Defense-in-Depth mechanisms and tools in place is important to any organization regardless of its size. This chapter includes three different case studies explaining how a small (Company-A), medium (Company-B), and large enterprise (Company-C) apply the best practices learned in all previous chapters. These case studies provide you with an in-depth and objective analysis of [...]]]></description>
			<content:encoded><![CDATA[<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:78.96pt;">
<div class=paragraph style=" padding:0.00pt 36.96pt 0.00pt 90.96pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Having Defense-in-Depth mechanisms and tools in place is important to any organization regardless of its size. This chapter includes three different case studies explaining how a small (Company-A), medium (Company-B), and large enterprise (Company-C) apply the best practices learned in all previous chapters. These case studies provide you with an in-depth and objective analysis of security technologies and techniques applied in different environments. The intent is to help you identify and implement practical security strategies that are both flexible and scalable.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:167.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 42.24pt; text-align:left;"><span class=font11><a href="#bookmark86"><b>Case Study of a Small Business</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 39.36pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This section uses Company-A as an example. Company-A is a small web development company based in Raleigh, North Carolina. Its office in Raleigh hosts 35 employees. The user population is composed of sales, marketing, finance personnel, and several web developers. Figure 12-1 illustrates the network architecture and topology of the Raleigh office of Company-A.</span></div>
<div class=paragraph style=" padding:6.24pt 37.44pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Raleigh office has a simple network architecture. Client workstations are connected to an access switch and then connected to the Cisco Adaptive Security Appliance (ASA) inside interface. The Cisco ASA outside interface connects directly to a router provided by the Internet service provider (ISP) of Company-A. The ISP completely manages this router; Company-A has no control over it. A third interface on the Cisco ASA hosts a demilitarized zone (DMZ) hosting several servers. These servers include web, e-mail, and FTP applications.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:177.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:84.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:311.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>342    </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.88pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-1 </b><span class=font43><i>Raleigh Office of Company-A</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 220.32pt 0.00pt 219.36pt; text-align:justify;"><span class=font31><i>Г </i><span class=font4>Internet </span><span class=font48 style=" letter-spacing:-0.50pt;">j</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.44pt; height:251.76pt; padding:0.00pt 62.64pt 0.00pt 61.92pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-159.jpg" alt="" style=" width:361.44pt; height:251.76pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:159.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Because this is a simple topology, all security policies are enforced in the Cisco ASA. The goal is to protect the internal and DMZ hosts from external threats, while allowing the following:</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 111.60pt; text-align:justify; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Client workstations must be able to access the web server at the DMZ (10.10.20.10) over HTTP and HTTPS. Clients should also be able to put and get files via FTP to the same server at 10.10.20.10.</span></div>
<div class=paragraph style=" padding:3.84pt 42.48pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Client workstations must be able to access the Internet over HTTP and HTTPS. No other protocol access is allowed to the Internet.</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Client workstations must be able to check their e-mail on the e-mail server at the</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 111.36pt; text-align:left;"><span class=font44>DMZ (10.10.20.20).</span></div>
<div class=paragraph style=" padding:5.04pt 38.16pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;The web server should be reachable from outside Internet clients over HTTP and HTTPS only. The Cisco ASA should do static Network Address Translation (NAT) for the web server to be reachable via a public IP address from the Internet.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:93.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>343</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:60.96pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 111.60pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The e-mail server should be able to receive e-mail from external hosts over the Simple Mail Transfer Protocol (SMTP). The Cisco ASA should do static NAT for the e-mail server to be reachable via a public IP address from the Internet.</span></div>
<div class=paragraph style=" padding:4.08pt 53.28pt 0.00pt 111.60pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The client workstations will be translated to the external public IP address of the Cisco ASA using Port Address Translation (PAT).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Raleigh Office Cisco ASA Configuration</b></span></div>
<div class=paragraph style=" padding:4.08pt 60.72pt 0.00pt 0.00pt; text-align:right;"><span class=font44>The following sections cover the steps necessary to complete the goals listed earlier.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:369.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring IP Addressing and Routing</span></div>
<div class=paragraph style=" padding:4.32pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">This section demonstrates how to configure the interfaces and default gateway on the Cisco ASA using the Adaptive Security Device Manager (ASDM). The following are the configuration steps:</span></div>
<div class=paragraph style=" padding:6.00pt 74.16pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 1   </b>Working with a new Cisco ASA installation, the administrator logs in via the command-line interface (CLI) and sets the management interface IP address (10.10.30.1) and other interface configuration with the following commands.</span></div>
<div class=paragraph style=" padding:5.04pt 163.92pt 0.00pt 133.44pt; text-align:left;"><span class=font23 style=" line-height:11.52pt;">Co-A-ASA1# configure terminal Co-A-ASA1(config)# interface Management0/0 Co-A-ASA1(config-if)# nameif management CoAASA1(configif)# security-level 80</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 133.44pt; text-align:left;"><span class=font23 style=" line-height:11.52pt;">CoAASA1(configif)# ip address 10.10.30.1 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 87.84pt 0.00pt 90.24pt; text-align:left;"><span class=font23 style=" line-height:11.52pt;">CoAASA1(configif)# no shutdown Co-A-ASA1(config-if)# exit Co-A-ASA1(config)# <span class=font44><b>Step 2  </b>The administrator enables ASDM access only from machines on the management network with the following commands:</span></span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 133.44pt; text-align:left;"><span class=font23>CoAASA1(config)# http server enable</span></div>
<div class=paragraph style=" padding:1.44pt 47.04pt 0.00pt 133.44pt; text-align:left;"><span class=font23 style=" line-height:12.00pt;">CoAASA1(config)# http 10.10.30.0 255.255.255.0 management CoAASA1(config)# asdm location 10.10.30.0 255.255.255.0 management</span></div>
<div class=paragraph style=" padding:0.96pt 72.96pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 3  </b>The next step is to configure the outside, inside, and DMZ interfaces. The administrator connects to the Cisco ASA via ASDM and clicks <b>Configuration &gt; Device Setup &gt; Interfaces, </b>as illustrated on Figure 12-2.</span></div>
<div class=paragraph style=" padding:6.00pt 80.16pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 4  </b>The administrator selects the <b>GigabitEthernet0/0 </b>interface and clicks the <b>Edit </b>button. The screen illustrated in Figure 12-3 is shown. The administrator enters the interface name <b>(outside), </b>the IP address configuration <b>(209.165.200.225), </b>subnet mask <b>(255.255.255.0), </b>and a</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">description for the outside interface.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:64.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>344   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 223.44pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-2 </b><span class=font43><i>Configuring the Cisco ASA Interfaces on ASDM</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:233.76pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-160.jpg" alt="" style=" width:336.96pt; height:233.76pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 281.28pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-3 </b><span class=font43><i>Outside Interface Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:275.52pt; height:252.48pt; padding:0.00pt 105.36pt 0.00pt 105.12pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-161.jpg" alt="" style=" width:275.52pt; height:252.48pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>345</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:53.28pt;">
<div class=paragraph style=" padding:0.00pt 78.00pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 5  </b>Similarly, the <b>GigabitEthernet0/1 </b>interface is configured as the inside interface, as shown in Figure 12-4. The security level for the inside interface is set to <b>100.</b></span></div>
<div class=paragraph style=" padding:9.36pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font44><b>Figure 12-4 </b><span class=font43><i>Inside Interface Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:275.52pt; height:252.00pt; padding:0.00pt 105.36pt 0.00pt 105.12pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-162.jpg" alt="" style=" width:275.52pt; height:252.00pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:110.88pt;">
<div class=paragraph style=" padding:0.00pt 72.96pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 6  </b>The <b>GigabitEthernet0/2 </b>interface is configured as the <b>dmz </b>interface, as shown in Figure 12-5. The security level of the <b>dmz </b>interface is set to <b>50.</b></span></div>
<div class=paragraph style=" padding:6.00pt 74.40pt 0.00pt 125.76pt; text-align:justify; text-indent:-35.52pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 7 </b>The next step is to configure the default route of the Cisco ASA to point to the ISP router <b>(209.165.200.226). </b>To configure the default route, navigate to <b>Configuration &gt; Device Setup &gt; Routing &gt; Static Routes </b>and click <b>Add. </b>The screen shown in Figure 12-6 is displayed. Choose the <b>outside </b>interface from the drop-down menu, and enter <b>0.0.0.0 </b>for the IP address and <b>0.0.0.0 </b>for the Mask. The Gateway IP is <b>209.165.200.226, </b>and the metric is <b>1. </b>Leave all the other options with their default value.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:134.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>346   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-5 </b><span class=font43><i>DMZ Interface Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:275.52pt; height:252.96pt; padding:0.00pt 105.36pt 0.00pt 105.12pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-163.jpg" alt="" style=" width:275.52pt; height:252.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 287.28pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-6 </b><span class=font43><i>Inside Interface Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.00pt; height:232.80pt; padding:0.00pt 75.12pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-164.jpg" alt="" style=" width:336.00pt; height:232.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>347</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:80.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring PAT on the Cisco ASA</span></div>
<div class=paragraph style=" padding:4.08pt 60.48pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The next step is to configure PAT for internal users to be able to communicate to the Internet. Complete the following steps to configure PAT on the Cisco ASA.</span></div>
<div class=paragraph style=" padding:5.76pt 75.84pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 1 </b>To configure PAT, go to <b>Configuration &gt; Firewall &gt; NAT Rules, </b>click <b>Add, </b>and choose <b>Add Dynamic NAT Rule </b>from the drop-down menu, as illustrated in Figure 12-7.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 268.80pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 12-7 </b><span class=font43><i>Configuring PAT for Internal Users</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.00pt; height:232.80pt; padding:0.00pt 75.12pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-165.jpg" alt="" style=" width:336.00pt; height:232.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:63.12pt;">
<div class=paragraph style=" padding:0.00pt 95.52pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 2  </b>The screen shown in Figure 12-8 is displayed. Under the <b>Original </b>section, choose the <b>inside </b>interface from the drop-down menu.</span></div>
<div class=paragraph style=" padding:6.24pt 74.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 3 </b>Expand the Source option to select the inside source address space. This is illustrated in Figure 12-9. Select the <b>inside network (10.10.10.0/24)</b></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44>and click <b>OK.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:152.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>348    </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 291.84pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-8 </b><span class=font43><i>Adding a Dynamic NAT Rule</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:286.08pt; height:197.76pt; padding:0.00pt 100.08pt 0.00pt 99.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-166.jpg" alt="" style=" width:286.08pt; height:197.76pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 323.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-9 </b><span class=font43><i>Selecting the Source</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:285.60pt; height:265.92pt; padding:0.00pt 100.08pt 0.00pt 100.32pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-167.jpg" alt="" style=" width:285.60pt; height:265.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:59.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>349</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:97.68pt;">
<div class=paragraph style=" padding:0.00pt 76.08pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 4  </b><span class=font44>Under the <b>Translated </b>section, click the <b>Manage </b>button to add a global address pool.</span></span></div>
<div class=paragraph style=" padding:6.00pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 5  </b><span class=font44>The screen shown in Figure 12-10 is displayed. Under the <b>IP Addresses to Add </b>section, click <b>Port Address Translation (PAT) using IP Address of the interface </b>and click the <b>Add </b>button to include it under the <b>Address pools, </b>as shown in Figure 12-10.</span></span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-10 </b><span class=font43><i>Configuring PAT to Use the Outside Interface Address</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:254.16pt; height:171.60pt; padding:0.00pt 116.16pt 0.00pt 115.68pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:254.16pt; height:171.60pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:157.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:96.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:157.92pt;">
<div class=block style=" width:157.92pt; height:12.72pt;">
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font0 style=" letter-spacing:-0.50pt;"><b>rf:</b><span style=" letter-spacing:0.00pt;"><b> </b></span><span class=font1 style=" letter-spacing:0.00pt;"><b>Add Global Address Pool</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:96.24pt;">
<div class=block style=" width:96.24pt; height:12.72pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 84.24pt; text-align:left;"><span class=font0 style=" letter-spacing:-0.50pt;"><b>E</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:157.92pt;">
<div class=block style=" width:157.92pt; height:30.72pt;">
<div class=paragraph style=" padding:5.04pt 111.12pt 0.00pt 6.72pt; text-align:left;"><span class=font0 style=" line-height:10.80pt;">Interface: | outside Pool ID: |l</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:96.24pt;">
<div class=block style=" width:96.24pt; height:30.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:157.92pt;">
<div class=block style=" width:157.92pt; height:38.88pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 11.76pt; text-align:left;"><span class=font0>IP Addresses to Add</span></div>
<div class=paragraph style=" padding:0.00pt 95.28pt 0.00pt 12.24pt; text-align:left;"><span class=font4 style=" line-height:10.32pt;">О <span class=font0>Range Starting IP Address: | Eoding IP Address: |</span></span></div>
</div>
</td>
<td class=cell rowspan="3" valign="top" style=" width:96.24pt;">
<div class=block style=" width:96.24pt; height:103.44pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font0>Addresses <span class=font38><i>Pud</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:157.92pt;">
<div class=block style=" width:157.92pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 17.52pt; text-align:left;"><span class=font0>Netmask (optiooal): <span class=font4>Q                             |         <sub>&gt;&gt;</sub> jj</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:157.92pt;">
<div class=block style=" width:157.92pt; height:56.64pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 12.24pt; text-align:left;"><span class=font4>О <span class=font0>Port Address Translation (PAT)                   |  ^ </span><span class=font3><b><i>о<sub>в</sub>\^<sub>в</sub></i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>j</span></div>
<div class=paragraph style=" padding:0.00pt 95.28pt 0.00pt 17.52pt; text-align:left;"><span class=font0 style=" line-height:10.80pt;">IP Address: Netmask (optional): |</span></div>
<div class=paragraph style=" padding:4.32pt 53.52pt 0.00pt 12.24pt; text-align:left;"><span class=font0 style=" line-height:6.24pt; letter-spacing:-0.50pt;"><b>л</b><span style=" letter-spacing:0.00pt;"><b> </b>Port Address Translation (PAT) using IP ^ Address of the Interface</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font4>I <span class=font0 style=" letter-spacing:-0.50pt;"><b>1</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:254.16pt;">
<div class=block style=" width:254.16pt; height:24.72pt;">
<div class=paragraph style=" padding:8.64pt 0.00pt 0.00pt 87.36pt; text-align:left;"><span class=font0>OK         <span style=" letter-spacing:-0.50pt;"><b>1</b></span><b>    </b>Cancel Help</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:157.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:96.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:99.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 6  </b><span class=font44>Click <b>OK </b>and apply your changes to the Cisco ASA.</span></span></div>
<div class=paragraph style=" padding:28.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring Static NAT for the DMZ Servers</span></div>
<div class=paragraph style=" padding:4.08pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The DMZ servers must be statically translated with a public IP address. Table 12-1 lists the IP address mapping of the DMZ servers.</span></div>
<div class=paragraph style=" padding:9.84pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font4><b>Table 12-1   </b><span class=font43><i>IP Address Mapping of DMZ Servers</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:362.16pt; height:58.08pt; padding:0.00pt 34.32pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:362.16pt; height:58.08pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:19.68pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font4><b>Server</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:19.68pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Inside IP Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:19.68pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Translated Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Web server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font43>10.10.20.10</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>209.165.200.227</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:19.44pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>E-mail server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:19.44pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font43>10.10.20.20</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:19.44pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>209.165.200.228</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:51.12pt;">
<div class=paragraph style=" padding:0.00pt 36.96pt 0.00pt 90.00pt; text-align:justify;"><span class=font44>Complete the following steps to configure static NAT for the DMZ web and e-mail servers.</span></div>
<div class=paragraph style=" padding:6.72pt 76.80pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 1   </b><span class=font44>Navigate to <b>Configuration &gt; Firewall &gt; NAT Rules, </b>click <b>Add, </b>and choose <b>Add Static NAT Rule </b>from the drop-down menu, as illustrated in Figure 12-11.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:59.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>350   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 299.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-11 </b><span class=font43><i>Adding a Static NAT Rule</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.00pt; height:233.28pt; padding:0.00pt 75.12pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-168.jpg" alt="" style=" width:336.00pt; height:233.28pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.64pt;">
<div class=paragraph style=" padding:0.00pt 74.40pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 2  </b><span class=font44>The screen shown in Figure 12-12 is displayed. First configure static NAT for the web server. Under the </span><b>Original </b><span class=font44>section, choose the </span><b>dmz </b><span class=font44>interface from the drop-down menu, and enter the web server physical IP address </span><b>(10.10.20.10) </b><span class=font44>as the source.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 299.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-12 </b><span class=font43><i>Adding a Static NAT Rule</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:184.32pt; height:199.20pt; padding:0.00pt 150.96pt 0.00pt 150.72pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-169.jpg" alt="" style=" width:184.32pt; height:199.20pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:43.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.68pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>351</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:86.88pt;">
<div class=paragraph style=" padding:0.00pt 87.12pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 3  </b>Under the <b>Translated </b>section, choose the <b>outside </b>interface from the drop-down menu.</span></div>
<div class=paragraph style=" padding:5.76pt 76.56pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 4  </b>Click the <b>Use IP address </b>option, and enter the public address to which the web server will be translated <b>(209.165.200.227).</b></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 5  </b>Click <b>OK.</b></span></div>
<div class=paragraph style=" padding:8.16pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 6  </b>Repeat the same procedure for the e-mail server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:100.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring Identity NAT for Inside Users</span></div>
<div class=paragraph style=" padding:3.84pt 61.68pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The inside users must be able to communicate with the DMZ servers. The goal is to configure identity NAT for inside users when communicating to the DMZ servers. Complete the following steps to configure identity NAT for inside users.</span></div>
<div class=paragraph style=" padding:5.52pt 90.96pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.24pt;"><b>Step 1   </b>Navigate to <b>Configuration &gt; Firewall &gt; NAT Rules, </b>click <b>Add, </b>as illustrated in Figure 12-13.</span></div>
<div class=paragraph style=" padding:8.88pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font44><b>Figure 12-13 </b><span class=font43><i>Configuring Identity NAT for the Inside Network on the DMZ</i></span></span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 76.32pt; text-align:left;"><span class=font46><i>a</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.00pt; height:233.28pt; padding:0.00pt 75.12pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-170.jpg" alt="" style=" width:336.00pt; height:233.28pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.88pt;">
<div class=paragraph style=" padding:0.00pt 78.24pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 2  </b>Under the <b>Original </b>section, choose the <b>inside </b>interface from the dropdown menu, and the inside network as the source <b>(10.10.10.0/24).</b></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><b>Step 3  </b>Under the Translated section, choose the <b>dmz </b>interface from the</span></div>
<div class=paragraph style=" padding:0.00pt 74.64pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">drop-down menu, and select the same inside network <b>(10.10.10.0/24) </b>as the translated IP address, as shown in Figure 12-13.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>352   </b><span class=font4>Chapter 12: Case Studies</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 4 </b>Click <b>OK.</b></span></div>
<div class=paragraph style=" padding:7.92pt 211.92pt 0.00pt 90.24pt; text-align:justify;"><span class=font44><b>Step 5  </b>Apply the changes to the Cisco ASA.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:25.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:165.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Controlling Access</span></div>
<div class=paragraph style=" padding:4.08pt 43.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Next, you need to configure policies on the Cisco ASA to control access and achieve the following goals.</span></div>
<div class=paragraph style=" padding:6.24pt 38.64pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;The web server should be reachable from outside Internet clients over the HTTP and HTTPS protocols only.</span></div>
<div class=paragraph style=" padding:4.08pt 38.40pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;The e-mail server should be able to receive e-mail from external hosts over the SMTP only.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>Complete the following steps to configure access rules on the Cisco ASA.</span></div>
<div class=paragraph style=" padding:6.48pt 83.04pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font44 style=" line-height:12.24pt;"><b>Step 1   </b>Navigate to <b>Configuration &gt; Firewall &gt; Access Rules, </b>click <b>Add. </b>In Figure 12-14 the Access Rule configuration is displayed.</span></div>
<div class=paragraph style=" padding:8.64pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font44><b>Figure 12-14 </b><span class=font43><i>Configuring Access Rules</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.48pt; height:232.80pt; padding:0.00pt 74.64pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-171.jpg" alt="" style=" width:336.48pt; height:232.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.88pt;">
<div class=paragraph style=" padding:0.00pt 74.16pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 2 </b>First, the access rule to allow Internet users to reach the web server at the DMZ is configured. Under <b>Action, </b>click <b>Permit.</b></span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 3  </b>Under source, select <b>any.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:60.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>353</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:116.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 4 </b>Under destination, enter the IP address of the web server</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 125.76pt; text-align:left;"><span class=font44><b>209.165.200.227.</b></span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 5  </b>Select HTTP <b>(TCP/HTTP) </b>under the service.</span></div>
<div class=paragraph style=" padding:7.20pt 74.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 6  </b>Optionally, you can enter a description for this access rule, as illustrated in Figure 12-14.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 7 </b>Click <b>OK.</b></span></div>
<div class=paragraph style=" padding:6.96pt 74.40pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 8  </b>Repeat the same steps to allow HTTPS (TCP port 443) access to the web server and SMTP (TCP port 25) access to the e-mail server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:86.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Cisco ASA Antispoofing Configuration</span></div>
<div class=paragraph style=" padding:3.84pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Company-A security administrator wants to protect the infrastructure from spoofed sources. The administrator enables Unicast Reverse Path Forwarding (Unicast RPF) to protect against IP spoofing attacks by ensuring that all packets have a source IP address that matches the correct source interface according to the routing table. To enable Unicast RPF, navigate to <b>Configuration &gt; Firewall &gt; Advanced &gt; Anti-spoofing. </b>Select the desired interface, and click <b>Enable, </b>as illustrated in Figure 12-15.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 299.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 12-15 </b><span class=font43><i>Configuring Unicast RPF</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.00pt; height:264.96pt; padding:0.00pt 75.12pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-172.jpg" alt="" style=" width:336.00pt; height:264.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:52.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:122.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:363.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>354   </b><span class=font4>Chapter 12: Case Studies</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.92pt;">
<div class=paragraph style=" padding:0.00pt 305.04pt 0.00pt 35.76pt; text-align:justify;"><span class=font6>Blocking Instant Messaging</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:188.88pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The security administrator is now tasked by his management to come up with a solution to prevent internal users from using Yahoo! and MSN instant messaging (IM) programs. The solution is to configure the Cisco ASA to block this traffic and log it. The security administrator completes the following steps to achieve this goal.</span></div>
<div class=paragraph style=" padding:6.24pt 74.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 1   </b>The first step is to configure an inspect map on the Cisco ASA. To do this, navigate to <b>Configuration &gt; Firewall &gt; Objects &gt; Inspect Maps &gt; Instant Messaging (IM).</b></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 2 </b>Click<b>Add.</b></span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 3  </b>The <b>Add Instant Messaging (IM) Inspect </b>screen is displayed.</span></div>
<div class=paragraph style=" padding:6.48pt 98.16pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.24pt;"><b>Step 4 </b>Enter a name and an optional description for the new inspect map configuration. In this example, the inspect map name is <b>IM.</b></span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 5  </b>Click <b>Add </b>to add a new inspection criterion.</span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 6  </b>The screen is shown in Figure 12-16 is displayed.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:122.88pt;">
<div class=block style=" width:122.88pt; height:10.08pt;">
<div class=paragraph style=" padding:0.00pt 3.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 12-16 </b><span class=font43><i>Adding</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:363.12pt;">
<div class=block style=" width:363.12pt; height:10.08pt;">
<div class=paragraph style=" padding:0.00pt 239.04pt 0.00pt 0.00pt; text-align:justify;"><span class=font43><i>an Instant Messaging Inspect Map</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:160.32pt; height:196.32pt; padding:0.00pt 162.96pt 0.00pt 162.72pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-173.jpg" alt="" style=" width:160.32pt; height:196.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:122.88pt;">
<div class=block style=" width:122.88pt; height:11.52pt;">
<div class=paragraph style=" padding:1.20pt 6.48pt 0.00pt 90.24pt; text-align:justify;"><span class=font44><b>Step 7</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:363.12pt;">
<div class=block style=" width:363.12pt; height:11.52pt;">
<div class=paragraph style=" padding:0.00pt 183.12pt 0.00pt 2.88pt; text-align:justify;"><span class=font44>Under <b>Match Criteria, </b>click <b>Single Match.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:122.88pt;">
<div class=block style=" width:122.88pt; height:11.52pt;">
<div class=paragraph style=" padding:1.20pt 6.48pt 0.00pt 90.24pt; text-align:justify;"><span class=font44><b>Step 8</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:363.12pt;">
<div class=block style=" width:363.12pt; height:11.52pt;">
<div class=paragraph style=" padding:0.00pt 225.36pt 0.00pt 2.88pt; text-align:justify;"><span class=font44>Under <b>Match Type, </b>click <b>Match.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:122.88pt;">
<div class=block style=" width:122.88pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 6.48pt 0.00pt 90.24pt; text-align:justify;"><span class=font44><b>Step 9</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:363.12pt;">
<div class=block style=" width:363.12pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 224.88pt 0.00pt 2.88pt; text-align:justify;"><span class=font44>Under <b>Criterion, </b>select <b>Protocol.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph style=" padding:0.00pt 95.76pt 0.00pt 90.24pt; text-align:justify;"><span class=font44><b>Step 10 </b>Check both protocols <b>(Yahoo! Messenger </b>and <b>MSN Messenger).</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:67.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:122.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:363.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:384.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:101.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>355</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:103.68pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 11 </b>Under the <b>Actions </b>sections, leave the default of <b>Drop Connection and</b></span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 125.76pt; text-align:left;"><span class=font44><b>Log </b>enabled.</span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 12 </b>Click <b>OK.</b></span></div>
<div class=paragraph style=" padding:6.96pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 13 </b>Navigate to <b>Configuration &gt; Firewall &gt; Service Policy Rules </b>and click <b>Add. </b>The first screen of the Configuration Wizard is displayed, as illustrated in Figure 12-17.</span></div>
<div class=paragraph style=" padding:9.12pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font44><b>Figure 12-17 </b><span class=font43><i>Adding a New Service Policy Rule</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:384.96pt;">
<div class=block style=" width:310.08pt; height:233.28pt; padding:0.00pt 0.00pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-174.jpg" alt="" style=" width:336.48pt; height:233.28pt;"></div>
</td>
<td class=cell valign="top" style=" width:101.04pt;">
<div class=block style=" width:101.04pt; height:233.28pt;">
<div class=paragraph style=" padding:14.88pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font45>16</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:110.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 14 </b>In this example, the service policy will be applied only to the inside</span></div>
<div class=paragraph style=" padding:0.72pt 74.88pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">interface. To do this, click <b>Interface </b>under the <b>Create a Service Policy and Apply To </b>section.</span></div>
<div class=paragraph style=" padding:6.24pt 123.12pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 15 </b>Select the <b>inside </b>interface, and enter a name, as shown in Figure 12-17.</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 16 </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:6.96pt 87.60pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 17 </b>The <b>Traffic Classification Criteria </b>screen is displayed, as shown in Figure 12-18. Click <b>Use class-default as the traffic class.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph style=" padding:0.00pt 314.40pt 0.00pt 90.24pt; text-align:justify;"><span class=font44><b>Step 18 </b>Click <b>Next.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:87.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:384.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:101.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>356    </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 259.44pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-18 </b><span class=font43><i>Traffic Classification Criteria Screen</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:304.80pt; height:234.24pt; padding:0.00pt 90.48pt 0.00pt 90.72pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-175.jpg" alt="" style=" width:304.80pt; height:234.24pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.28pt;">
<div class=paragraph style=" padding:0.00pt 100.08pt 0.00pt 36.48pt; text-align:left; text-indent:53.76pt;"><span class=font4 style=" line-height:20.40pt;"><b>Step 19 </b><span class=font44>The </span><b>Rule Actions </b><span class=font44>screen is shown, as illustrated in Figure 12-19. </span><b>Figure 12-19 </b><span class=font43><i>Rule Actions Screen</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:302.40pt; height:231.84pt; padding:0.00pt 91.92pt 0.00pt 91.68pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-176.jpg" alt="" style=" width:302.40pt; height:231.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:43.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>357</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:517.44pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:18.00pt;"><b>Step 20 </b>Under the Protocol Inspection tab, check <b>IM </b>and click <b>Configure.</b></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:18.00pt;"><b>Step 21 </b>Select the previously configured inspection map <b>(IM).</b></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:18.00pt;"><b>Step 22 </b>Click <b>OK </b>on the <b>Select IM Inspect Map </b>screen.</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:18.00pt;"><b>Step 23 </b>Click <b>Finish </b>to end the wizard.</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:18.00pt;"><b>Step 24 </b>Apply the configuration to the Cisco ASA.</span></div>
<div class=paragraph style=" padding:1.20pt 108.48pt 0.00pt 36.24pt; text-align:left; text-indent:53.52pt;"><span class=font44 style=" line-height:15.36pt;">Example 12-1 shows the Cisco ASA CLI configuration for Company-A. <span class=font3><b>Example 12-1   </b></span><span class=font43><i>CLI Configuration of the Cisco ASA at the Raleigh Office</i></span></span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:15.36pt;">Co-A-ASA1# show running-config</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>: Saved</span></div>
<div class=paragraph style=" padding:11.04pt 314.16pt 0.00pt 98.16pt; text-align:left; text-indent:-1.68pt;"><span class=font23 style=" line-height:8.40pt;">ASA Version 8.0(1) !</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">hostname Co-A-ASA1</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">enable password 8Ry2YjIyt7RRXU24 encrypted</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">names</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 253.44pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!outside interface configuration interface GigabitEthernet0/0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">description outside interface connected to the Internet</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">nameif outside</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">security-level 0</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 209.165.200.225 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 257.52pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!inside interface configuration interface GigabitEthernet0/1</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">description inside interface connected to corporate network</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">nameif inside</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">security-level 100</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 10.10.10.1 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 270.24pt 0.00pt 97.20pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">!dmz interface configuration interface GigabitEthernet0/2</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">description dmz interface where web, email, and FTP servers reside</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">nameif dmz</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">security-level 50</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 10.10.20.1 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 270.24pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">interface GigabitEthernet0/3 shutdown no nameif no security-level no ip address</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 240.24pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!management interface configuration interface Management0/0</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">nameif management</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">security-level 80</span></div>
<div class=paragraph style=" padding:1.68pt 38.64pt 0.00pt 0.00pt; text-align:right;"><span class=font43><i>continues</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:58.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>358   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:518.40pt;">
<div class=paragraph style=" padding:0.00pt 140.64pt 0.00pt 101.52pt; text-align:left; text-indent:-65.28pt;"><span class=font3 style=" line-height:15.36pt;"><b>Example 12-1   </b><span class=font43><i>CLI Configuration of the Cisco ASA at the Raleigh Office (Continued) </i></span><span class=font23>ip address 10.10.30.1 255.255.255.0</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">!ACL controlling access to the web and e-mail server</span></div>
<div class=paragraph style=" padding:0.24pt 38.40pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">access-list outside_access_in extended permit tcp any host 209.165.200.228 eq smtp access-list outside_access_in_ remark Allowing HTTP to the webserver access-list outside_access_in_ extended permit tcp any host 209.165.200.227 eq www access-list outside_access_in_ remark Allowing HTTPS to the webserver access-list outside_access_in_ extended permit tcp any host 209.165.200.227 eq https access-list outside_access_in_ remark Allowing SMTP to the email server access-list outside_access_in_1 extended permit tcp any host 209.165.200.228 eq smtp <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">pager lines 24</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">mtu outside 1500</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">mtu inside 1500</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">mtu dmz 1500</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">mtu management 1500</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!Unicast RPF Configuration</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip verify reverse-path interface outside</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip verify reverse-path interface inside</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip verify reverse-path interface dmz</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">no failover</span></div>
<div class=paragraph style=" padding:0.24pt 211.44pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">icmp unreachable rate-limit 1 burst-size 1 no asdm history enable arp timeout 14400 <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.68pt 240.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!PAT Configuration for inside users nat-control</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">global (outside) 1 interface</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">nat (inside) 1 10.10.10.0 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 98.40pt; text-align:left;"><span class=font23 style=" line-height:9.12pt;">'Static NAT configuration for web and e-mail servers</span></div>
<div class=paragraph style=" padding:0.72pt 81.60pt 0.00pt 97.20pt; text-align:justify;"><span class=font23 style=" line-height:9.12pt;">static (dmz,outside) 209.165.200.227 10.10.20.10 netmask 255.255.255.255 static (dmz,outside) 209.165.200.228 10.10.20.20 netmask 255.255.255.255 <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 115.92pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.88pt;">'Static identity NAT configuration for inside network at the DMZ static (inside,dmz) 10.10.10.0 10.10.10.0 netmask 255.255.255.0 <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 163.20pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!ACL is applied to the outside interface access-group outside_access_in_1 in interface outside route outside 0.0.0.0 0.0.0.0 209.165.200.226 1</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">timeout xlate 3:00:00</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">timeout uauth 0:05:00 absolute</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dynamic-access-policy-record DfltAccessPolicy</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">http server enable</span></div>
<div class=paragraph style=" padding:0.24pt 219.12pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">http 10.10.30.0 255.255.255.0 management no snmp-server location no snmp-server contact</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>359</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:508.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-1   </b><span class=font43><i>CLI Configuration of the Cisco ASA at the Raleigh Office (Continued)</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 90.48pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">snmp-server enable traps snmp authentication linkup linkdown coldstart no crypto isakmp nat-traversal telnet timeout 5</span></div>
<div class=paragraph style=" padding:0.24pt 223.44pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">ssh 10.10.30.0 255.255.255.0 management ssh timeout 5 console timeout 0 threat-detection basic-threat threat-detection statistics access-list <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.68pt 248.88pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">class-map inspection_default match default-inspection-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 387.12pt 0.00pt 98.16pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;"><sub>! !</sub></span></div>
<div class=paragraph style=" padding:1.68pt 210.24pt 0.00pt 101.28pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">policy-map type inspect dns preset_dns_map parameters message-length maximum 512</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 219.12pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">'policy map to block Yahoo! and MSN IM. policy-map type inspect im IM description Blocking Instant Messanging parameters</span></div>
<div class=paragraph style=" padding:0.24pt 257.52pt 0.00pt 101.28pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">match protocol msn-im yahoo-im drop-connection log policy-map global_policy class inspection_default inspect dns preset_dns_map inspect ftp inspect h323 h225 inspect h323 ras inspect netbios inspect rsh inspect rtsp inspect skinny inspect esmtp inspect sqlnet inspect sunrpc inspect tftp inspect sip inspect xdmcp</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>!</span></div>
<div class=paragraph style=" padding:2.16pt 150.24pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">'Service policy map to block IM policy-map inside-policy description Service Policy to block IM for Inside Users class class-default inspect im IM</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>!</span></div>
<div class=paragraph style=" padding:1.92pt 240.24pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:9.84pt;">'global service policy service-policy global_policy global</span></div>
<div class=paragraph style=" padding:9.60pt 137.52pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">'service policy for IM applied to the inside interface only service-policy inside-policy interface inside</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:67.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>360    </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font8><b>Atlanta Office Cisco IOS Configuration</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Company-A opened a small branch office in Atlanta, Georgia. This new office has only 4 salesmen and 12 web developers. The Atlanta office network topology is simple. A Cisco IOS Software router with the IOS Firewall features set is configured to protect the internal network. This is illustrated in Figure 12-20.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-20 </b><span class=font43><i>Atlanta Office Network Topology</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:46.56pt; height:32.64pt; padding:0.00pt 220.08pt 0.00pt 219.36pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-177.jpg" alt="" style=" width:46.56pt; height:32.64pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.44pt; height:234.48pt; padding:0.00pt 62.64pt 0.00pt 61.92pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-178.jpg" alt="" style=" width:361.44pt; height:234.48pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.40pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The router has only two interfaces enabled. The inside interface resides on the 10.100.10.0/ 24 network, and the outside interface faces the Internet.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:74.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font6>Locking Down the Cisco IOS Router</span></div>
<div class=paragraph style=" padding:4.32pt 39.36pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The security administrator at Company-A must configure the router appropriately to increase the security of the Atlanta office network. The administrator uses the Security Device Manager (SDM) to configure the router and perform a security audit. Using SDM, the administrator can configure the router quickly using the best practices recommended in Chapter 2, &quot;Preparation Phase.&quot;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:61.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:383.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:102.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>361</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:137.04pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">You can complete the following steps to perform a security audit and fix any discrepancies found on the Cisco IOS router.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 1   </b>Log in to the Cisco IOS router using SDM.</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><b>Step 2  </b>Navigate to <b>Configure &gt; Security Audit, </b>and click the <b>Perform security</b></span></div>
<div class=paragraph style=" padding:0.24pt 76.56pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><b>audit </b>button, as illustrated in Figure 12-21. Alternatively, you can perform a one-step lockdown to configure default recommendations by clicking the <b>One-step lockdown </b>button. In this example, the step-by-step option is selected, which allows you to customize your configuration.</span></div>
<div class=paragraph style=" padding:9.36pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font44><b>Figure 12-21 </b><span class=font43><i>Performing a Security Audit with SDM</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:383.28pt;">
<div class=block style=" width:308.40pt; height:265.44pt; padding:0.00pt 0.00pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-179.jpg" alt="" style=" width:336.00pt; height:265.44pt;"></div>
</td>
<td class=cell valign="top" style=" width:102.72pt;">
<div class=block style=" width:102.72pt; height:265.44pt;">
<div class=paragraph style=" padding:23.76pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font45>34</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:91.20pt;">
<div class=paragraph style=" padding:0.00pt 78.00pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 3  </b>The <b>Security Audit Wizard </b>welcome screen shown in Figure 12-22 is displayed.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 4  </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><b>Step 5  </b>The Security Audit Interface Configuration screen shown in</span></div>
<div class=paragraph style=" padding:0.24pt 81.36pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Figure 12-23 is displayed. In this example, a Cisco 871 router is used. The outside interface is <b>FastEthernet4, </b>and the inside interface is <b>Vlan 1.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:60.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:383.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:102.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>362   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 253.68pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:36.48pt;"><b>Figure 12-22 </b><span class=font43><i>Security Audit Wizard Welcome Screen </i></span><b>Security Audit</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:312.48pt; height:242.40pt; padding:0.00pt 86.64pt 0.00pt 86.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-180.jpg" alt="" style=" width:312.48pt; height:242.40pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 200.40pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:36.48pt;"><b>Figure 12-23 </b><span class=font43><i>Security Audit Wizard Interface Configuration Screen </i></span><b>Security Audit</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:312.48pt; height:242.40pt; padding:0.00pt 86.64pt 0.00pt 86.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-181.jpg" alt="" style=" width:312.48pt; height:242.40pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:43.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:321.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>363</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:71.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 6  </b><span class=font44>Click </span><b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 74.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 7  </b><span class=font44>SDM performs the audit to make sure that the recommended settings are configured on the router. As illustrated in Figure 12-24, the router fails on numerous items.</span></span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-24 </b><span class=font43><i>Security Audit Wizard Interface Configuration Screen</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt;">
<div class=block style=" width:125.04pt; height:5.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:39.36pt;">
<div class=block style=" width:39.36pt; height:5.76pt;">
<div class=paragraph style=" text-align:justify;"><span class=font1><b>Security Audit</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:321.60pt;">
<div class=block style=" width:321.60pt; height:5.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.00pt;">
<div class=paragraph style=" padding:0.00pt 156.00pt 0.00pt 132.72pt; text-align:justify;"><span class=font1 style=" line-height:7.20pt;">Please wait while Security Audit checks if the recommended security settings are configured on the router.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:223.68pt; height:119.04pt; padding:0.00pt 134.40pt 0.00pt 127.92pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:223.68pt; height:119.04pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:153.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:10.08pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font1>No</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:10.08pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font1>Item Nama</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:10.08pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 12.24pt; text-align:left;"><span class=font1>Status</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.68pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font1>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.68pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Disable Finger Service</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.56pt; text-align:left;"><span class=font24 style=" letter-spacing:-1.00pt;"><b><i>*S </i></b><span class=font1 style=" letter-spacing:0.00pt;">Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font1>2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Disable PAD Service</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.56pt; text-align:left;"><span class=font24 style=" letter-spacing:-1.00pt;"><b><i>*S </i></b><span class=font1 style=" letter-spacing:0.00pt;">Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font39>a</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Disable TCP small servers Service</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.56pt; text-align:left;"><span class=font24 style=" letter-spacing:-1.00pt;"><b><i>*S </i></b><span class=font1 style=" letter-spacing:0.00pt;">Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font1>4</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Disable UDP small servers Service</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.56pt; text-align:left;"><span class=font24 style=" letter-spacing:-1.00pt;"><b><i>*S </i></b><span class=font1 style=" letter-spacing:0.00pt;">Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:6.96pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font1>5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:6.96pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Disable IP bootp server Service</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:6.96pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 11.52pt; text-align:left;"><span class=font39>X <span class=font1>Not Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.44pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font1>Б</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.44pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Disable CDP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.44pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 11.52pt; text-align:left;"><span class=font39>X <span class=font1>Not Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.20pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font1>7</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Disable IP source mute</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 11.52pt; text-align:left;"><span class=font39>X <span class=font1>Not Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font1>8</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Enable Password encryption Service</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 11.52pt; text-align:left;"><span class=font39>X <span class=font1>Not Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.44pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font1>S</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.44pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Enable TCP Keepalives for inbound telnet sessions</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.44pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 11.52pt; text-align:left;"><span class=font39>X <span class=font1>Not Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font1>1D</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.20pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Enable TCP Keepalives for outbound telnet sessions</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.20pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 11.52pt; text-align:left;"><span class=font39>X <span class=font1>Not Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:6.96pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font1>11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:6.96pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Enable Sequence Numbers and Time Stamps on Debugs</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:6.96pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 11.52pt; text-align:left;"><span class=font39>X <span class=font1>Not Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:6.96pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font1>12</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:6.96pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Enable IP CEF</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:6.96pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.56pt; text-align:left;"><span class=font24 style=" letter-spacing:-1.00pt;"><b><i>*S </i></b><span class=font1 style=" letter-spacing:0.00pt;">Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.68pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font1>13</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.68pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Disable IP Gratuitous Arps</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.56pt; text-align:left;"><span class=font24 style=" letter-spacing:-1.00pt;"><b><i>*S </i></b><span class=font1 style=" letter-spacing:0.00pt;">Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:6.72pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font1>1 +</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:6.72pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Set Scheduler Interval</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:6.72pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 11.52pt; text-align:left;"><span class=font39>X <span class=font1>Not Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:7.92pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font1>15</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:153.84pt;">
<div class=block style=" width:153.84pt; height:7.92pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font1>Set TCP Synwalttlme</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.80pt;">
<div class=block style=" width:58.80pt; height:7.92pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 11.52pt; text-align:left;"><span class=font39>X <span class=font1>Not Passed</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:153.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:2.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.00pt;">
<div class=paragraph style=" padding:0.00pt 140.40pt 0.00pt 128.40pt; text-align:justify;"><span class=font1 style=" line-height:7.20pt;">Click &quot;Close&quot; to continue fixing the identified security problems or undoing the configured security configurations in the router.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.04pt;">
<div class=paragraph style=" padding:0.00pt 204.24pt 0.00pt 211.20pt; text-align:justify;"><span class=font1>Close&nbsp;Save Report</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 110.40pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">SDM allows you to save a report that lists all the configuration checks that have passed or failed. The report is illustrated in Figure 12-25.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:218.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:321.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>364   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-25 </b><span class=font43><i>Security Audit Report</i></span></span></div>
<div class=paragraph style=" padding:7.44pt 245.76pt 0.00pt 0.00pt; text-align:right;"><span class=font1>I <span class=font38><b>Hosmame |con^any-A-io5-fw</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.56pt;">
<div class=paragraph style=" padding:0.00pt 309.12pt 0.00pt 135.84pt; text-align:justify;"><span class=font38><b><u>Report</u> Saiuruary</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:213.12pt; height:298.56pt; padding:0.00pt 136.80pt 0.00pt 136.08pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:213.12pt; height:298.56pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:163.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:38.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>No</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>Item Name</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font38><b>Status</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>1</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Disable Finger Service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font38><b>Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>2</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>Disable PAD Service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font2 style=" letter-spacing:-0.50pt;">V<span style=" letter-spacing:0.00pt;"> </span><span class=font38 style=" letter-spacing:0.00pt;"><b>Passed</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38 style=" letter-spacing:0.50pt;"><i>3</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Disable TCP small servers Service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font38><b>^ Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font0><b>-1</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Disable LDP small servers Service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font2 style=" letter-spacing:-0.50pt;">V<span style=" letter-spacing:0.00pt;"> </span><span class=font38 style=" letter-spacing:0.00pt;"><b>Passed</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>5</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Disable </b><span style=" letter-spacing:-0.50pt;"><b>ГР</b></span><b> bootp server Service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font38><b>&quot; Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>6</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Disable CDP</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>7</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Disable </b><span style=" letter-spacing:-0.50pt;"><b>ГР</b></span><b> source route</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font38><b>&quot; Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>S</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Enable Password encryption Service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>9</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Enable TCP Keepalives for inbound telnet sessions</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font38><b>&quot; Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>10</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Enable TCP Keepalives for outbound telnet sessions</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>11</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Enable Sequence Numbers and Time Stamps on Debugs</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font38><b>&quot; Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>12</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>Enable IP CEF</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font2 style=" letter-spacing:-0.50pt;">V<span style=" letter-spacing:0.00pt;"> </span><span class=font38 style=" letter-spacing:0.00pt;"><b>Passed</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>13</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Disable IP Gratuitous Arps</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font38><b>Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>14</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>Set Scheduler Interval</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>15</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>Set TCP Synwait time</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>^ Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>16</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>Set Banner</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>17</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Enable Logging</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>^ Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>1S</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>Set Enable Secret Password</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>19</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>Disable SNMP</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font2 style=" letter-spacing:-0.50pt;">ч/<span style=" letter-spacing:0.00pt;"> </span><span class=font38 style=" letter-spacing:0.00pt;"><b>Passed</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>20</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>Set Scheduler Allocate</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>21</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>Set Users</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font38><b>&quot; Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Enable Telnet settings</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38 style=" letter-spacing:0.50pt;"><i>23</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Enable NetFlow Monitoring</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font38><b>&quot; Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>2</b><span class=font0><b>-1</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>Disable </b><span style=" letter-spacing:-0.50pt;"><b>TP</b></span><b> Redirects.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>Disable </b><span style=" letter-spacing:-0.50pt;"><b>TP</b></span><b> Proxy Arp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font38><b>&quot; Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38 style=" letter-spacing:0.50pt;"><i>26</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Disable </b><span style=" letter-spacing:-0.50pt;"><b>TP</b></span><b> Directed Broadcast</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font2 style=" letter-spacing:-0.50pt;">V<span style=" letter-spacing:0.00pt;"> </span><span class=font38 style=" letter-spacing:0.00pt;"><b>Passed</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38><b>Disable </b><span style=" letter-spacing:-0.50pt;"><b>TP</b></span><b> Unreachables</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>^ Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38 style=" letter-spacing:0.50pt;"><i>2S</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>Disable IP Mask Reply</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font2 style=" letter-spacing:-0.50pt;">V<span style=" letter-spacing:0.00pt;"> </span><span class=font38 style=" letter-spacing:0.00pt;"><b>Passed</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38 style=" letter-spacing:0.50pt;"><i>29</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>Disable </b><span style=" letter-spacing:-0.50pt;"><b>ГР</b></span><b> Unreachables on Null interface</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font38><b>&quot; Xot Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38 style=" letter-spacing:0.50pt;"><i>30</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>enable Unicast RPF on all outside interfaces</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>31</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>Enable Firewall on all outside interfaces</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>^ Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.64pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38 style=" letter-spacing:0.50pt;"><i>32</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.64pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font38><b>Set Access class on Hi'IP server service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.64pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 0.96pt; text-align:left;"><span class=font38><b><sup>x</sup> Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38 style=" letter-spacing:0.50pt;"><i>33</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.40pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font38><b>Set Access class on VTY lines</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>X Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>34</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>Enable SSH for access to the router</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.16pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font38><b>&quot; Xot Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:8.64pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font38><b>35</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:163.68pt;">
<div class=block style=" width:163.68pt; height:8.64pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>enable AAA</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:8.64pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font38><b>* Not Passed</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:163.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:38.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:81.12pt;">
<div class=paragraph style=" padding:0.00pt 74.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 8  </b><span class=font44>SDM asks you to enter a new enable secret password and to configure a login banner, as illustrated in Figure 12-26.</span></span></div>
<div class=paragraph style=" padding:6.00pt 77.28pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 9  </b><span class=font44>After you enter the new enable secret password and login banner, click </span><b>Next.</b></span></div>
<div class=paragraph style=" padding:6.00pt 85.68pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 10 </b><span class=font44>SDM allows you to configure an administrative account, as shown in Figure 12-27. To configure a new account, click </span><b>Add.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:127.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>365</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:362.64pt; height:530.40pt; padding:0.00pt 86.88pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-182.jpg" alt="" style=" width:362.64pt; height:530.40pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>366    </b><span class=font4>Chapter 12: Case Studies</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:87.12pt;">
<div class=paragraph style=" padding:0.00pt 89.76pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 11 </b>Enter the username and password, as shown in Figure 12-27. In this example, a user named <b>companyAadmin </b>is created.</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 12 </b>Click <b>OK </b>after entering the username and password.</span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 13 </b>Click <b>Next </b>to continue with the Security Audit Wizard.</span></div>
<div class=paragraph style=" padding:6.96pt 81.12pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 14 </b>In the next screen, SDM allows you to enable logging and configure a system log (SYSLOG) server, as illustrated in Figure 12-28.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 316.80pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 12-28 </b><span class=font43><i>Configuring Logging</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:312.48pt; height:241.92pt; padding:0.00pt 86.64pt 0.00pt 86.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-183.jpg" alt="" style=" width:312.48pt; height:241.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:129.12pt;">
<div class=paragraph style=" padding:0.00pt 77.52pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 15 </b>In this example, the logging level is set to <b>informational (level 6), </b>and the SYSLOG server IP address is <b>10.100.10.222.</b></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 16 </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 102.24pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 17 </b>The Advanced Firewall Configuration Wizard welcome screen is displayed, as shown in Figure 12-29.</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 18 </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 74.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 19 </b>Check the inside and outside interfaces. In this example, <b>FastEthernet4 </b>is the outside interface, and <b>Vlan1 </b>is the inside interface. This is illustrated in Figure 12-30.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:72.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>367</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 184.08pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-29 </b><span class=font43><i>Advanced Firewall Configuration Wizard Welcome Screen</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:300.00pt; height:217.44pt; padding:0.00pt 92.88pt 0.00pt 93.12pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-184.jpg" alt="" style=" width:300.00pt; height:217.44pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 205.44pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-30 </b><span class=font43><i>IOS Firewall Inside and Outside Interface Selection</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:300.00pt; height:216.96pt; padding:0.00pt 92.88pt 0.00pt 93.12pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-185.jpg" alt="" style=" width:300.00pt; height:216.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph style=" padding:0.00pt 314.40pt 0.00pt 90.24pt; text-align:justify;"><span class=font4><b>Step 20 </b><span class=font44>Click </span><b>Next.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:64.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>368   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:65.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>Step 21 </b><span class=font44>The screen shown in Figure 12-31 is displayed. In this screen, SDM</span></span></div>
<div class=paragraph style=" padding:0.24pt 74.16pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">allows you to enable predefined application security policies. You can use the slider to select the security level. In this example, the security level is set to <span class=font4><b>High.</b></span></span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-31 </b><span class=font43><i>Application Security Policies</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:300.00pt; height:216.96pt; padding:0.00pt 92.88pt 0.00pt 93.12pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-186.jpg" alt="" style=" width:300.00pt; height:216.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:121.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 22 </b><span class=font44>Click </span><b>Next.</b></span></div>
<div class=paragraph style=" padding:6.96pt 84.96pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 23 </b><span class=font44>The SDM Wizard allows you enter the primary and secondary DNS servers for name resolution, as illustrated in Figure 12-32. In this example, the primary DNS server is </span><b>10.100.10.21, </b><span class=font44>and the secondary</span></span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 125.76pt; text-align:left;"><span class=font44>DNS server is <span class=font4><b>10.100.10.22.</b></span></span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 24 </b><span class=font44>Click </span><b>Next </b><span class=font44>after entering the DNS server information.</span></span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>Step 25 </b><span class=font44>A summary screen lists the configuration changes, as illustrated in</span></span></div>
<div class=paragraph style=" padding:0.24pt 74.40pt 0.00pt 125.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Figure 12-33. Click <span class=font4><b>Finish </b></span>to send the configuration changes to the Cisco IOS router.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:146.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>369</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:356.40pt; height:232.80pt; padding:0.00pt 93.12pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-187.jpg" alt="" style=" width:356.40pt; height:232.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:356.40pt; height:232.80pt; padding:0.00pt 93.12pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-188.jpg" alt="" style=" width:356.40pt; height:232.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:80.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>370   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:516.24pt;">
<div class=paragraph style=" padding:0.00pt 70.08pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Example 12-2 shows the CLI configuration of the router at the Atlanta office after completing the previous steps.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-2  </b><span class=font43><i>CLI Configuration of the Cisco IOS Router at the Atlanta Office</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">company-A-ios-fw#show running-config</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Building configuration...</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Current configuration : 8080 bytes</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>!</span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">version 12.4</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">no service pad</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">service tcp-keepalives-in</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">service tcp-keepalives-out</span></div>
<div class=paragraph style=" padding:0.24pt 124.56pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">service timestamps debug datetime msec localtime show-timezone service timestamps log datetime msec localtime show-timezone service password-encryption service sequence-numbers <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 282.72pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.40pt;">hostname company-A-ios-fw <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>boot-start-marker</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>boot-end-marker</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.64pt 287.28pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.12pt;">no logging buffered logging console critical</span></div>
<div class=paragraph style=" padding:0.72pt 193.68pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.12pt;">enable secret 5 $1$XlSV$Pa0oIYeuSY5CZOGXXOJjF/ <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.64pt 334.56pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">aaa new-model <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.64pt 205.92pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.88pt;">aaa authentication login local_authen local aaa authorization exec local_author local <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">aaa session-id common</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">no ip source-route</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip cef</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip tcp synwait-time 10</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">no ip bootp server</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip name-server 10.100.10.21</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip name-server 10.100.10.22</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip ssh time-out 60</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip ssh authentication-retries 2</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 201.60pt 0.00pt 101.52pt; text-align:left; text-indent:-4.56pt;"><span class=font23 style=" line-height:9.60pt;">parameter-map type protocol-info msn-servers server name messenger.hotmail.com server name gateway.messenger.hotmail.com server name webmessenger.msn.com</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 201.60pt 0.00pt 101.52pt; text-align:left; text-indent:-4.56pt;"><span class=font23 style=" line-height:9.60pt;">parameter-map type protocol-info aol-servers server name login.oscar.aol.com server name toc.oscar.aol.com server name <a href="http://oam-d09a.blue.aol.com">oam-d09a.blue.aol.com</a></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:60.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.68pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>371</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.80pt;">
<div class=paragraph style=" padding:0.00pt 116.88pt 0.00pt 89.76pt; text-align:left; text-indent:-53.52pt;"><span class=font3 style=" line-height:15.36pt;"><b>Example 12-2  </b><span class=font43><i>CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued) </i></span><span class=font24>I</span><span class=font24 style=" letter-spacing:-1.00pt;"> </span><span class=font23>parameter-map type protocol-info yahoo-servers</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:186.00pt; height:213.36pt; padding:0.00pt 199.92pt 0.00pt 100.08pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:186.00pt; height:213.36pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>scs.msg.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>scsa.msg.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>scsb.msg.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>scsc.msg.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>scsd.msg.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>cs16.msg.dcn.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>cs19.msg.dcn.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>cs42.msg.dcn.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23><a href="http://cs53.msg.dcn.yahoo.com">cs53.msg.dcn.yahoo.com</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>cs54.msg.dcn.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>ads1.vip.scd.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>radio1.launch.vip.dal.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23><a href="http://in1.msg.vip.re2.yahoo.com">in1.msg.vip.re2.yahoo.com</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>data1.my.vip.sc5.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>address1.pim.vip.mud.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>edit.messenger.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>messenger.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23><a href="http://http.pager.yahoo.com">http.pager.yahoo.com</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>privacy.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>csa.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>csb.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.08pt;">
<div class=block style=" width:136.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>csc.yahoo.com</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:278.40pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 205.92pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.84pt;">parameter-map type regex sdm-regex-nonascii pattern [&quot;<a href="file:///x00-/x80">\x00-\x80</a>]</span></div>
<div class=paragraph style=" padding:39.60pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23>username companyAadmin password 7 02050D4808095E731F</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">class-map type inspect smtp match-any sdm-app-smtp</span></div>
<div class=paragraph style=" padding:0.00pt 158.88pt 0.00pt 97.20pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">match   data-length gt 5000000 class-map type inspect http match-any sdm-app-nonascii</span></div>
<div class=paragraph style=" padding:0.00pt 175.92pt 0.00pt 97.20pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">match   req-resp header regex sdm-regex-nonascii class-map type inspect imap match-any sdm-app-imap</span></div>
<div class=paragraph style=" padding:0.00pt 163.20pt 0.00pt 97.20pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">match invalid-command class-map type inspect match-any sdm-cls-insp-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol dns</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol https</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol icmp</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol imap</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol pop3</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol tcp</span></div>
<div class=paragraph style=" padding:0.00pt 180.24pt 0.00pt 97.20pt; text-align:left; text-indent:4.08pt;"><span class=font23 style=" line-height:9.60pt;">match protocol udp class-map type inspect match-all sdm-insp-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 175.92pt 0.00pt 97.20pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">match class-map sdm-cls-insp-traffic class-map type inspect match-all sdm-protocol-pop3</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol pop3</span></div>
<div class=paragraph style=" padding:1.68pt 38.64pt 0.00pt 0.00pt; text-align:right;"><span class=font43><i>continues</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>372   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:217.20pt;">
<div class=paragraph style=" padding:0.00pt 116.88pt 0.00pt 36.24pt; text-align:justify;"><span class=font3><b>Example 12-2  </b><span class=font43><i>CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 70.80pt 0.00pt 0.00pt; text-align:center;"><span class=font23 style=" line-height:9.60pt;">class-map type inspect match-any sdm-cls-icmp-access</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol icmp</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol tcp</span></div>
<div class=paragraph style=" padding:0.24pt 167.52pt 0.00pt 96.96pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">match protocol udp class-map type inspect match-any sdm-cls-protocol-im</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol ymsgr yahoo-servers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol msnmsgr msn-servers</span></div>
<div class=paragraph style=" padding:0.24pt 175.92pt 0.00pt 96.96pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">match protocol aol aol-servers class-map type inspect pop3 match-any sdm-app-pop3</span></div>
<div class=paragraph style=" padding:0.24pt 145.92pt 0.00pt 96.96pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">match invalid-command class-map type inspect http match-any sdm-http-blockparam</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match   request port-misuse im</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match   request port-misuse p2p</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match   request port-misuse tunneling</span></div>
<div class=paragraph style=" padding:0.00pt 184.56pt 0.00pt 96.96pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">match   req-resp protocol-violation class-map type inspect match-all sdm-protocol-im</span></div>
<div class=paragraph style=" padding:0.00pt 184.56pt 0.00pt 96.96pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">match class-map sdm-cls-protocol-im class-map type inspect match-all sdm-icmp-access</span></div>
<div class=paragraph style=" padding:0.00pt 184.56pt 0.00pt 96.96pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">match class-map sdm-cls-icmp-access class-map type inspect match-all sdm-invalid-src</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match access-group 100</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:246.24pt; height:300.72pt; padding:0.00pt 144.24pt 0.00pt 95.52pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:246.24pt; height:300.72pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:149.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:97.20pt;">
<div class=block style=" width:97.20pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 2.88pt 0.00pt 0.00pt; text-align:right;"><span class=font23>class-map type inspect</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>http match-any sdm-app-httpmethods</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>bcopy</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>bdelete</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>bmove</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>bpropfind</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>bproppatch</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>connect</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>copy</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>delete</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>edit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>getattribute</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>getattributenames</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>getproperties</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>index</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>lock</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>mkcol</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>mkdir</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>move</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>notify</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>options</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>poll</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>post</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>propfind</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>proppatch</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>put</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>revadd</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>revlabel</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>revlog</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>revnum</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>save</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.28pt; text-align:left;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>search</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:149.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>373</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 116.88pt 0.00pt 36.24pt; text-align:justify;"><span class=font3><b>Example 12-2  </b><span class=font43><i>CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:216.24pt; height:96.72pt; padding:0.00pt 174.24pt 0.00pt 95.52pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:216.24pt; height:96.72pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt;">
<div class=block style=" width:29.04pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:37.68pt;">
<div class=block style=" width:37.68pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>setattribute</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt;">
<div class=block style=" width:29.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:37.68pt;">
<div class=block style=" width:37.68pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>startrev</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt;">
<div class=block style=" width:29.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:37.68pt;">
<div class=block style=" width:37.68pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>stoprev</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt;">
<div class=block style=" width:29.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:37.68pt;">
<div class=block style=" width:37.68pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>subscribe</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt;">
<div class=block style=" width:29.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:37.68pt;">
<div class=block style=" width:37.68pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>trace</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt;">
<div class=block style=" width:29.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:37.68pt;">
<div class=block style=" width:37.68pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>unedit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt;">
<div class=block style=" width:29.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:37.68pt;">
<div class=block style=" width:37.68pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>unlock</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt;">
<div class=block style=" width:29.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:37.68pt;">
<div class=block style=" width:37.68pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>unsubscribe</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:10.08pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>class-map type</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:10.08pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>inspect</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:10.08pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>match-all sdm-protocol-http</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt;">
<div class=block style=" width:29.04pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>match</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:37.68pt;">
<div class=block style=" width:37.68pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font23>protocol</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>http</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:9.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:414.48pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">class-map type inspect match-all sdm-protocol-smtp</span></div>
<div class=paragraph style=" padding:0.24pt 175.92pt 0.00pt 97.20pt; text-align:left; text-indent:4.08pt;"><span class=font23 style=" line-height:9.60pt;">match protocol smtp class-map type inspect match-all sdm-protocol-imap</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match protocol imap</span></div>
<div class=paragraph style=" padding:0.00pt 386.88pt 0.00pt 98.16pt; text-align:justify;"><span class=font23 style=" line-height:9.84pt;"><sub>! !</sub></span></div>
<div class=paragraph style=" padding:1.20pt 201.60pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">policy-map type inspect sdm-permit-icmpreply class type inspect sdm-icmp-access</span></div>
<div class=paragraph style=" padding:0.00pt 304.80pt 0.00pt 101.52pt; text-align:left; text-indent:4.08pt;"><span class=font23 style=" line-height:9.60pt;">inspect class class-default pass</span></div>
<div class=paragraph style=" padding:0.24pt 184.56pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">policy-map type inspect http sdm-action-app-http class type inspect http sdm-http-blockparam log reset</span></div>
<div class=paragraph style=" padding:0.24pt 201.60pt 0.00pt 105.60pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">class type inspect http sdm-app-httpmethods log reset</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">class type inspect http sdm-app-nonascii</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">log</span></div>
<div class=paragraph style=" padding:0.00pt 201.60pt 0.00pt 97.20pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">reset class class-default policy-map type inspect smtp sdm-action-smtp class type inspect smtp sdm-app-smtp</span></div>
<div class=paragraph style=" padding:0.00pt 201.60pt 0.00pt 97.20pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">reset class class-default policy-map type inspect imap sdm-action-imap class type inspect imap sdm-app-imap</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">log</span></div>
<div class=paragraph style=" padding:0.24pt 201.60pt 0.00pt 97.20pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">reset class class-default policy-map type inspect pop3 sdm-action-pop3 class type inspect pop3 sdm-app-pop3</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">log</span></div>
<div class=paragraph style=" padding:0.00pt 240.24pt 0.00pt 97.20pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">reset class class-default policy-map type inspect sdm-inspect class type inspect sdm-invalid-src</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">drop log</span></div>
<div class=paragraph style=" padding:0.24pt 231.60pt 0.00pt 105.60pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">class type inspect sdm-protocol-http inspect</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.84pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">service-policy http sdm-action-app-http</span></div>
<div class=paragraph style=" padding:1.44pt 38.64pt 0.00pt 0.00pt; text-align:right;"><span class=font43><i>continues</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>374   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:498.96pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-2  </b><span class=font43><i>CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 231.60pt 0.00pt 105.60pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">class type inspect sdm-protocol-smtp inspect</span></div>
<div class=paragraph style=" padding:0.00pt 231.60pt 0.00pt 101.28pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">service-policy smtp sdm-action-smtp class type inspect sdm-protocol-imap inspect</span></div>
<div class=paragraph style=" padding:0.24pt 231.60pt 0.00pt 101.28pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">service-policy imap sdm-action-imap class type inspect sdm-protocol-pop3 inspect</span></div>
<div class=paragraph style=" padding:0.00pt 231.60pt 0.00pt 101.28pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">service-policy pop3 sdm-action-pop3 class type inspect sdm-protocol-im drop log</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">class type inspect sdm-insp-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 244.80pt 0.00pt 96.96pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">inspect class class-default policy-map type inspect sdm-permit class class-default</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 295.92pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">zone security out-zone zone security in-zone</span></div>
<div class=paragraph style=" padding:0.24pt 103.20pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">zone-pair security sdm-zp-self-out source self destination out-zone service-policy type inspect sdm-permit-icmpreply</span></div>
<div class=paragraph style=" padding:0.24pt 103.44pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">zone-pair security sdm-zp-out-self source out-zone destination self service-policy type inspect sdm-permit</span></div>
<div class=paragraph style=" padding:0.24pt 98.88pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">zone-pair security sdm-zp-in-out source in-zone destination out-zone service-policy type inspect sdm-inspect</span></div>
<div class=paragraph style=" padding:48.48pt 308.64pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.84pt;">interface Null0 no ip unreachables</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:3.12pt 291.36pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">interface FastEthernet0 <sub>!</sub></span></div>
<div class=paragraph style=" padding:3.12pt 292.56pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">interface FastEthernet1 <sub>!</sub></span></div>
<div class=paragraph style=" padding:3.12pt 291.36pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">interface FastEthernet2 <sub>!</sub></span></div>
<div class=paragraph style=" padding:3.12pt 291.36pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">interface FastEthernet3 <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 283.20pt 0.00pt 101.28pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">interface FastEthernet4 description $FW_OUTSIDE$</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 209.165.200.231 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">no ip redirects</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">no ip unreachables</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">no ip proxy-arp</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">zone-member security out-zone</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip route-cache flow</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">duplex auto</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:77.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>375</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:507.36pt;">
<div class=paragraph style=" padding:0.00pt 116.88pt 0.00pt 101.52pt; text-align:left; text-indent:-65.28pt;"><span class=font3 style=" line-height:15.36pt;"><b>Example 12-2  </b><span class=font43><i>CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued) </i></span><span class=font23>speed auto</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 287.28pt 0.00pt 101.28pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.84pt;">interface Vlan1 description $FW_INSIDE$</span></div>
<div class=paragraph style=" padding:0.00pt 231.60pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 10.100.10.1 255.255.255.0 no ip redirects no ip unreachables no ip proxy-arp zone-member security in-zone ip route-cache flow</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23>ip route 0.0.0.0 0.0.0.0 209.165.200.225</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.64pt 287.52pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.88pt;">ip http server no ip http secure-server <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.68pt 278.64pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">logging trap informational logging 10.100.10.222</span></div>
<div class=paragraph style=" padding:0.00pt 163.20pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list 100 remark SDM_ACL Category=128 access-list 100 permit ip host 255.255.255.255 any access-list 100 permit ip 127.0.0.0 0.255.255.255 any access-list 100 permit ip 209.165.200.0 0.0.0.255 any access-list 101 remark VTY Access-class list access-list 101 remark SDM_ACL Category=1 access-list 101 permit ip 10.100.10.0 0.0.0.255 any access-list 101 deny     ip any any no cdp run</span></div>
<div class=paragraph style=" padding:29.76pt 334.56pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.40pt;">control-plane <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 94.56pt 0.00pt 96.96pt; text-align:justify;"><span class=font23 style=" line-height:8.40pt;">banner login &quot;C*** THIS IS A RESTRICTED SYSTEM, UNAUTHORIZED ACCESS&quot;C <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 244.56pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">line con 0 login authentication local_authen no modem enable transport output telnet line aux 0 login authentication local_authen transport output telnet line vty 0 4 access-class 101 in authorization exec local_author login authentication local_authen transport input telnet ssh</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 270.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">scheduler max-task-time 5000 scheduler allocate 4000 1000 scheduler interval 500 end</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:68.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:383.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:102.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>376    </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:106.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring Basic Network Address Translation (NAT)</span></div>
<div class=paragraph style=" padding:4.08pt 40.08pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The router administrator needs to configure basic NAT for internal users to access the Internet. The following steps are completed to enable basic NAT on the Cisco IOS router.</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 1   </b><span class=font44>Log in to the router using SDM.</span></span></div>
<div class=paragraph style=" padding:6.48pt 86.88pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.24pt;"><b>Step 2  </b><span class=font44>Navigate to </span><b>Configure &gt; NAT </b><span class=font44>and click </span><b>Basic NAT, </b><span class=font44>as illustrated in Figure 12-34.</span></span></div>
<div class=paragraph style=" padding:9.84pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-34 </b><span class=font43><i>Configuring Basic NAT</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:383.28pt;">
<div class=block style=" width:308.40pt; height:257.76pt; padding:0.00pt 0.00pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-189.jpg" alt="" style=" width:336.00pt; height:257.76pt;"></div>
</td>
<td class=cell valign="top" style=" width:102.72pt;">
<div class=block style=" width:102.72pt; height:257.76pt;">
<div class=paragraph style=" padding:23.52pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font45>34</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:59.52pt;">
<div class=paragraph style=" padding:0.00pt 122.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 3  </b><span class=font44>Click the </span><b>Launch the selected task </b><span class=font44>button to start the NAT Configuration Wizard.</span></span></div>
<div class=paragraph style=" padding:6.96pt 83.28pt 0.00pt 90.24pt; text-align:justify;"><span class=font4><b>Step 4  </b><span class=font44>The NAT Configuration Wizard welcome screen appears. Click </span><b>Next.</b></span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 5  </b><span class=font44>The screen shown in Figure 12-35 is displayed.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:130.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:383.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:102.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>377</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 273.84pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 12-35 </b><span class=font43><i>Basic NAT Configuration Wizard</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:295.68pt; height:217.44pt; padding:0.00pt 95.28pt 0.00pt 95.04pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-190.jpg" alt="" style=" width:295.68pt; height:217.44pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:97.20pt;">
<div class=paragraph style=" padding:0.00pt 81.84pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font44 style=" line-height:12.24pt;"><b>Step 6  </b>Choose the interface that connects to the Internet from the drop-down menu. <b>FastEthernet4 </b>is selected in this example.</span></div>
<div class=paragraph style=" padding:5.76pt 84.96pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 7  </b>In this example, the inside network will be translated to the public IP address of the outside interface.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 8   </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:7.92pt 74.88pt 0.00pt 90.24pt; text-align:justify;"><span class=font44><b>Step 9  </b>The wizard displays a summary screen listing the configuration changes.</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44>Click <b>Finish.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:128.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring Site-to-Site VPN</span></div>
<div class=paragraph style=" padding:4.08pt 42.96pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Users at the office in Atlanta need to securely access resources in the Raleigh office. The security administrator configures a site-to-site IPsec tunnel between the Cisco ASA in Raleigh and the Cisco IOS router in Atlanta.</span></div>
<div class=paragraph style=" padding:6.24pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The following are the steps that need to be completed to configure the Cisco IOS router in Atlanta to terminate a site-to-site IPsec tunnel with the Cisco ASA in Raleigh.</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 1  </b>Log in to the router using SDM.</span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 2  </b>Navigate to <b>Configure &gt; VPN </b>and choose <b>Site-to-Site VPN, </b>as</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44>illustrated in Figure 12-36.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:71.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:383.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:102.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>378   </b><span class=font4>Chapter 12: Case Studies</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 235.68pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 12-36 </b><span class=font43><i>Configuring a Site-to-Site VPN Using SDM</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:383.28pt;">
<div class=block style=" width:308.40pt; height:258.24pt; padding:0.00pt 0.00pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-191.jpg" alt="" style=" width:336.00pt; height:258.24pt;"></div>
</td>
<td class=cell valign="top" style=" width:102.72pt;">
<div class=block style=" width:102.72pt; height:258.24pt;">
<div class=paragraph style=" padding:24.00pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font45>34</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:158.64pt;">
<div class=paragraph style=" padding:0.00pt 74.40pt 0.00pt 90.24pt; text-align:justify;"><span class=font44><b>Step 3   </b>Click <b>Create a Site to Site VPN </b>and click the <b>Launch the selected task</b></span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 125.76pt; text-align:left;"><span class=font44>button.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><b>Step 4  </b>The <b>Site-to-Site VPN Wizard </b>welcome screen is displayed, as</span></div>
<div class=paragraph style=" padding:0.24pt 74.64pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">illustrated in Figure 12-37. The <b>Quick setup </b>option allows you to easily configure a site-to-site VPN tunnel to another Cisco router with minimal interaction. In this case, the router will be creating a site-to-site VPN tunnel to a Cisco ASA, then the <b>Step by step wizard </b>is selected. This option lets you customize the configuration.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 5 </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 74.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 6  </b>The screen shown in Figure 12-38 is displayed. Select the interface that will terminate the VPN tunnel. In this example, <b>FastEthernet4 </b>(the outside interface of the router) is selected.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:125.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:383.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:102.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>379</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 224.88pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-37 </b><span class=font43><i>SDM Site-to-Site VPN Wizard Welcome Screen</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:312.48pt; height:242.40pt; padding:0.00pt 86.64pt 0.00pt 86.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-192.jpg" alt="" style=" width:312.48pt; height:242.40pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 156.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-38 </b><span class=font43><i>Configuring the VPN Interface, Remote Peer, and Preshared Keys</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:312.48pt; height:242.40pt; padding:0.00pt 86.64pt 0.00pt 86.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-193.jpg" alt="" style=" width:312.48pt; height:242.40pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:42.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>380    </b><span class=font4>Chapter 12: Case Studies</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:105.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;"><b>Step 7  </b>In this case, the VPN peer (Cisco ASA) is configured with a static IP</span></div>
<div class=paragraph style=" padding:0.00pt 74.64pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">address. Choose <b>Peer with static IP address </b>from the drop-down menu and enter the IP address of the peer <b>(209.165.200.225). </b>Preshared keys are used in this example for tunnel authentication.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 8 </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 74.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 9  </b>The next screen allows you to configure an Internet Key Exchange (IKE) (as illustrated in Figure 12-39). This policy must match the IKE policy on the Cisco ASA. Click <b>Add </b>to enter a new IKE policy.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 254.88pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 12-39 </b><span class=font43><i>Configuring the IKE Policy with SDM</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:311.52pt; height:240.00pt; padding:0.00pt 87.12pt 0.00pt 87.36pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-194.jpg" alt="" style=" width:311.52pt; height:240.00pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:134.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;"><b>Step 10 </b>In this case, a new policy is configured to use preshared keys for</span></div>
<div class=paragraph style=" padding:0.00pt 74.16pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">authentication. The selected encryption protocol is Advanced Encryption Standard <b>AES_256. </b>Diffie-Hellman (DH) <b>Group 2 </b>is used. The IKE hashing algorithm is Secure Hash Algorithm <b>SHA_1. </b>The default 24-hour lifetime for IKE is selected.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 11 </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 77.52pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 12 </b>The next screen enables you to configure the IPsec policies. Click <b>Add </b>to add a new transform-set (IPsec phase two policies).</span></div>
<div class=paragraph style=" padding:6.24pt 94.80pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 13 </b>The dialog box illustrated in Figure 12-40 appears allowing you to configure the IPsec policies.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.68pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>381</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 202.32pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 12-40 </b><span class=font43><i>Configuring the IPsec Phase Two Policies with SDM</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:166.08pt; height:204.48pt; padding:0.00pt 160.08pt 0.00pt 159.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-195.jpg" alt="" style=" width:166.08pt; height:204.48pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:260.64pt;">
<div class=paragraph style=" padding:0.00pt 104.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 14 </b>Enter a name for the new transform set. In this case, the name is <b>tunnel-to-asa.</b></span></div>
<div class=paragraph style=" padding:6.00pt 105.60pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 15 </b>The Encapsulatation Security Payload (ESP) protocol is used in this example. The integrity algorithm used in this example is</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 125.76pt; text-align:left;"><span class=font44><b>ESP_SHA_HMAC, </b>and the encryption algorithm is <b>ESP_AES_256.</b></span></div>
<div class=paragraph style=" padding:0.96pt 74.88pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The Cisco ASA configuration must match these settings to establish the site-to-site IPsec VPN tunnel.</span></div>
<div class=paragraph style=" padding:6.00pt 76.80pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 16 </b>Tunnel mode is used in this example to encrypt both the payload (data) and IP header.</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 17 </b>Click <b>OK </b>to add the new transform-set.</span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 18 </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 19 </b>The screen shown in Figure 12-41 is displayed. It allows you to select the traffic you would like to protect.</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 20 </b>Click <b>Protect all traffic between the following subnets.</b></span></div>
<div class=paragraph style=" padding:6.96pt 74.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 21 </b>Configure the local and remote networks (the networks that will be able to communicate over the VPN tunnel). In this case, the local network is <b>10.100.10.0/24, </b>and the remote network is <b>10.10.10.0/24.</b></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 22 </b>Click <b>Next.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:75.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>382   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 330.96pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-41 </b><span class=font43><i>Traffic to Protect</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:312.48pt; height:242.40pt; padding:0.00pt 86.64pt 0.00pt 86.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-196.jpg" alt="" style=" width:312.48pt; height:242.40pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:63.12pt;">
<div class=paragraph style=" padding:0.00pt 75.84pt 0.00pt 125.76pt; text-align:justify; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 23 </b><span class=font44>A summary screen listing the configuration changes is displayed. Click </span><b>Finish </b><span class=font44>to apply the changes.</span></span></div>
<div class=paragraph style=" padding:6.00pt 74.64pt 0.00pt 125.76pt; text-align:justify; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 24 </b><span class=font44>Because NAT/PAT was configured on the router, SDM shows a warning message asking you if you would like to bypass NAT for the traffic over the VPN tunnel. The warning screen is shown in Figure 12-42.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 314.64pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-42 </b><span class=font43><i>SDM Warning Screen</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:216.00pt; height:147.84pt; padding:0.00pt 135.12pt 0.00pt 134.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-197.jpg" alt="" style=" width:216.00pt; height:147.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 176.40pt 0.00pt 90.24pt; text-align:justify;"><span class=font4><b>Step 25 </b><span class=font44>Click </span><b>Yes </b><span class=font44>to bypass NAT for the tunnel traffic.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>383</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:398.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44>Example 12-3 shows the CLI VPN configuration of the router.</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-3  </b><span class=font43><i>CLI VPN Configuration of the Router</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 295.92pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!Phase 1 IKE policy crypto isakmp policy 2 encr aes 256</span></div>
<div class=paragraph style=" padding:0.00pt 283.20pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">authentication pre-share group 2</span></div>
<div class=paragraph style=" padding:0.48pt 175.92pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.40pt;">crypto isakmp key cisco123 address 209.165.200.225 !</span></div>
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>!Phase 2 policy</span></div>
<div class=paragraph style=" padding:1.68pt 111.60pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">crypto ipsec transform-set tunnel-to-asa esp-aes 256 esp-sha-hmac <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 145.44pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!crypto-map configuration for the Tunnel to the Cisco ASA crypto map SDM_CMAP_1 1 ipsec-isakmp</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">description Tunnel <a href="http://to209.165.200.225">to209.165.200.225</a></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">set peer 209.165.200.225</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">set transform-set tunnel-to-asa</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">match address 102</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!ACL defining tunnel traffic</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list 102 remark SDM_ACL Category=4</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list 102 remark IPSec Rule</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list 102 permit ip 10.100.10.0 0.0.0.255 10.10.10.0 0.0.0.255</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 253.44pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!Outside Interface Configuration interface FastEthernet4</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">description $FW_OUTSIDE$</span></div>
<div class=paragraph style=" padding:0.48pt 214.56pt 0.00pt 96.96pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">ip address 209.165.200.231 255.255.255.0 ip nat outside crypto map SDM_CMAP_1</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>!NAT Configuration - bypassing NAT for tunnel traffic</span></div>
<div class=paragraph style=" padding:1.68pt 73.44pt 0.00pt 97.20pt; text-align:justify;"><span class=font23 style=" line-height:8.16pt;">ip nat inside source route-map SDM_RMAP_1 interface FastEthernet4 overload <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 214.56pt 0.00pt 100.80pt; text-align:left; text-indent:-3.84pt;"><span class=font23 style=" line-height:9.60pt;">route-map SDM_RMAP_1 permit 1 match ip address 105 access-list 105 remark SDM_ACL Category=2 access-list 105 remark IPSec Rule</span></div>
<div class=paragraph style=" padding:0.24pt 98.88pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list 105 deny     ip 10.100.10.0 0.0.0.255 10.10.10.0 0.0.0.255 access-list 105 permit ip 10.100.10.0 0.0.0.255 any</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:99.12pt;">
<div class=paragraph style=" padding:0.00pt 72.24pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The next task is to configure the Cisco ASA in the Raleigh office to terminate the site-to-site VPN tunnel. Complete the following steps to complete this task.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 1  </b>Log in to the Cisco ASA using ASDM.</span></div>
<div class=paragraph style=" padding:7.68pt 74.88pt 0.00pt 90.24pt; text-align:justify;"><span class=font44><b>Step 2  </b>From the main ASDM menu, choose <b>Wizards &gt; IPsec VPN Wizard, </b>as</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 126.24pt; text-align:left;"><span class=font44>shown in Figure 12-43.</span></div>
<div class=paragraph style=" padding:6.96pt 90.24pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 3  </b>The VPN Wizard starts by allowing you to select the tunnel type, as illustrated in Figure 12-44. Click <b>Site-to-Site.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>384   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:39.12pt;">
<div class=paragraph style=" padding:0.00pt 96.00pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 4  </b><span class=font44>Choose the </span><b>outside </b><span class=font44>interface as the VPN tunnel interface from the drop-down menu.</span></span></div>
<div class=paragraph style=" padding:8.16pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-43 </b><span class=font43><i>Launching the ASDM IPsec VPN Wizard</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:330.24pt; height:239.04pt; padding:0.00pt 78.00pt 0.00pt 77.76pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-198.jpg" alt="" style=" width:330.24pt; height:239.04pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 251.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-44 </b><span class=font43><i>ASDM VPN Wizard—VPN Tunnel Type</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:303.36pt; height:225.60pt; padding:0.00pt 91.44pt 0.00pt 91.20pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-199.jpg" alt="" style=" width:303.36pt; height:225.60pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <b>385</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:89.28pt;">
<div class=paragraph style=" padding:0.00pt 74.16pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 5  </b><span class=font44>In this example, the Cisco ASA will be configured to allow inbound IPsec sessions to bypass all configured access control lists (ACL).</span></span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 6  </b><span class=font44>Click </span><b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 78.24pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 7  </b><span class=font44>The screen shown in Figure 12-45 is displayed. Here you can enter the remote site peer information.</span></span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-45 </b><span class=font43><i>ASDM VPN Wizard—Remote Peer Information</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:310.08pt; height:229.92pt; padding:0.00pt 88.08pt 0.00pt 87.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-200.jpg" alt="" style=" width:310.08pt; height:229.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:176.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 8  </b><span class=font44>Enter the peer IP address </span><b>(209.165.200.231 </b><span class=font44>in this example).</span></span></div>
<div class=paragraph style=" padding:6.48pt 89.04pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.24pt;"><b>Step 9  </b><span class=font44>Under </span><b>Authentication Method, </b><span class=font44>click </span><b>Pre-shared key </b><span class=font44>and enter the preshared key. In this example, the preshared key is </span><b>1qazXSW2.</b></span></div>
<div class=paragraph style=" padding:5.28pt 74.64pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.24pt;"><b>Step 10 </b><span class=font44>By default, the IP address of the remote peer is used as the tunnel group name. Leave the default configuration.</span></span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 11 </b><span class=font44>Click </span><b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 78.24pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 12 </b><span class=font44>The screen shown in Figure 12-46 is displayed. Here you can enter the IKE policy information.</span></span></div>
<div class=paragraph style=" padding:6.24pt 74.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 13 </b><span class=font44>The IKE policy parameters must match those configured in the router. In this case, the same encryption protocol, authentication hashing algorithm, and DH group are configured.</span></span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 14 </b><span class=font44>Click </span><b>Next.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:54.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>386   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 275.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-46 </b><span class=font43><i>ASDM VPN Wizard—IKE Policy</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:300.48pt; height:223.20pt; padding:0.00pt 85.20pt 0.00pt 100.32pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-201.jpg" alt="" style=" width:300.48pt; height:223.20pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 78.24pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 15 </b><span class=font44>The screen shown in Figure 12-47 is displayed. Here you can enter the IPsec phase 2 information.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 181.20pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-47 </b><span class=font43><i>ASDM VPN Wizard—IPsec Encryption and Authentication</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:300.48pt; height:222.72pt; padding:0.00pt 92.88pt 0.00pt 92.64pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-202.jpg" alt="" style=" width:300.48pt; height:222.72pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:53.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 294.96pt; text-align:justify;"><span class=font4>Case Study of a Small Business <span class=font44><b>387</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:101.04pt;">
<div class=paragraph style=" padding:0.00pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.24pt;"><b>Step 16 </b>The IPsec encryption and authentication protocol parameters must match those configured in the router, as shown in Figure 12-47.</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 17 </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 77.52pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 18 </b>The screen shown in Figure 12-48 is displayed. This screen allows you to enter the local and remote networks that will communicate over the IPsec site-to-site VPN tunnel.</span></div>
<div class=paragraph style=" padding:9.36pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font44><b>Figure 12-48 </b><span class=font43><i>ASDM VPN Wizard—Hosts and Networks</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:310.08pt; height:229.92pt; padding:0.00pt 88.08pt 0.00pt 87.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-203.jpg" alt="" style=" width:310.08pt; height:229.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:164.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 19 </b>Under <b>Action, </b>click <b>Protect.</b></span></div>
<div class=paragraph style=" padding:7.92pt 74.64pt 0.00pt 90.24pt; text-align:justify;"><span class=font44><b>Step 20 </b>Enter the local network information. In this case, the <b>inside-network/24</b></span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44>is selected.</span></div>
<div class=paragraph style=" padding:6.72pt 87.84pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.24pt;"><b>Step 21 </b>Enter the remote network information. The <b>10.100.10.0/24, atlanta-office </b>remote network is selected in this example.</span></div>
<div class=paragraph style=" padding:5.28pt 76.80pt 0.00pt 90.24pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;"><b>Step 22 </b>Check the <b>Exempt ASA side host/network from address translation</b></span></div>
<div class=paragraph style=" padding:0.00pt 90.24pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">option and choose the <b>inside </b>interface from the drop-down menu to bypass NAT for tunnel traffic.</span></div>
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:18.00pt;"><b>Step 23 </b>Click <b>Next.</b></span></div>
<div class=paragraph style=" padding:0.00pt 132.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:18.00pt;"><b>Step 24 </b>The summary screen shown in Figure 12-49 is displayed. <b>Step 25 </b>Click <b>Finish </b>to apply the changes to the Cisco ASA.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>388    </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 253.44pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-49 </b><span class=font43><i>ASDM VPN Wizard—Summary Screen</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:310.08pt; height:155.04pt; padding:0.00pt 88.08pt 0.00pt 87.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-204.jpg" alt="" style=" width:310.08pt; height:155.04pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:310.08pt; height:63.84pt; padding:0.00pt 88.08pt 0.00pt 87.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-205.jpg" alt="" style=" width:310.08pt; height:63.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:214.32pt;">
<div class=paragraph style=" padding:0.00pt 107.76pt 0.00pt 0.00pt; text-align:right;"><span class=font44 style=" line-height:15.12pt;">Example 12-4 shows the Cisco ASA CLI site-to-site VPN configuration.</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font3 style=" line-height:15.12pt;"><b>Example 12-4  </b><span class=font43><i>Cisco ASA CLI Site-to-Site VPN Configuration</i></span></span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:15.12pt;">!IKE Enabled on the outside interface</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>crypto isakmp enable outside</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 262.56pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!IKE Policy (phase one policy) crypto isakmp policy 10</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">authentication pre-share</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">encryption aes-256</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">hash sha</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">group 2</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">lifetime 86400</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!Phase 2 policy and crypto map configuration</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">crypto map outside_map 20 match address outside_20_cryptomap</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">crypto map outside_map 20 set peer 209.165.200.231</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">crypto map outside_map 20 set transform-set ESP-AES-256-SHA</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 188.64pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.84pt;">!Crypto map is applied to the outside interface crypto map outside_map interface outside</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:100.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.32pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 255.36pt; text-align:justify;"><span class=font4>Case Study of a Medium-Sized Enterprise <b>389</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:184.80pt;">
<div class=paragraph style=" padding:0.00pt 178.32pt 0.00pt 98.16pt; text-align:left; text-indent:-61.92pt;"><span class=font3 style=" line-height:13.92pt;"><a name="bookmark95"><b>E</b></a><b>xample 12-4  </b><span class=font43><i>Cisco ASA CLI Site-to-Site VPN Configuration (Continued) </i></span><span class=font23><sub>!</sub></span></span></div>
<div class=paragraph style=" padding:0.00pt 64.56pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.64pt;">!ACL used by the crypto map to define the traffic that will be encrypted access-list outside_20_cryptomap extended permit ip 10.10.10.0 255.255.255.0 object-group atlanta-office</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:8.64pt;"><sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 154.56pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!Tunnel group configuration for the site-to-site tunnel tunnel-group 209.165.200.231 type ipsec-l2l tunnel-group 209.165.200.231 ipsec-attributes pre-shared-key *</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 189.12pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">'Bypassing NAT for the VPN tunnel traffic nat (inside) 0 access-list inside_nat0_outbound</span></div>
<div class=paragraph style=" padding:0.96pt 64.56pt 0.00pt 105.60pt; text-align:left; text-indent:-8.40pt;"><span class=font23 style=" line-height:8.16pt;">access-list inside_nat0_outbound extended permit ip 10.10.10.0 255.255.255.0 object-group atlanta-office</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;"><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 150.24pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">'Object Group defining the Atlanta office remote network object-group network atlanta-office network-object 10.100.10.0 255.255.255.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:276.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark86"><b>Case Study of a Medium-Sized Enterprise</b></a></span></div>
<div class=paragraph style=" padding:3.84pt 39.12pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Company-B is a medium-sized software development company based in Chicago, Illinois. This organization has 1200 employees and 75 contractors at a call center in a partner office (Partner-A). Figure 12-50 illustrates a high-level overview of the Chicago office for Company-B.</span></div>
<div class=paragraph style=" padding:6.24pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Two routers (R1 and R2) reside at the Internet Edge followed by two Cisco ASAs with the Advanced Inspection and Prevention Security Services Module (AIP-SSM). The AIP-SSM provides intrusion prevention system (IPS) functionality. Web, e-mail, and DNS servers reside at a DMZ network. A Cisco Secure Monitoring, Analysis, and Response System (CS-MARS), a Cisco Secure Access Control Server (ACS), and a Simple Network Management Protocol (SNMP) server reside in the management network.</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>Company-B has three major user groups in the Chicago office:</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Sales</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Engineering</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Finance</span></div>
<div class=paragraph style=" padding:2.40pt 42.96pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Company-B's security manager has learned the techniques and methodologies discussed earlier on this book. The security manager develops a strategic plan to implement best practices to increase the security of their network infrastructure. The following sections include several tasks that the security manager of Company-B completes to increase the security of the network and its components.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:90.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>390   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-50 </b><span class=font43><i>High-Level Overview of Company-B Chicago Office</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:358.56pt; height:478.32pt; padding:0.00pt 64.32pt 0.00pt 63.12pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-206.jpg" alt="" style=" width:358.56pt; height:478.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:82.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:215.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:94.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:117.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 255.36pt; text-align:justify;"><span class=font4>Case Study of a Medium-Sized Enterprise <b>391</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:182.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Protecting the Internet Edge Routers</b></span></div>
<div class=paragraph style=" padding:3.36pt 43.44pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">On the Internet edge routers (R1 and R2), the administrator configures an ACL to deny packets from illegal sources (RFC 1918 and RFC 3330 addresses). In addition, this ACL denies traffic with source addresses belonging within the internal address space of Company-B (that is, 209.165.201.0/24) that is entering from an external source. Example 12-5 shows the ACL configuration.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-5 </b><span class=font43><i>Antispoofing ACL</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 167.28pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list 100 deny ip host 0.0.0.0 any access-list 100 deny ip 127.0.0.0 0.255.255.255 any access-list 100 deny ip 192.0.2.0 0.0.0.255 any access-list 100 deny ip 224.0.0.0 31.255.255.255 any access-list 100 deny ip 10.0.0.0 0.255.255.255 any access-list 100 deny ip 172.16.0.0 0.15.255.255 any access-list 100 deny ip 192.168.0.0 0.0.255.255 any access-list 100 deny ip any 209.165.201.0 0.0.0.255 access-list 100 permit ip any any</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.04pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left; text-indent:-54.24pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>In addition, the administrator performs a security audit using SDM and makes the necessary changes, as the Company-A administrator.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:58.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Configuring the AIP-SSM on the Cisco ASA</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Two Cisco ASAs protect the Chicago office internal network. The IP address configuration of both Cisco ASAs is illustrated in Figure 12-51.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-51  </b><span class=font43><i>Cisco ASAs at the Chicago Office</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="5" valign="top" style=" width:215.52pt;">
<div class=block style=" width:147.84pt; height:128.16pt; padding:0.00pt 0.00pt 0.00pt 67.68pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-207.jpg" alt="" style=" width:147.84pt; height:128.16pt;"></div>
</td>
<td class=cell colspan="2" valign="top" style=" width:123.12pt;">
<div class=block style=" width:123.12pt; height:24.96pt;">
<div class=paragraph style=" padding:11.76pt 108.72pt 0.00pt 0.00pt; text-align:left; text-indent:-9.60pt;"><span class=font1 style=" line-height:7.20pt;">SSM Management 10.200.30.3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:24.96pt;layout-flow:vertical-ideographic;">
</div>
</td>
<td class=cell valign="top" style=" width:117.36pt;">
<div class=block style=" width:117.36pt; height:24.96pt;">
<div class=paragraph style=" padding:12.24pt 67.92pt 0.00pt 9.60pt; text-align:left; text-indent:-9.60pt;"><span class=font1 style=" line-height:7.20pt;">SSM Management 10.200.30.4</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:123.12pt;">
<div class=block style=" width:123.12pt; height:17.28pt;">
<div class=paragraph style=" padding:3.60pt 6.72pt 0.00pt 94.08pt; text-align:justify;"><span class=font4>ASA-2</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:147.36pt;">
<div class=block style=" width:147.36pt; height:17.28pt;">
<div class=paragraph style=" padding:0.00pt 109.20pt 0.00pt 0.48pt; text-align:left;"><span class=font1 style=" line-height:7.20pt;">Outside 209.165.201.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:123.12pt;">
<div class=block style=" width:123.12pt; height:18.24pt;">
<div class=paragraph style=" padding:0.00pt 45.84pt 0.00pt 44.88pt; text-align:justify; text-indent:-1.68pt;"><span class=font1 style=" line-height:7.20pt;">Management 10.200.30.2</span></div>
</div>
</td>
<td class=cell colspan="2" rowspan="2" valign="top" style=" width:147.36pt;">
<div class=block style=" width:147.36pt; height:31.68pt;">
<div class=paragraph style=" padding:17.04pt 89.76pt 0.00pt 25.44pt; text-align:justify;"><span class=font4>AIP-SSM</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="2" valign="top" style=" width:94.08pt;">
<div class=block style=" width:94.08pt; height:67.68pt;">
<div class=paragraph style=" padding:13.20pt 0.00pt 0.00pt 23.04pt; text-align:center;"><span class=font1>DMZ</span></div>
<div class=paragraph style=" padding:1.68pt 20.16pt 0.00pt 43.44pt; text-align:justify;"><span class=font1>10.200.20.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.04pt;">
<div class=block style=" width:29.04pt; height:13.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:176.40pt;">
<div class=block style=" width:176.40pt; height:54.24pt;">
<div class=paragraph style=" padding:16.80pt 0.00pt 0.00pt 29.04pt; text-align:left;"><span class=font1>Inside</span></div>
<div class=paragraph style=" padding:1.44pt 116.16pt 0.00pt 29.76pt; text-align:justify;"><span class=font1>10.200.10.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:103.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:215.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:94.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:117.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:113.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:81.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:94.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:98.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:98.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4>392    Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:292.32pt;">
<div class=paragraph style=" padding:0.00pt 52.80pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The following are the IP addresses of each of the interfaces of the primary Cisco ASA (ASA-1):</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Outside: </b>209.165.201.1</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Inside: </b>10.200.10.1</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;DMZ: </b>10.200.20.1</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Management: </b>10.200.30.1</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;AIP-SSM Management interface: </b>10.200.30.3</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">The following are the IP addresses of each of the interfaces of the secondary Cisco ASA</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44>(ASA-2):</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Outside: </b>209.165.201.2</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Inside: </b>10.200.10.2</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;DMZ: </b>10.200.20.2</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Management: </b>10.200.30.2</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;AIP-SSM management interface: </b>10.200.30.4</span></div>
<div class=paragraph style=" padding:2.40pt 40.08pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The administrator configures the necessary access and address translation for internal services in a procedure that is similar to the steps you learned previously in this chapter. After performing these basic configuration steps, the security administrator initializes the AIP-SSM. To verify that the ASA-1 recognizes the AIP-SSM, the administrator uses the <b>show module </b>command, as shown in Example 12-6.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-6  </b><span class=font43><i>Output of the </i><b>show module </b><i>Command</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:289.44pt;">
<div class=block style=" width:289.44pt; height:16.08pt;">
<div class=paragraph style=" padding:0.00pt 82.08pt 0.00pt 96.96pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">companyB-ASA1# show module Mod Card Type</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:98.40pt;">
<div class=block style=" width:98.40pt; height:16.08pt;">
<div class=paragraph style=" padding:8.16pt 60.72pt 0.00pt 17.52pt; text-align:justify;"><span class=font23>Model</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:98.16pt;">
<div class=block style=" width:98.16pt; height:16.08pt;">
<div class=paragraph style=" padding:8.16pt 57.12pt 0.00pt 0.48pt; text-align:justify;"><span class=font23>Serial No.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:113.52pt;">
<div class=block style=" width:113.52pt; height:16.56pt;">
<div class=paragraph style=" padding:0.00pt 4.80pt 0.00pt 105.36pt; text-align:justify;"><span class=font23>0</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:274.32pt;">
<div class=block style=" width:274.32pt; height:16.56pt;">
<div class=paragraph style=" padding:0.00pt 39.36pt 0.00pt 0.24pt; text-align:justify;"><span class=font23>ASA 5520 Adaptive Security Appliance ASA5520-K8</span></div>
<div class=paragraph style=" padding:1.44pt 39.12pt 0.00pt 0.00pt; text-align:justify;"><span class=font23>ASA 5500 Series Security Services Module-10 ASA-SSM-10</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:98.16pt;">
<div class=block style=" width:98.16pt; height:16.56pt;">
<div class=paragraph style=" padding:0.00pt 51.60pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:9.84pt;">JMX1113L0Y4 JAB101502D9</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:195.36pt;">
<div class=block style=" width:195.36pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 9.60pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>Mod MAC Address Range</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:290.64pt;">
<div class=block style=" width:290.64pt; height:8.64pt;">
<div class=paragraph style=" padding:0.48pt 73.44pt 0.00pt 64.32pt; text-align:justify;"><span class=font23>Hw Version     Fw Version     Sw Version</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:113.52pt;">
<div class=block style=" width:113.52pt; height:21.36pt;">
<div class=paragraph style=" padding:0.48pt 4.80pt 0.00pt 105.36pt; text-align:justify;"><span class=font23>0</span></div>
</div>
</td>
<td class=cell colspan="2" rowspan="2" valign="top" style=" width:175.92pt;">
<div class=block style=" width:175.92pt; height:27.60pt;">
<div class=paragraph style=" padding:0.48pt 18.00pt 0.00pt 0.48pt; text-align:justify;"><span class=font23><a href="http://001a.6d7c.8c95">001a.6d7c.8c95</a> to <a href="http://001a.6d7c.8c99">001a.6d7c.8c99</a> 2.0</span></div>
<div class=paragraph style=" padding:0.96pt 17.76pt 0.00pt 0.48pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">0016.c79f.78c1 to 0016.c79f.78c1 1.0 SSM Application Name Status</span></div>
</div>
</td>
<td class=cell colspan="2" rowspan="2" valign="top" style=" width:196.56pt;">
<div class=block style=" width:196.56pt; height:27.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 26.16pt; text-align:left;"><span class=font23>1.0(11)2 8.0(2)</span></div>
<div class=paragraph style=" padding:0.72pt 68.88pt 0.00pt 30.24pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">1.0(10)0 6.0(2)E1 SSM Application Version</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:113.52pt;">
<div class=block style=" width:113.52pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 5.04pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>Mod</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:195.36pt;">
<div class=block style=" width:195.36pt; height:18.48pt;">
<div class=paragraph style=" padding:0.00pt 56.64pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.84pt;">1 IPS Mod Status</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:94.08pt;">
<div class=block style=" width:94.08pt; height:18.48pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 51.12pt; text-align:left;"><span class=font23>Up</span></div>
<div class=paragraph style=" padding:1.20pt 22.08pt 0.00pt 0.00pt; text-align:justify;"><span class=font23>Data Plane Status</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:196.56pt;">
<div class=block style=" width:196.56pt; height:18.48pt;">
<div class=paragraph style=" padding:0.48pt 134.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>6.0(2)E1</span></div>
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>Compatibility</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:195.36pt;">
<div class=block style=" width:195.36pt; height:18.24pt;">
<div class=paragraph style=" padding:0.00pt 56.64pt 0.00pt 113.52pt; text-align:justify;"><span class=font23>Up Sys</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 113.52pt; text-align:left;"><span class=font23>Up</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:290.64pt;">
<div class=block style=" width:290.64pt; height:18.24pt;">
<div class=paragraph style=" padding:0.00pt 231.60pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:10.32pt;">Not Applicable Up</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:65.28pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The highlighted lines show that the module is running IPS Software Version 6.0(2)E1 and that it is operational.</span></div>
<div class=paragraph style=" padding:6.24pt 44.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The administrator logs into ASA-1 via the CLI and connects to the AIP-SSM using the <b>session 1 </b>command. This puts him on the AIP-SSM CLI. To initialize the AIP-SSM, the administrator uses the <b>setup </b>command, as demonstrated in Example 12-7.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:40.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:113.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:81.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:94.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:98.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:98.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 255.36pt; text-align:justify;"><span class=font4>Case Study of a Medium-Sized Enterprise <b>393</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:508.56pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-7 </b><span class=font43><i>Initializing ASA-1 AIP-SSM</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">sensor# setup</span></div>
<div class=paragraph style=" padding:0.24pt 151.44pt 0.00pt 96.48pt; text-align:left; text-indent:18.72pt;"><span class=font23 style=" line-height:9.60pt;">— System Configuration Dialog — At any point you may enter a question mark '?' for help. Use ctrl-c to abort configuration dialog at any prompt. Default settings are in square brackets '[]'. Current Configuration: service host network-settings host-ip 10.1.9.201/24,10.1.9.1 host-name sensor telnet-option disabled ftp-timeout 300 login-banner-text exit</span></div>
<div class=paragraph style=" padding:0.00pt 312.96pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">time-zone-settings offset 0</span></div>
<div class=paragraph style=" padding:0.00pt 274.32pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">standard-time-zone-name UTC exit</span></div>
<div class=paragraph style=" padding:0.00pt 278.88pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">summertime-option disabled ntp-option disabled exit</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">service web-server</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">port 443</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">exit</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Current time: Mon May 14 18:26:51 2007</span></div>
<div class=paragraph style=" padding:0.24pt 137.28pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Setup Configuration last modified: Mon May 14 17:45:30 2007 Continue with configuration dialog?[yes]: yes Enter host name[sensor]: companyB-AIP-SSMI</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Enter IP interface[10.1.9.201/24,10.1.9.1]: 10.200.30.3/24,10.200.30.1</span></div>
<div class=paragraph style=" padding:0.24pt 232.56pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Enter telnet-server status[disabled]: Enter web-server port[443]: Modify current access list?[no]: yes Current access list entries:</span></div>
<div class=paragraph style=" padding:0.24pt 295.68pt 0.00pt 97.20pt; text-align:left; text-indent:8.16pt;"><span class=font23 style=" line-height:9.60pt;">No entries Permit: 10.200.30.0/24 Permit:</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Modify system clock settings?[no]: no</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Modify virtual sensor &quot;vs0&quot; configuration?[no]: yes</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Current interface configuration</span></div>
<div class=paragraph style=" padding:0.24pt 231.60pt 0.00pt 105.12pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Command control: GigabitEthernet0/0 Unused:</span></div>
<div class=paragraph style=" padding:0.24pt 297.12pt 0.00pt 105.36pt; text-align:left; text-indent:8.40pt;"><span class=font23 style=" line-height:9.60pt;">GigabitEthernet0/1 Monitored: None</span></div>
<div class=paragraph style=" padding:0.00pt 244.80pt 0.00pt 96.48pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Add Monitored interfaces?[no]: yes Interface[]: GigabitEthernet0/1 Interface[]:</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">The following configuration was entered.</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">service host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">network-settings</span></div>
<div class=paragraph style=" padding:1.44pt 38.88pt 0.00pt 0.00pt; text-align:right;"><span class=font43><i>continues</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:67.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>394   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:277.44pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-7 </b><span class=font43><i>Initializing ASA-1 AIP-SSM (Continued)</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 245.76pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">host-ip 10.200.30.3/24,10.200.30.1 host-name companyB-AIP-SSM1 telnet-option disabled access-list 10.200.30.0/24 ftp-timeout 300 no login-banner-text exit</span></div>
<div class=paragraph style=" padding:0.24pt 313.20pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">time-zone-settings offset 0</span></div>
<div class=paragraph style=" padding:0.24pt 274.56pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">standard-time-zone-name UTC exit</span></div>
<div class=paragraph style=" padding:0.24pt 279.12pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">summertime-option disabled ntp-option disabled exit</span></div>
<div class=paragraph style=" padding:0.00pt 313.20pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">service web-server port 443 exit</span></div>
<div class=paragraph style=" padding:0.24pt 291.60pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">service analysis-engine virtual-sensor vs0</span></div>
<div class=paragraph style=" padding:0.24pt 232.80pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">physical-interface GigabitEthernet0/1 exit exit</span></div>
<div class=paragraph style=" padding:0.00pt 151.44pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">[0] Go to the command prompt without saving this config. [1] Return back to the setup without saving this config. [2] Save this configuration and exit setup. Enter your selection[2]: 2 Configuration Saved.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:144.24pt;">
<div class=paragraph style=" padding:0.00pt 49.20pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Example 12-7, the administrator configures the AIP-SSM hostname, IP address, and subnet mask of the management interface, in addition to the default gateway. The administrator allows management access only from machines in the 10.200.30.0/24 management network. Also, the GigabitEthernet0/1 interface is enabled for traffic inspection. Finally, the administrator saves the configuration and exits the interactive setup session.</span></div>
<div class=paragraph style=" padding:22.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Configuring Active-Standby Failover on the Cisco ASA</b></span></div>
<div class=paragraph style=" padding:3.12pt 58.08pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Maintaining appropriate redundancy mechanisms within infrastructure devices is extremely important for any organization. The Cisco ASA supports active-active and active-standby failover.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:25.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:59.28pt;">
<div class=paragraph style=" padding:0.00pt 42.96pt 0.00pt 89.76pt; text-align:left; text-indent:-54.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>When the active unit fails, it changes to the standby state while the standby unit changes to the active state. The unit that becomes active takes ownership of the IP addresses and MAC addresses of the failed unit. The unit that is now in standby state takes over the standby IP addresses and MAC addresses. Because network devices see no change in the MAC-to-IP address pairing, no ARP entries change or time out anywhere on the network.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:52.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 255.36pt; text-align:justify;"><span class=font4>Case Study of a Medium-Sized Enterprise <b>395</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:189.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">When a pair of Cisco ASAs is configured in active-active failover mode, both appliances are actively passing traffic at the same time. In contrast, when configured in active-standby mode, the primary appliance is the active one and the secondary appliance is in standby and does not pass traffic. After the primary fails, the secondary takes over and begins to pass traffic.</span></div>
<div class=paragraph style=" padding:5.76pt 36.96pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The network security team of Company-B evaluates both options. They decide to implement active-standby failover because, for active-active to work, the appliances must be configured in multicontext mode. Active-active requires a minimum of two security contexts on each appliance. Company-B has a site-to-site VPN tunnel to a business partner (Partner-A). The Cisco ASA does not support VPN when configured in multicontext mode.</span></div>
<div class=paragraph style=" padding:6.96pt 39.36pt 0.00pt 90.00pt; text-align:justify;"><span class=font44>The following are the steps taken to configure active-standby failover on the Cisco ASAs.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font4><b>Step 1 </b><span class=font44>Log in to the Cisco ASA using ASDM.</span></span></div>
<div class=paragraph style=" padding:6.48pt 77.52pt 0.00pt 126.24pt; text-align:left; text-indent:-36.48pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 2  </b><span class=font44>On the main toolbar, click <b>Wizards </b>and choose <b>High Availability and Scalability Wizard, </b>as illustrated in Figure 12-52.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 192.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-52 </b><span class=font43><i>Launching the High Availability and Scalability Wizard</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 382.32pt; text-align:left;"><span class=font45>16</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:335.52pt; height:223.44pt; padding:0.00pt 75.12pt 0.00pt 75.36pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-208.jpg" alt="" style=" width:335.52pt; height:242.88pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 102.48pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 3  </b><span class=font44>The screen shown in Figure 12-53 is displayed. Click <b>Configure Active/Standby failover.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:75.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.56pt;">
<div class=paragraph style=" padding:0.00pt 318.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>396   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:245.28pt; padding:0.00pt 88.32pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-209.jpg" alt="" style=" width:361.20pt; height:245.28pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:213.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 4  </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:7.20pt 74.88pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 5  </b><span class=font44>Enter the IP address of the secondary appliance, as shown in Figure 12-54. The IP address of the secondary appliance management interface is <b>10.200.30.2 </b>in this case. ASDM completes several compatibility and connectivity checks on the secondary appliance. These steps are listed within the ASDM screen shown in Figure 12-54. If successful, ASDM allows you to proceed to the next step. However, if issues exist, ASDM marks each check that failed. You must fix any errors before proceeding further.</span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 6  </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:7.20pt 77.52pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 7  </b><span class=font44>The screen shown in Figure 12-55 is displayed. This screen allows you to configure a dedicated interface for failover communication between the two appliances. Choose an available interface from the drop-down menu. In this case, the interface selected is <b>GigabitEthernet0/3.</b></span></span></div>
<div class=paragraph style=" padding:6.24pt 78.24pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 8  </b><span class=font44>Enter a name for the failover interface. In this example, the interface is called <b>failover </b>for simplicity. This is an arbitrarily name.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:94.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 255.36pt; text-align:justify;"><span class=font4>Case Study of a Medium-Sized Enterprise <b>397</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 203.28pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-54 </b><span class=font43><i>Failover Peer Connectivity and Compatibility Check</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:310.08pt; height:229.68pt; padding:0.00pt 88.08pt 0.00pt 87.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-210.jpg" alt="" style=" width:310.08pt; height:229.68pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:245.28pt; padding:0.00pt 88.32pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-211.jpg" alt="" style=" width:361.20pt; height:245.28pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:63.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>398   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:299.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 9  </b><span class=font44>Assign an IP address for this interface, in addition to a standby IP</span></span></div>
<div class=paragraph style=" padding:0.96pt 74.88pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">address, as shown in Figure 12-55. In this example, the active IP address is <b>10.200.40.1, </b>and the secondary is <b>10.200.40.2.</b></span></div>
<div class=paragraph style=" padding:6.24pt 78.48pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 10 </b><span class=font44>Configure a subnet mask for this interface. A 30-bit <b>(255.255.255.252) </b>subnet mask is configured in this example.</span></span></div>
<div class=paragraph style=" padding:5.76pt 74.16pt 0.00pt 125.52pt; text-align:justify; text-indent:-35.28pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 11 </b><span class=font44>You can optionally encrypt the failover communication data exchanged by both appliances. To enable encryption, select the <b>Use 32 hexadecimal character key </b>option under <b>Communication Encryption.</b></span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 12 </b><span class=font44>Enter a 32 hexadecimal character key.</span></span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 13 </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>Step 14 </b><span class=font44>You can configure stateful failover to maintain connection status,</span></span></div>
<div class=paragraph style=" padding:0.00pt 72.72pt 0.00pt 125.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">translation, and other information on the standby appliance to avoid interruption of services when a failover occurs. You can configure a dedicated interface or use the previously configured failover interface for this communication. On busy networks where numerous connections are built and torn down at a fast pace, a dedicated interface is suggested. In this case, all other interfaces on the Cisco ASAs are used for other purposes, and the stateful failover traffic of Company-B does not present an oversubscription risk based on tests that the administrator performed in the lab prior to deployment. The administrator configures the failover LAN link interface as the stateful failover link, as shown in Figure 12-56.</span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-56 </b><span class=font43><i>Configuring the Stateful Failover Link</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:303.36pt; height:225.12pt; padding:0.00pt 91.44pt 0.00pt 91.20pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-212.jpg" alt="" style=" width:303.36pt; height:225.12pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 255.36pt; text-align:justify;"><span class=font4>Case Study of a Medium-Sized Enterprise <b>399</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:42.96pt;">
<div class=paragraph style=" padding:0.00pt 74.16pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 15 </b><span class=font44>You must configure a standby IP address for each interface that is enabled on the Cisco ASA. The standby appliance uses these IP addresses. The screen shown in Figure 12-57 allows you to configure the standby IP address for each interface.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 255.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-57 </b><span class=font43><i>Configuring the Standby IP Addresses</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:300.48pt; height:222.72pt; padding:0.00pt 92.88pt 0.00pt 92.64pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-213.jpg" alt="" style=" width:300.48pt; height:222.72pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:193.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 16 </b><span class=font44>Click </span><b>Next.</b></span></div>
<div class=paragraph style=" padding:6.96pt 88.80pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 17 </b><span class=font44>A summary screen showing the configuration items to be sent to the security appliance is displayed. Click </span><b>Finish </b><span class=font44>to apply the changes.</span></span></div>
<div class=paragraph style=" padding:4.56pt 104.64pt 0.00pt 36.24pt; text-align:left; text-indent:53.52pt;"><span class=font44 style=" line-height:15.12pt;">Example 12-8 includes the CLI commands sent to the primary appliance. <span class=font3><b>Example 12-8 </b></span><span class=font43><i>Failover Configuration on the Primary ASA </i></span><span class=font23>failover</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.48pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">failover lan unit primary</span></div>
<div class=paragraph style=" padding:0.24pt 175.68pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">failover lan interface failover GigabitEthernet0/3 failover key *****</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">failover link failover GigabitEthernet0/3</span></div>
<div class=paragraph style=" padding:0.00pt 55.92pt 0.00pt 96.72pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">failover interface ip failover 10.200.40.1 255.255.255.252 standby 10.200.40.2 interface GigabitEthernet0/3</span></div>
<div class=paragraph style=" padding:0.00pt 214.32pt 0.00pt 96.96pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">description LAN/STATE Failover Interface monitor-interface dmz monitor-interface inside monitor-interface outside monitor-interface management</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:65.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.00pt 0.00pt 36.24pt; text-align:justify;"><span class=font4><b>400   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:97.68pt;">
<div class=paragraph style=" padding:0.00pt 95.76pt 0.00pt 36.24pt; text-align:left; text-indent:53.52pt;"><span class=font44 style=" line-height:15.12pt;">Example 12-9 includes the CLI commands sent to the secondary appliance. <span class=font3><b>Example 12-9 </b></span><span class=font43><i>Failover Configuration on the Secondary ASA </i></span><span class=font23>failover</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">failover lan unit secondary</span></div>
<div class=paragraph style=" padding:0.24pt 175.92pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">failover lan interface failover GigabitEthernet0/3 failover key *****</span></div>
<div class=paragraph style=" padding:0.24pt 55.92pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">failover interface ip failover 10.200.40.1 255.255.255.252 standby 10.200.40.2 interface GigabitEthernet0/3 no shutdown</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:80.16pt;">
<div class=paragraph style=" padding:0.00pt 65.04pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">You will see the message shown in Example 12-10 after the secondary appliance is configured and the configuration replication is performed.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-10 </b><span class=font43><i>Failover Configuration Replication Confirmation</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">companyB-ASA1#..</span></div>
<div class=paragraph style=" padding:0.00pt 155.76pt 0.00pt 96.96pt; text-align:left; text-indent:34.32pt;"><span class=font23 style=" line-height:9.60pt;">Detected an Active mate Beginning configuration replication from mate. companyB-ASA1# End configuration replication from mate.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:133.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Configuring AAA on the Infrastructure Devices</b></span></div>
<div class=paragraph style=" padding:2.88pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The network administrator configures authentication, authorization, and accounting (AAA) for administrative access to all routers within the network. The network administrator uses command authorization to enforce which commands users can invoke and execute in the routers. Example 12-11 shows a AAA configuration template used for all routers within the organization:</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-11 </b><span class=font43><i>AAA Configuration on Routers</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">aaa new-model</span></div>
<div class=paragraph style=" padding:0.24pt 167.52pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">aaa authentication login default group tacacs+ local tacacs-server host 172.18.85.181 tacacs-server key 1qaz2wsx</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:113.52pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The <b>aaa new-model </b>command enables the AAA security services. The <b>aaa authentication </b>command defines the default method list. Incoming logins on all interfaces (by default) use TACACS+ for authentication. If no TACACS+ server responds, the network access server uses the information contained in the local username database for authentication. The <b>tacacs-server host </b>command identifies the TACACS+ server as having an IP address of <b>172.18.85.181. </b>The <b>tacacs-server </b>key command defines the shared encryption key to be <b>1qaz2wsx.</b></span></div>
<div class=paragraph style=" padding:6.24pt 39.12pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The administrator also configures AAA on the Cisco ASAs for Telnet, Secure Shell (SSH), HTTPS, and serial console access. The commands used are shown in Example 12-12.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 289.68pt; text-align:justify;"><span class=font4>Case Study of a Large Enterprise <b>401</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:212.88pt;">
<div class=paragraph style=" padding:0.00pt 44.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">In this example, authentication is performed using an external TACACS+ server (that is, Cisco Secure ACS).</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><a name="bookmark96"><b>E</b></a><b>xample 12-12 </b><span class=font43><i>Cisco ASA AAA Configuration</i></span></span></div>
<div class=paragraph style=" padding:6.72pt 55.92pt 0.00pt 105.36pt; text-align:left; text-indent:-7.20pt;"><span class=font23 style=" line-height:8.16pt;">!The following commands define a TACACS+ server and limit the number of failed attempts to 4.The server group name is svrgrp</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">!</span></div>
<div class=paragraph style=" padding:2.40pt 244.56pt 0.00pt 101.28pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">aaa-server svrgrp protocol tacacs+ max-failed-attempts 4</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:8.64pt;">!The TACACS+ server (172.18.85.101) and a shared secret (1qaz2wsx) are defined. The</span></div>
<div class=paragraph style=" padding:0.00pt 154.56pt 0.00pt 96.96pt; text-align:left; text-indent:8.40pt;"><span class=font23 style=" line-height:8.64pt;">timeout is set to 5 seconds. aaa-server svrgrp host 172.18.85.101 1qaz2wsx timeout 5 <sub>!</sub></span></div>
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>!Telnet authentication</span></div>
<div class=paragraph style=" padding:1.20pt 218.64pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.40pt;">aaa authentication telnet console svrgrp <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>!Serial console port authentication</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>aaa authentication serial console svrgrp</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 210.24pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!HTTPS authentication for ASDM connections aaa authentication secure-http-client</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:164.64pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Cisco Secure ACS is used as the TACACS+ server. The following steps are taken to add the routers and the Cisco ASAs as authentication clients on Cisco Secure ACS:</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 1  </b><span class=font44>Log in to the Cisco Secure ACS web admin console.</span></span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>Step 2  </b><span class=font44>Choose <b>Network Configuration </b>on the left, and click <b>Add Entry </b>to add</span></span></div>
<div class=paragraph style=" padding:0.24pt 100.08pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">an entry for the Cisco ASAs or routers in either the TACACS+ or RADIUS server database.</span></div>
<div class=paragraph style=" padding:6.00pt 90.48pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 3  </b><span class=font44>Choose the server database according to the routers and Cisco ASA configurations. Because TACACS+ is used in this example, choose <b>TACACS+ (Cisco IOS) </b>under the <b>Authenticate Using </b>drop-down menu.</span></span></div>
<div class=paragraph style=" padding:6.24pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 4 </b><span class=font44>Configure the shared key. This key is used for authentication between the authentication client (router or Cisco ASA) and Cisco Secure ACS.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:78.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark86"><b>Case Study of a Large Enterprise</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 36.96pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Company-C is a large enterprise that offers numerous information technology products and services. Over the past few years, this company has been growing at a fast pace. Recently, Company-C acquired Company-A and Company-B. The Raleigh and Atlanta offices of Company-A became branch offices, and the Chicago office of Company-B became a regional office, as illustrated in Figure 12-58. The headquarters is located in New York City.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:72.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:658.80pt; height:486.00pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt;">
<div class=block style=" width:658.80pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt;">
<div class=block style=" width:544.32pt; height:375.12pt; padding:0.00pt 36.96pt 0.00pt 77.52pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-214.jpg" alt="" style=" width:544.32pt; height:375.12pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt;">
<div class=block style=" width:658.80pt; height:2.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt;">
<div class=block style=" width:658.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 329.04pt 0.00pt 289.92pt; text-align:justify;"><span class=font3>Call Center</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt;">
<div class=block style=" width:658.80pt; height:65.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 289.68pt; text-align:justify;"><span class=font4>Case Study of a Large Enterprise <b>403</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:233.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following is a high-level explanation of the New York office topology:</span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;At the Internet edge, a pair of Cisco Catalyst 6500 switches is deployed with FWSMs.</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;A cluster of Cisco ASAs is configured for IPsec- and SSL-based remote access VPN.</span></div>
<div class=paragraph style=" padding:4.80pt 38.64pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Cisco routers are configured to terminate IPsec site-to-site VPN tunnels to the branch offices and the regional office.</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;The user population includes the following:</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 118.80pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">—&nbsp;A call center of more than 100 customer service representatives</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 118.80pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">—&nbsp;The executive floor</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 118.80pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">—&nbsp;Sales representatives</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 118.80pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">—&nbsp;Engineering</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 118.80pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">—&nbsp;Finance</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;A large data center is also located at the New York office.</span></div>
<div class=paragraph style=" padding:1.92pt 37.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">With the dramatic growth, Company-C staff members initiate several corporate initiatives and projects to increase the security of the network. The following sections include information about different techniques and methodologies that Company-C staff members use.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:116.88pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 36.48pt; text-align:justify;"><span class=font8><b>Creating a New Computer Security Incident Response Team (CSIRT)</b></span></div>
<div class=paragraph style=" padding:3.12pt 65.76pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Company-C management starts the process to create a Computer Security Incident Response Team (CSIRT). The CSIRT will comprise staff members from different departments within an organization:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Global information technology (IT)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Information Security (InfoSec)</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Operation Security (OpSec)</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Business analysis team</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:106.32pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 36.00pt; text-align:justify;"><span class=font4 style=" line-height:11.76pt;"><b>TIP&nbsp;</b><span class=font44>In some large organizations, the CSIRT may be a full-time staff. Deciding whether the staff</span></span></div>
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">members should be full-time or not depends on your organizational needs and budget. What is important is to clearly identify who needs to be involved at each level of the CSIRT planning, implementation, and operation. For instance, one of the most challenging tasks is the process of identifying the staff members who will be performing security incident response functions.</span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In addition, you must identify which internal and external organizations will interface with the CSIRT. Evangelize and communicate the CSIRT responsibilities accordingly with these entities.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:61.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.24pt; text-align:justify;"><span class=font4><b>404   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:43.20pt;">
<div class=paragraph style=" padding:0.00pt 39.36pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The new CSIRT team develops and documents roles and responsibilities for all CSIRT members and their functions. Each member has a different background and qualifications. These roles and responsibilities are assigned based on the experience and strengths of each member.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:25.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:179.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Creating New Security Policies</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The executive team of Company-C also delegates the tasks of creating new security policies within the organization. Since Company-C acquired Company-A and Company-B new policies need to be defined and followed. The following are the new policies that are created:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Physical security</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Perimeter security</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Device security</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Remote access VPN</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Patch management</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Change management</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Internet access policy</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:158.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font6>Physical Security Policy</span></div>
<div class=paragraph style=" padding:4.08pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The physical security policy is created to protect and preserve information, physical assets, and human assets by reducing the exposure to various physical threats. A new employee badge system is deployed to deny unauthorized access and to track authorized entry. Card access and monitoring devices will be used to ensure that sensitive information is not compromised and access to control office work areas is monitored. The building facility manager will ensure that appropriate monitoring devices allow monitoring of primary accesses and that each individual is screened for access. In addition, a video surveillance system must be implanted and appropriately managed. This video system should function with an existing Ethernet switched environment, and it should reduce the complexity while lowering the cost of deploying video surveillance. It also provides video surveillance system owners with the flexibility to design solutions tailored to their unique requirements.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font6>Perimeter Security Policy</span></div>
<div class=paragraph style=" padding:4.32pt 39.12pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The company already has perimeter configuration guidelines that are implemented within the organization. However, these guidelines were never documented in an organized fashion. The staff members at Company-C create a detailed perimeter security policy.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 289.68pt; text-align:justify;"><span class=font4>Case Study of a Large Enterprise <b>405</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:500.16pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font6>Device Security Policy</span></div>
<div class=paragraph style=" padding:4.08pt 41.04pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Just as with perimeter security, the company already has device configuration guidelines that are implemented within the organization. However, these guidelines were never documented in an organized fashion. The staff members at Company-C create a detailed device security policy. These devices include infrastructure devices such as routers, switches, and other equipment.</span></div>
<div class=paragraph style=" padding:27.60pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font6>Remote Access VPN Policy</span></div>
<div class=paragraph style=" padding:4.32pt 37.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The remote access VPN policy defines the appropriate use of remote access VPN (including IPsec and SSL-based remote access VPNs). The policies include the process of how employees request remote access VPN and how administrators create, modify, and delete remote access accounts. In this case, Company-C uses generic token cards with one-time passwords (OTP) for remote access. When Company-C staff members start developing the remote access VPN policy, they are trying to clarify answers to the following questions:</span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Does a remote access security policy exist?</span></div>
<div class=paragraph style=" padding:5.04pt 39.60pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Is the security policy frequently reviewed and revised to reflect technology changes, outmoded approaches, or new product or service offerings affecting company/ customer relationships and system interaction?</span></div>
<div class=paragraph style=" padding:4.08pt 38.16pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Does the remote access policy specify guidelines for the selection and implementation mechanisms that control access among authorized users and corporate computers and networks?</span></div>
<div class=paragraph style=" padding:4.08pt 51.84pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Does the remote access policy conform to all existing corporate communications guidelines?</span></div>
<div class=paragraph style=" padding:4.32pt 38.64pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Does the remote access policy address the physical protection of the communications medium, devices, computers, and data storage at the remote site?</span></div>
<div class=paragraph style=" padding:4.08pt 39.60pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Does the security policy require the classification of the functions, applications, and data to determine the levels of security needed to protect the asset?</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Does a policy exist to obtain access to important proprietary information at remote</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 111.84pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">sites?</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Does a policy exist for reporting unauthorized activity?</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Does a policy exist that defines appropriate personal use of company equipment?</span></div>
<div class=paragraph style=" padding:1.68pt 50.40pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Do remote access users have to sign a form stating they know and understand the remote access policies?</span></div>
<div class=paragraph style=" padding:4.08pt 38.88pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Is there a formal, complete, and tested disaster recovery plan in place for the remote sites?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:79.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.24pt; text-align:justify;"><span class=font4><b>406    </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:185.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font6>Patch Management Policy</span></div>
<div class=paragraph style=" padding:3.84pt 38.16pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The patch management policy establishes requirements for a secure patch management program for all Company-C networks to prevent disruption of service and unauthorized use because of vulnerabilities in unpatched systems. The patch management program shall be used to create a consistently configured environment that ensures security against known vulnerabilities in operating systems and application software. A key component of patch management is the intake and selection of information regarding both security issues and patch release. The patch cycle shall be used to facilitate the application of standard patch releases and updates. This cycle can be time or event based. For example, the schedule can mandate that system updates occur quarterly, or a cycle may be driven by the release of service packs or maintenance releases. Testing of software patches is crucial. Company-C creates a patch test process within this policy. After a patch has been determined valid, it shall be placed in a test environment that closely mirrors the production environment. Critical applications and supported operating platforms must be fully accounted for while testing the patch infrastructure.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:74.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Change Management Policy</span></div>
<div class=paragraph style=" padding:3.84pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Change management practices are applied to the patch management process and any other configuration or system changes within the whole infrastructure. After a configuration or a system has been identified for change, a request-for-change must be submitted, and the configuration should be modified according to the procedures that the change management process has established.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:25.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:101.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font6>Internet Usage Policy</span></div>
<div class=paragraph style=" padding:3.84pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The Internet usage policy allows for reasonable use of the Internet by outlining the permitted and prohibited behaviors and defining violations. This policy should apply to all Internet users who access the Internet through the computing or networking resources. This includes permanent, full-time, and part-time employees; contract workers; temporary agency workers; business partners; and vendors. The Internet users of your organization are expected to be familiar with and to comply with this policy, which should also require the use of common sense and good judgment while using Internet services.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:51.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Deploying IPsec Remote Access VPN</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Company-C deploys a cluster of Cisco ASAs to provide IPsec remote access VPN services. Figure 12-59 illustrates the topology listing the Cisco ASAs and their corresponding IP addresses.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:89.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:289.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:196.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 289.68pt; text-align:justify;"><span class=font4>Case Study of a Large Enterprise <span class=font44><b>407</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 275.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-59 </b><span class=font43><i>Remote Access VPN Cisco ASAs</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:197.28pt; height:85.92pt; padding:0.00pt 169.68pt 0.00pt 119.04pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-215.jpg" alt="" style=" width:197.28pt; height:85.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.80pt;">
<div class=paragraph style=" padding:0.00pt 308.64pt 0.00pt 115.68pt; text-align:justify; text-indent:3.60pt;"><span class=font4 style=" line-height:9.60pt;">Remote Access VPN ASA Cluster</span></div>
<div class=paragraph style=" padding:0.72pt 305.28pt 0.00pt 111.12pt; text-align:justify;"><span class=font1>Virtual IP 209.165.202.131</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:289.68pt;">
<div class=block style=" width:289.68pt; height:26.16pt;">
<div class=paragraph style=" padding:0.24pt 93.84pt 0.00pt 174.48pt; text-align:justify;"><span class=font4>ASA-1</span></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:196.32pt;">
<div class=block style=" width:196.32pt; height:45.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 25.92pt; text-align:left;"><span class=font4>ASA-2</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 9.36pt; text-align:left;"><span class=font14 style=" line-height:7.20pt;"><b><i>d</i></b></span></div>
<div class=paragraph style=" padding:2.16pt 108.72pt 0.00pt 10.80pt; text-align:left;"><span class=font1 style=" line-height:7.20pt;">Management IP: 10.250.30.2 Outside: 209.165.202.130 Inside: 10.250.10.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:289.68pt;">
<div class=block style=" width:289.68pt; height:19.20pt;">
<div class=paragraph style=" padding:0.00pt 78.48pt 0.00pt 134.40pt; text-align:right;"><span class=font1 style=" line-height:7.20pt;">Management IP: 10.250.30.1 Outside: 209.165.202.129 Inside: 10.250.10.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:72.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 212.16pt 0.00pt 239.04pt; text-align:justify;"><span class=font4>Corporate</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:51.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:107.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following are the IP addresses of each interface on the first Cisco ASA (ASA-1):</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Management interface: </b>10.250.30.1</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Inside interface: </b>10.250.10.1</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Outside interface: </b>209.165.202.129</span></div>
<div class=paragraph style=" padding:0.24pt 44.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:15.84pt;">The following are the IP addresses of each interface on the second Cisco ASA (ASA-2):</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Management interface: </b>10.250.30.2</span></div>
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Inside interface: </b>10.250.10.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph style=" padding:0.00pt 227.76pt 0.00pt 111.84pt; text-align:justify;"><span class=font44><b>Outside interface: </b>209.165.202.130</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:80.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:289.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:196.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.24pt; text-align:justify;"><span class=font4><b>408    </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The following sections demonstrate how the Cisco ASAs are configured for IPsec and SSL remote access VPN.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:142.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring IPsec Remote Access VPN</span></div>
<div class=paragraph style=" padding:4.08pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The administrator completes the following steps to configure IPsec remote access VPN on the Cisco ASAs:</span></div>
<div class=paragraph style=" padding:2.88pt 204.96pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 1   </b><span class=font44>Log in to the Cisco ASA using ASDM. </span><b>Step 2  </b><span class=font44>On the main menu, choose <b>Wizards. </b></span><b>Step 3  </b><span class=font44>Select the <b>IPsec VPN Wizard.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 4 </b><span class=font44>The IPsec VPN Wizard starts. Specify the tunnel type as shown in</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 125.76pt; text-align:left;"><span class=font44>Figure 12-60.</span></div>
<div class=paragraph style=" padding:11.04pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-60 </b><span class=font43><i>Configuring the Tunnel Type</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:309.84pt; height:229.68pt; padding:0.00pt 88.32pt 0.00pt 87.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-216.jpg" alt="" style=" width:309.84pt; height:229.68pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:63.12pt;">
<div class=paragraph style=" padding:0.00pt 74.40pt 0.00pt 125.76pt; text-align:justify; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 5 </b><span class=font44>All remote access VPN clients will be connecting to the outside interface. Choose the <b>outside </b>interface from the <b>VPN Tunnel Interface </b>drop-down menu, as shown in Figure 12-60.</span></span></div>
<div class=paragraph style=" padding:6.24pt 74.88pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 6 </b><span class=font44>Enable inbound IPsec sessions to bypass all configured ACLs, as shown in Figure 12-60.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:68.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 289.68pt; text-align:justify;"><span class=font4>Case Study of a Large Enterprise <b>409</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:71.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 7  </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:6.96pt 74.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 8  </b><span class=font44>The screen shown in Figure 12-61 is displayed. Under <b>VPN Client Type, </b>click <b>Cisco VPN Client, Release 3.x or higher, or other Easy VPN Remote product.</b></span></span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-61 </b><span class=font43><i>Remote Access VPN Client Type</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:309.60pt; height:229.68pt; padding:0.00pt 88.32pt 0.00pt 88.08pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:309.60pt; height:229.68pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:236.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt;">
<div class=block style=" width:73.20pt; height:20.64pt;">
<div class=paragraph style=" padding:11.04pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font24 style=" letter-spacing:-1.00pt;">i<span class=font4 style=" letter-spacing:0.00pt;"><b>'J'JU'JISi</b></span>'li</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:236.40pt;">
<div class=block style=" width:236.40pt; height:20.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt;">
<div class=block style=" width:73.20pt; height:29.28pt;">
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 12.96pt; text-align:left;"><span class=font25><b><i>Ш Щ</i></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:236.40pt;">
<div class=block style=" width:236.40pt; height:29.28pt;">
<div class=paragraph style=" padding:14.40pt 23.04pt 0.00pt 16.80pt; text-align:left;"><span class=font0 style=" line-height:6.24pt;">REmote <span class=font1>access users </span>of <span class=font1>various </span>types <span class=font1>can open </span>VPN tunnels to this ASA, Select the type <span class=font1>of </span>VPN client <span class=font1>for </span>this tunnel.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt;">
<div class=block style=" width:73.20pt; height:12.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:236.40pt;">
<div class=block style=" width:236.40pt; height:12.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt;">
<div class=block style=" width:73.20pt; height:13.68pt;">
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 16.56pt; text-align:left;"><span class=font43><i>'------&quot; W</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:236.40pt;">
<div class=block style=" width:236.40pt; height:13.68pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 16.32pt; text-align:left;"><span class=font0>VPN Client Type:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt;">
<div class=block style=" width:73.20pt; height:26.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 33.36pt; text-align:left;"><span class=font45>- <span class=font22><b><i>\</i></b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:236.40pt;">
<div class=block style=" width:236.40pt; height:26.64pt;">
<div class=paragraph style=" padding:2.16pt 107.52pt 0.00pt 35.28pt; text-align:left;"><span class=font1 style=" line-height:10.80pt;">(+) Cisco: <span class=font0>VPN Client, Release З.к or hlaher,| or other Easy VPN Remote </span>product</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt;">
<div class=block style=" width:73.20pt; height:12.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:236.40pt;">
<div class=block style=" width:236.40pt; height:12.72pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 35.28pt; text-align:left;"><span class=font1>0 <span class=font0>Microsoft Windows client using </span><span class=font42><b>L2TP </b></span><span class=font0>over IPsec</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt;">
<div class=block style=" width:73.20pt; height:48.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:236.40pt;">
<div class=block style=" width:236.40pt; height:48.24pt;">
<div class=paragraph style=" padding:2.16pt 62.16pt 0.00pt 46.80pt; text-align:left;"><span class=font0 style=" line-height:6.48pt;">Specify the PPP authentication protocol. If a protocol is not specified on the remote <span class=font1>client, </span>do not specify it.</span></div>
<div class=paragraph style=" padding:0.00pt 21.12pt 0.00pt 46.80pt; text-align:left;"><span class=font0 style=" line-height:18.00pt;">? PAP    <span class=font1>0 </span>CHAP     <span class=font42><b>R7] MS</b></span>-CHAP<span class=font42><b>-V</b></span><b>1     ? </b><span class=font42><b>M5</b></span>-CHAP<span class=font42><b>-V2    </b></span>? EAP-PROXY Specify if the client will send tunnel group name a? - usernarne@tunnelgroup.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt;">
<div class=block style=" width:73.20pt; height:13.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:236.40pt;">
<div class=block style=" width:236.40pt; height:13.68pt;">
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 47.76pt; text-align:left;"><span class=font1>r~J <span class=font0>Client will send tunnel group name as username@tunnelgroup.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt;">
<div class=block style=" width:73.20pt; height:34.32pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:236.40pt;">
<div class=block style=" width:236.40pt; height:34.32pt;">
<div class=paragraph style=" padding:2.64pt 26.64pt 0.00pt 47.76pt; text-align:left;"><span class=font0 style=" line-height:6.24pt;">If рге-shared authentication is used <span class=font1>with </span>this option then DefaultRAGroup's pre-shared key and ppp authentication are also modified.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:309.60pt;">
<div class=block style=" width:309.60pt; height:18.48pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 184.80pt; text-align:left;"><span class=font0>| &lt;Back <b>|| Nnnts ]| </b>Finish | [ Cancel | | Help |</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:73.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:236.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:135.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 9 </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:7.20pt 75.12pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 10 </b><span class=font44>The screen shown in Figure 12-62 is displayed. Configure a preshared key and a VPN tunnel group, as shown in Figure 12-62. In this example, the preshared key is <b>1qaz2wsx, </b>and the tunnel group is <b>IPSEC-RA-GROUP.</b></span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 11 </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:7.20pt 83.04pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 12 </b><span class=font44>The screen shown in Figure 12-63 is displayed. In this example, the Cisco ASAs are configured for external authentication to a RADIUS server. The AAA server group name is <b>RADIUS-Server, </b>as shown in Figure 12-63.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:112.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.24pt; text-align:justify;"><span class=font4><b>410    </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 175.20pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-62 </b><span class=font43><i>VPN Client Authentication Method and Tunnel Group Name</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:310.08pt; height:229.92pt; padding:0.00pt 88.08pt 0.00pt 87.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-217.jpg" alt="" style=" width:310.08pt; height:229.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 315.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-63 </b><span class=font43><i>Client Authentication</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:316.80pt; height:229.92pt; padding:0.00pt 84.72pt 0.00pt 84.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-218.jpg" alt="" style=" width:316.80pt; height:229.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:69.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.68pt 0.00pt 289.68pt; text-align:justify;"><span class=font4>Case Study of a Large Enterprise <b>411</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph style=" padding:0.00pt 314.40pt 0.00pt 90.24pt; text-align:justify;"><span class=font4><b>Step 13 </b><span class=font44>Click <b>Next.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:53.28pt;">
<div class=paragraph style=" padding:0.00pt 74.88pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 14 </b><span class=font44>The screen shown in Figure 12-64 is displayed. This screen allows you to configure an IP address pool used for remote access VPN connections. Click <b>New </b>to add a new pool.</span></span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-64 </b><span class=font43><i>IPsec Remote Access VPN IP Address Pool</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:315.36pt; height:228.48pt; padding:0.00pt 85.20pt 0.00pt 85.44pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-219.jpg" alt="" style=" width:315.36pt; height:228.48pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:159.12pt;">
<div class=paragraph style=" padding:0.00pt 74.88pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 15 </b><span class=font44>Specify a name for the IP address pool. In this example, the name of the pool is <b>IPSec-Pool.</b></span></span></div>
<div class=paragraph style=" padding:6.24pt 75.36pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 16 </b><span class=font44>Configure the starting and ending IP addresses, in addition to a subnet mask. In this example, the address range in the pool is from <b>10.250.50.1 </b>to <b>10.250.50.254, </b>with a 24-bit subnet mask <b>(255.255.255.0).</b></span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 17 </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:7.20pt 74.40pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 18 </b><span class=font44>The screen shown in Figure 12-65 is displayed. This screen allows you to configure the primary and secondary DNS and WINS servers, in addition to the domain name. In this example, the primary DNS server is <b>172.18.124.12; </b>the secondary DNS server is <b>172.18.124.13; </b>the primary WINS server is <b>172.18.124.14; </b>and the secondary WINS server is <b>172.18.124.15. </b>The domain name is <a href="http://companyc.com"><b>companyc.com</b></a><b>.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:92.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.00pt 0.00pt 36.24pt; text-align:justify;"><span class=font4><b>412   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 258.00pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-65 </b><span class=font43><i>DNS and WINS Server Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:316.80pt; height:229.92pt; padding:0.00pt 84.72pt 0.00pt 84.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-220.jpg" alt="" style=" width:316.80pt; height:229.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:145.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 19 </b><span class=font44>Click </span><b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 82.32pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 20 </b><span class=font44>The screen shown in Figure 12-66 is displayed. This screen allows you to configure the IKE policy used by remote access VPN connections. In this example, the encryption algorithm used is </span><b>AES-256. SHA </b><span class=font44>is used for authentication, and the Diffie-Hellman (DH) group used is </span><b>5.</b></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 21 </b><span class=font44>Click </span><b>Next.</b></span></div>
<div class=paragraph style=" padding:7.20pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 22 </b><span class=font44>The screen shown in Figure 12-67 is displayed. This screen allows you to configure the IPsec encryption and authentication parameters. In this example, the encryption protocol used is </span><b>AES-256, </b><span class=font44>and </span><b>SHA </b><span class=font44>is used for IPsec Phase 2 authentication.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:162.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 289.68pt; text-align:justify;"><span class=font4>Case Study of a Large Enterprise <b>413</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:364.80pt; height:245.28pt; padding:0.00pt 84.72pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-221.jpg" alt="" style=" width:364.80pt; height:245.28pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:364.80pt; height:245.28pt; padding:0.00pt 84.72pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-222.jpg" alt="" style=" width:364.80pt; height:245.28pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:67.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.00pt 0.00pt 36.24pt; text-align:justify;"><span class=font4><b>414   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:95.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 23 </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:7.20pt 74.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 24 </b><span class=font44>The screen shown in Figure 12-68 is displayed. This screen allows you to configure the Cisco ASA to bypass NAT for remote access VPN connections. In this case, the inside network is selected <b>(10.250.10.0/24). </b>The inside 10.250.10.0/24 network will not be translated when communicating with remote access VPN clients.</span></span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-68 </b><span class=font43><i>Bypassing NAT and Configuring Split Tunneling</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:316.80pt; height:229.44pt; padding:0.00pt 84.72pt 0.00pt 84.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-223.jpg" alt="" style=" width:316.80pt; height:229.44pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:103.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>Step 25 </b><span class=font44>The screen shown in Figure 12-68 also allows you to configure split</span></span></div>
<div class=paragraph style=" padding:0.00pt 74.64pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">tunneling for remote access VPN connections. To enable split tunneling, select <b>Enable split tunneling </b>to let remote users have simultaneous encrypted access to the resources defined earlier, and unencrypted access to the Internet option.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 26 </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:6.72pt 87.12pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 27 </b><span class=font44>A summary screen appears. Click <b>Finish </b>to apply the changes to the Cisco ASA.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:126.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 289.68pt; text-align:justify;"><span class=font4>Case Study of a Large Enterprise <b>415</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:154.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring Load-Balancing</span></div>
<div class=paragraph style=" padding:3.60pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.24pt;">The administrator configures load-balancing on each security appliance. The following are the steps to configure load-balancing for remote access VPN.</span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 1   </b><span class=font44>Log in to the Cisco ASA using ASDM.</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 2  </b><span class=font44>On the main menu, choose <b>Wizards.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 3  </b><span class=font44>Choose the <b>High Availability and Scalability Wizard.</b></span></span></div>
<div class=paragraph style=" padding:3.12pt 74.64pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 4  </b><span class=font44>The High Availability and Scalability Wizard starts. The screen shown in Figure 12-69 is displayed. Click <b>Configure VPN Cluster Load Balancing, </b>as shown in Figure 12-69.</span></span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 12-69 </b><span class=font43><i>High Availability and Scalability Wizard</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:310.08pt; height:229.44pt; padding:0.00pt 88.08pt 0.00pt 87.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-224.jpg" alt="" style=" width:310.08pt; height:229.44pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:61.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 5 </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>Step 6  </b><span class=font44>The screen shown in Figure 12-70 is displayed. Enter the cluster IP</span></span></div>
<div class=paragraph style=" padding:0.24pt 74.40pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">address. The cluster IP address is the virtual address that VPN clients will use to connect to the cluster. In this example, the cluster IP address is <b>209.165.202.131.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:107.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.00pt 0.00pt 36.24pt; text-align:justify;"><span class=font4><b>416   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 233.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 12-70 </b><span class=font43><i>VPN Cluster Load-Balancing Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:310.08pt; height:229.92pt; padding:0.00pt 88.08pt 0.00pt 87.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-225.jpg" alt="" style=" width:310.08pt; height:229.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:207.12pt;">
<div class=paragraph style=" padding:0.00pt 76.56pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 7  </b><span class=font44>Enter a UDP port for load-balancing communication between all Cisco ASAs within the cluster. In this example, the default UDP port <b>(9023) </b>is used.</span></span></div>
<div class=paragraph style=" padding:6.24pt 81.60pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 8  </b><span class=font44>Optionally, you can encrypt all VPN load-balancing traffic. Check the <b>Enable IPsec encryption </b>option to enable encryption.</span></span></div>
<div class=paragraph style=" padding:6.24pt 86.40pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 9  </b><span class=font44>Configure a preshared secret. In this example, the preshared secret is <b>2wsx1qaz.</b></span></span></div>
<div class=paragraph style=" padding:5.76pt 74.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.24pt;"><b>Step 10 </b><span class=font44>The priority is set to <b>5. </b>The higher the priority, the more commonly that this ASA will become the master of the cluster.</span></span></div>
<div class=paragraph style=" padding:5.52pt 74.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 11 </b><span class=font44>The public interface is the <b>outside </b>interface in this example. The private interface is the <b>inside </b>interface, as shown in Figure 12-70.</span></span></div>
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 12 </b><span class=font44>Click <b>Next.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 13 </b><span class=font44>A summary screen is displayed.</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 14 </b><span class=font44>Click <b>Finish </b>to apply the configuration to the Cisco ASA.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:108.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 289.68pt; text-align:justify;"><span class=font4>Case Study of a Large Enterprise <b>417</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:475.44pt;">
<div class=paragraph style=" padding:0.00pt 68.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Example 12-13 shows the Cisco ASA remote access VPN and load-balancing CLI configuration.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 12-13 </b><span class=font43><i>Cisco ASA Remote Access VPN and Load-Balancing Configuration</i></span></span></div>
<div class=paragraph style=" padding:6.72pt 331.20pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">hostname asa-1 !</span></div>
<div class=paragraph style=" padding:2.40pt 150.48pt 0.00pt 101.28pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">interface GigabitEthernet0/0 description Outside interface connected to the Internet nameif outside security-level 0</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 209.165.202.129 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 132.48pt 0.00pt 101.28pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">interface GigabitEthernet0/1 description Inside interface connected to corporate network nameif inside security-level 100</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 10.250.10.1 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 291.60pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">interface Management0/0 nameif management security-level 0</span></div>
<div class=paragraph style=" padding:0.00pt 231.60pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 10.250.30.1 255.255.255.0 management-only</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!Split tunneling ACL</span></div>
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 96.96pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">access-list IPSEC-RA-GROUP_splitTunnelAcl standard permit 10.250.10.0 255.255.255.0 !ACL to bypass NAT for remote access VPN connections</span></div>
<div class=paragraph style=" padding:0.72pt 60.24pt 0.00pt 105.60pt; text-align:left; text-indent:-8.64pt;"><span class=font23 style=" line-height:8.16pt;">access-list inside_nat0_outbound extended permit ip 10.250.10.0 255.255.255.0 10.250.50.0 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 102.48pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;"><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 94.56pt 0.00pt 97.20pt; text-align:left; text-indent:5.28pt;"><span class=font23 style=" line-height:8.88pt;">!IP address pool for remote access VPN clients ip local pool IPSec-Pool 10.250.50.1-10.250.50.254 mask 255.255.255.0 <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>!NAT configuration</span></div>
<div class=paragraph style=" padding:0.96pt 188.88pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.40pt;">nat (inside) 0 access-list inside_nat0_outbound <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!RADIUS Configuration for remote access VPN authentication</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">aaa-server RADIUS-Server protocol radius</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">aaa-server RADIUS-Server (management) host 172.18.85.181</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">timeout 5</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">key cisco123</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!Crypto map configuration</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-256-</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">SHA</span></div>
<div class=paragraph style=" padding:0.24pt 68.64pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP crypto map outside_map interface outside</span></div>
<div class=paragraph style=" padding:1.68pt 38.64pt 0.00pt 0.00pt; text-align:right;"><span class=font43><i>continues</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:101.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.24pt; text-align:justify;"><span class=font4><b>418    </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:343.92pt;">
<div class=paragraph style=" padding:0.00pt 102.96pt 0.00pt 98.16pt; text-align:left; text-indent:-61.92pt;"><span class=font3 style=" line-height:13.92pt;"><b>Example 12-13 </b><span class=font43><i>Cisco ASA Remote Access VPN and Load-Balancing Configuration (Continued) </i></span><span class=font23><sub>!</sub></span></span></div>
<div class=paragraph style=" padding:0.00pt 218.64pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!ISAKMP enabled on the outside interface crypto isakmp enable outside !ISAKMP policy for Remote Access VPN crypto isakmp policy 10</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">authentication pre-share</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">encryption aes-256</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">hash sha</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">group 5</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">lifetime 86400</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 265.92pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!Load-balancing Configuration vpn load-balancing</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">cluster key 2wsx1qaz</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">cluster ip address 209.165.202.131</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">cluster encryption</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">participate</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 227.28pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">!Remote Access Group Configuration group-policy IPSEC-RA-GROUP internal group-policy IPSEC-RA-GROUP attributes</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 100.80pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">wins-server value 172.18.124.14 172.18.124.15</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dns-server value 172.18.124.12 172.18.124.13</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">vpn-tunnel-protocol IPSec</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">split-tunnel-policy tunnelspecified</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">split-tunnel-network-list value IPSEC-RA-GROUP_splitTunnelAcl</span></div>
<div class=paragraph style=" padding:0.00pt 192.96pt 0.00pt 96.96pt; text-align:left; text-indent:4.32pt;"><span class=font23 style=" line-height:9.60pt;">default-domain value companyc.com tunnel-group IPSEC-RA-GROUP type remote-access tunnel-group IPSEC-RA-GROUP general-attributes</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">address-pool IPSec-Pool</span></div>
<div class=paragraph style=" padding:0.00pt 201.36pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">authentication-server-group RADIUS-Server default-group-policy IPSEC-RA-GROUP tunnel-group IPSEC-RA-GROUP ipsec-attributes pre-shared-key *</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:74.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Reacting to a Security Incident</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">It is 4:00 a.m. (0400) on Christmas day, and the CSIRT team hotline rings with a call from one of the database administrators. The network is congested, and no transactions are possible to the most critical application in the organization from different sections of the organization. The CSIRT collects all available information from the database administrator and completes the steps described in the following sections.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:132.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:108.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:378.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 289.68pt; text-align:justify;"><span class=font4>Case Study of a Large Enterprise <b>419</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:321.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font6>Identifying, Classifying, and Tracking the Security Incident or Attack</span></div>
<div class=paragraph style=" padding:4.08pt 38.16pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">One of the members of the CSIRT collects NetFlow data from the data center distribution switch and correlates this data with CS-MARS. He notices that most of the traffic is HTTP (TCP port 80). This traffic is originating from known sources in the sales department (floor) in the New York office and from unknown sources. The CSIRT team works with a network administrator and discovers that the unknown sources are IP addresses belonging to the Atlanta branch office network. However, this process took almost an hour.</span></div>
<div class=paragraph style=" padding:24.96pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font6>Reacting to the Incident</span></div>
<div class=paragraph style=" padding:4.08pt 39.12pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The CSIRT team works with the network administrators in the Atlanta and New York offices to configure an ACL on the router in the Atlanta office and a VACL on the access switch in the sales floor. This ACL only blocks HTTP traffic from the offending machines. The malicious traffic has been contained, but it is possible that other machines have been infected.</span></div>
<div class=paragraph style=" padding:6.24pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The CSIRT team works with the desktop support group and server administrators. After doing research and forensics on the traffic, they discover that the traffic pattern is similar to a published vulnerability on security intelligence sites such as Cisco Security Center and US-CERT. However, their network IPS and other mechanisms were not able to detect the threat because the necessary signatures were not installed.</span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The server administrators and desktop support representatives download a security patch from the operating system vendor. Subsequently, they install this operating system patch on the affected machines. They also push this update via their patch management system to all machines within the organization. In addition, the correct signatures are installed on the IPS systems within the organization.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:108.00pt;">
<div class=block style=" width:108.00pt; height:140.40pt;">
<div class=paragraph style=" padding:0.00pt 8.88pt 0.00pt 36.96pt; text-align:justify;"><span class=font6>Postmortem</span></div>
<div class=paragraph style=" padding:5.28pt 2.64pt 0.00pt 0.00pt; text-align:right;"><span class=font44>The</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:378.00pt;">
<div class=block style=" width:378.00pt; height:140.40pt;">
<div class=paragraph style=" padding:12.96pt 36.24pt 0.00pt 3.36pt; text-align:left; text-indent:-3.36pt;"><span class=font44 style=" line-height:16.08pt;">CSIRT creates a postmortem including the following information: Total amount of labor spent working on the incident Elapsed time from the beginning of the incident to its resolution Elapsed time for each stage of the incident-handling process Time it took the incident response team to respond to the initial report of the incident Estimated monetary damage from the incident Lessons learned Action plan</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:86.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:108.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:378.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.24pt 0.00pt 36.24pt; text-align:justify;"><span class=font4><b>420   </b>Chapter 12: Case Studies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:218.88pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The lessons learned section in the postmortem is documented, including all items that will improve the incident response process and the proactive preparation of resources and processes to better defend against new threats. In this example, the following are areas that should be improved and are taken into an action plan:</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;The incident identification process was successful because the correct tools and mechanisms were in place. However, the identification of the Atlanta office IP address space was not obvious, and the process was delayed for more than an hour. Better documentation and diagrams should be prepared to avoid this in the future. The CSIRT team, in addition to network administrators, should have this information accessible when responding to an attack.</span></div>
<div class=paragraph style=" padding:4.08pt 38.64pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;IPS signatures were not upgraded because of a bad tuning and update process. A new process is developed to address this caveat.</span></div>
<div class=paragraph style=" padding:3.84pt 55.92pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;ACLs were deployed manually to contain and mitigate the attack. The network engineering teams will evaluate and create other tools and technologies, such as remotely triggered black holes (RTBH) or more appropriate mechanisms, to quarantine infected sources in a more effective fashion.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44>Each item on this action plan is assigned an owner and a due date.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:177.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark97"><a name="bookmark98"><b>S</b></a><b>ummary</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 41.04pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This chapter covered three case studies: a small business, a medium-sized enterprise, and a large enterprise. It demonstrated some of the most common applications and procedures discussed within this book. However, each of the previous chapters presented detailed instructions on how to proactively and reactively defend against security threats.</span></div>
<div class=paragraph style=" padding:6.24pt 43.92pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Various configuration examples were included in this chapter. The examples included infrastructure protection mechanisms and practices, basic firewall configuration, site-to-site and remote access VPNs, and a basic example of a CSIRT responding to a security incident. Security threats such as distributed denial of service (DDoS) attacks, worms, and others can result in significant loss of time and money for many organizations. It is highly recommended that you consider the extent to which the organization could afford a significant service outage and take steps commensurate with the risk.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:147.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.32pt;">
<div class=paragraph style=" padding:0.00pt 37.68pt 0.00pt 384.24pt; text-align:justify;"><span class=font4>Summary <b>421</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:116.88pt;">
<div class=paragraph style=" padding:0.00pt 41.52pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The network security lifecycle requires specialized support and a commitment to best practice standards. In this book, you learned best practices drawn upon disciplined processes, frameworks, expert advice, and proven technologies that will help you protect your infrastructure and organization. You learned the complete security lifecycle of a network, from strategy development to operations and optimization. You must take a proactive approach to security, an approach that starts with an assessment to identify and categorize your risks. In addition, you need to understand the network security technical details relating to security policy and incident response procedures. This book covered numerous best practices that will help you orchestrate a long-term strategy for your organization.</span></div>
</div>
</td>
]]></content:encoded>
			<wfw:commentRss>http://ciscoasa.org.ua/2010/03/chapter-12-case-studies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter 11: IPv6 Security</title>
		<link>http://ciscoasa.org.ua/2010/03/chapter-11-ipv6-security/</link>
		<comments>http://ciscoasa.org.ua/2010/03/chapter-11-ipv6-security/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 10:23:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[address space]]></category>
		<category><![CDATA[generation protocol]]></category>
		<category><![CDATA[internet header]]></category>
		<category><![CDATA[internet protocol version]]></category>
		<category><![CDATA[internet protocol version 4]]></category>
		<category><![CDATA[internet protocol version 6]]></category>
		<category><![CDATA[ipv6 packets]]></category>
		<category><![CDATA[ipv6 security]]></category>
		<category><![CDATA[ipv6 services]]></category>
		<category><![CDATA[microsoft windows vista]]></category>
		<category><![CDATA[packet fragmentation]]></category>
		<category><![CDATA[payloads]]></category>

		<guid isPermaLink="false">http://ciscoasa.org.ua/?p=267</guid>
		<description><![CDATA[

Internet Protocol Version 6 (IPv6) is often called the next generation protocol and is designed to replace the widely deployed Internet Protocol Version 4 (IPv4). Despite that, IPv6 has only been implemented in a few places, but it is expected to grow over time. For example, Microsoft Windows Vista includes support for IPv6.
IPv6 enables easier [...]]]></description>
			<content:encoded><![CDATA[<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:123.12pt;">
<div class=paragraph style=" padding:0.00pt 37.20pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Internet Protocol Version 6 (IPv6) is often called the next generation protocol and is designed to replace the widely deployed Internet Protocol Version 4 (IPv4). Despite that, IPv6 has only been implemented in a few places, but it is expected to grow over time. For example, Microsoft Windows Vista includes support for IPv6.</span></div>
<div class=paragraph style=" padding:6.00pt 37.20pt 0.00pt 91.20pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">IPv6 enables easier support and maintenance of service provider networks than previous versions. The large address space improves the usage of online support systems and enables the inexpensive provision of address space to end users. Many service providers in Europe, Asia, and the United States are currently working on providing IPv6 services to enterprises and small businesses. This chapter includes several IPv6 security topics. It also provides a comparison with IPv4 from a threat and mitigation perspective.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:91.20pt;">
<div class=block style=" width:91.20pt; height:8.88pt;">
<div class=paragraph style=" padding:0.00pt 30.00pt 0.00pt 37.68pt; text-align:justify;"><span class=font4><b>NOTE</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:394.80pt;">
<div class=block style=" width:394.80pt; height:8.88pt;">
<div class=paragraph style=" padding:0.00pt 150.00pt 0.00pt 0.00pt; text-align:justify;"><span class=font44>This chapter requires a basic knowledge of the IPv6 protocol.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:198.96pt;">
<div class=paragraph style=" padding:0.00pt 54.72pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">IPv6 is defined in RFC 2460, &quot;Internet Protocol, Version 6 (IPv6) Specification.&quot; The following are some of the main differences between IPv6 and IPv4:</span></div>
<div class=paragraph style=" padding:6.24pt 37.20pt 0.00pt 112.56pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Expanded addressing: </b>The IP address size is increased in IPv6 to 128 bits from the 32 bits supported in IPv4. This introduces considerable flexibility while supporting more levels of addressing hierarchy. Multicast routing scalability is also improved by the addition of a &quot;scope&quot; field to multicast addresses.</span></div>
<div class=paragraph style=" padding:3.60pt 38.40pt 0.00pt 112.56pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Simplified header format: </b>Several of the header fields used in IPv4 are not used in IPv6. These fields include check sum, Internet header length (IHL), identification flag, and fragment offset.</span></div>
<div class=paragraph style=" padding:3.60pt 54.96pt 0.00pt 112.56pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Improved support for extensions and options: </b>IPv6 encodes information into separate headers.</span></div>
<div class=paragraph style=" padding:3.84pt 36.72pt 0.00pt 112.56pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Fragmentation performed at the end hosts: </b>Unlike IPv4 packets, routers do not perform packet fragmentation on IPv6 packets. IPv6 supports payloads that are longer than 64 Kilobytes (KB).</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44><b>•&nbsp;Authentication: </b>IPv6 supports built-in authentication and confidentiality.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:91.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:98.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:295.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.48pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>330    </b><span class=font4>Chapter 11: IPv6 Security</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:79.68pt;">
<div class=paragraph style=" padding:0.00pt 95.76pt 0.00pt 35.76pt; text-align:justify;"><span class=font44><a name="bookmark83"><b>T</b></a><b>IP&nbsp;</b>Several sites include good information about IPv6, including the following:</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font44 style=" line-height:17.76pt;"><b>•&nbsp;Cisco IPv6 information on IOS: </b><a href="http://www.cisco.com/go/ipv6">http://www.cisco.com/go/ipv6</a></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font44 style=" line-height:17.76pt;"><b>•&nbsp;IPv6 Forum: </b><a href="http://www.ipv6forum.com">http://www.ipv6forum.com</a></span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font44 style=" line-height:17.76pt;"><b>•&nbsp;6Net IPv6 International Research: </b><a href="http://www.6net.org">http://www.6net.org</a></span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font44 style=" line-height:17.76pt;"><b>•&nbsp;Internet2 IPv6 Working Group: </b><a href="http://ipv6.internet2.edu">http://ipv6.internet2.edu</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:407.04pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The first thing you need to learn about IPv6 security is the different types of security threats that may affect your IPv6 deployment. This chapter covers the most common types of threats in IPv6 and other security topics, such as:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Reconnaissance</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Filtering in IPv6</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Spoofing</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Header manipulation and fragmentation</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Broadcast amplification or smurf attacks</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;IPv6 routing security</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;IPsec and IPv6</span></div>
<div class=paragraph style=" padding:21.84pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark76"><b>Reconnaissance</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Reconnaissance in IPv6 is not as easy to perform as in IPv4 networks. Do not forget that IPv6 has many more addresses than IPv4 (2<sup>Л</sup>64 to be exact, or 128-bit addresses). Performing a network scan for that many addresses is not feasible for an attacker because it takes a considerable amount of time to scan millions of addresses.</span></div>
<div class=paragraph style=" padding:6.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Attackers use different techniques to gain more visibility of your network. Inevitably, many network administrators may adopt addresses that are easy to remember to assign to network devices (for example, ::10, ::20, ::F00D). Attackers may use these types of addresses in specific scans or reconnaissance methodologies. Instead of standardizing on host addresses, try something that is more difficult for attackers to guess. For example, you may want to use something like ::DEE1 for default gateways. Some people refer to this technique as <i>security through obscurity. </i>That technique can be beneficial, because it does not require administrative complications. Standardizing on a short, fixed pattern for interfaces that should not be directly accessed from the outside allows for a short filter list at the border routers.</span></div>
<div class=paragraph style=" padding:6.24pt 42.96pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Because Domain Name System (DNS) is still used to map systems to IPv6 addresses on external and internal networks, an attacker can obtain information on your IPv6 network addresses if he compromises the DNS infrastructure/application.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:65.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 361.20pt; text-align:justify;"><span class=font4>Filtering in IPv6 <b>331</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:492.00pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;"><a name="bookmark84">J</a>ust as for IPv4, it is recommended that you filter all IPv6 services at the perimeter router or firewall in an effort to protect the internal networks.</span></div>
<div class=paragraph style=" padding:5.76pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Privacy becomes a problem when you use DHCPv6 on an IPv6 network. An IPv6 address has two parts. The first part is the subnet prefix, and the second part is a local identifier. This identifier is typically derived from your MAC address. The subnet prefix is a fixed 64-bit length for all current definitions. DHCP is not suitable for some IPv6 environments because you can technically get an IPv6 address via DHCPv6 in your corporate network and then get the same address when you are at home or at a hotel. Attackers can track you down with the use of web cookies that can retain your address information. That is why it is recommended that you use IPv6 Privacy Extensions for external communication. RFC 3041 defines the use of IPv6 Privacy Extensions.</span></div>
<div class=paragraph style=" padding:23.28pt 0.00pt 0.00pt 37.20pt; text-align:left;"><span class=font11><a href="#bookmark76"><b>Filtering in IPv6</b></a></span></div>
<div class=paragraph style=" padding:3.12pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Filtering of unauthorized access in IPv6 is similar to IPv4. This section includes examples of IPv6 access control lists (ACL), in addition to best practices when filtering ICMPv6 unnecessary packets and extension headers.</span></div>
<div class=paragraph style=" padding:24.24pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Filtering Access Control Lists (ACL)</b></span></div>
<div class=paragraph style=" padding:2.88pt 49.68pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can configure the filters or ACLs using Layer 3 and Layer 4 information. You can configure an IPv6 ACL in a Cisco IOS router using the <b>ipv6 access-list </b>command. The command uses the permit and deny subcommands with the following options:</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">ipv6 access-list command and its subcommands</span></div>
<div class=paragraph style=" padding:0.00pt 41.52pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">permit <span class=font3 style=" letter-spacing:1.00pt;"><b><i>protocol</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>{source-ipv6-prefix/prefix-length</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font39>I </span>any <span class=font39>I </span>host <span class=font3 style=" letter-spacing:1.00pt;"><b><i>source-ipv6-address}</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[operator</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[port-number]]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>{destination-ipv6-prefix/prefix-length</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font39>I </span>any <span class=font39>I </span>host <span class=font3 style=" letter-spacing:1.00pt;"><b><i>destination-ipv6-address}</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[operator</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[port-number]]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>[dest-option-type <span class=font3 style=" letter-spacing:1.00pt;"><b><i>[doh-number</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font39>I </span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>doh-type]]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>[dscp <span class=font3 style=" letter-spacing:1.00pt;"><b><i>value]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>[flow-label <span class=font3 style=" letter-spacing:1.00pt;"><b><i>value]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>[fragments] [log] [log-input] [mobility] [mobility-type <span class=font3 style=" letter-spacing:1.00pt;"><b><i>[mh-number</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font39>I </span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>mh-type]]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i>  </i></b></span>[reflect <span class=font3 style=" letter-spacing:1.00pt;"><b><i>name</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>[timeout <span class=font3 style=" letter-spacing:1.00pt;"><b><i>value]]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>[routing] [routing-type <span class=font3 style=" letter-spacing:1.00pt;"><b><i>routing-number]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i>  </i></b></span>[sequence <span class=font3 style=" letter-spacing:1.00pt;"><b><i>value]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i>  </i></b></span>[time-range <span class=font3 style=" letter-spacing:1.00pt;"><b><i>name]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>deny <span class=font3 style=" letter-spacing:1.00pt;"><b><i>protocol</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>{source-ipv6-prefix/prefix-length</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font39>I </span>any <span class=font39>I </span>host <span class=font3 style=" letter-spacing:1.00pt;"><b><i>source-ipv6-address}</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[operator</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[port-number]]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>{destination-ipv6-prefix/prefix-length</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font39>I </span>any <span class=font39>I </span>host <span class=font3 style=" letter-spacing:1.00pt;"><b><i>destination-ipv6-address}</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[operator</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[port-number]]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>[dest-option-type <span class=font3 style=" letter-spacing:1.00pt;"><b><i>[doh-number</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font39>I </span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>doh-type]]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>dscp <span class=font3 style=" letter-spacing:1.00pt;"><b><i>value]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>flow-label <span class=font3 style=" letter-spacing:1.00pt;"><b><i>value]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>fragments] <span class=font3 style=" letter-spacing:1.00pt;"><b><i>[</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>log] <span class=font3 style=" letter-spacing:1.00pt;"><b><i>[</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>log-input] <span class=font3 style=" letter-spacing:1.00pt;"><b><i>[</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>mobility] <span class=font3 style=" letter-spacing:1.00pt;"><b><i>[</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>mobility-type <span class=font3 style=" letter-spacing:1.00pt;"><b><i>[mh-number</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font39>I </span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>mh-type]]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i>  </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span>routing]  <span class=font3 style=" letter-spacing:1.00pt;"><b><i>[routing-type</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>routing-number]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[sequence</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>value]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i>  </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[time-range</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>name]</i></b></span><span class=font3 style=" letter-spacing:-0.50pt;"><b><i> </i></b></span><span class=font3 style=" letter-spacing:1.00pt;"><b><i>[undetermined-transport]</i></b></span></span></div>
<div class=paragraph style=" padding:4.56pt 42.72pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Example 11-1 shows an ACL in a Cisco IOS router allowing HTTP traffic (TCP port 80) from a trusted IPv6 host and denying all other traffic.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 11-1 </b><span class=font43><i>IPv6 Access Control List</i></span></span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ipv6 access-list outside_acl</span></div>
<div class=paragraph style=" padding:0.00pt 193.20pt 0.00pt 97.20pt; text-align:left; text-indent:4.08pt;"><span class=font23 style=" line-height:9.60pt;">permit tcp 2001:1234:0300:0101::/32 any eq 80 interface FastEthernet 0/0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ipv6 traffic-filter outside_acl in</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.48pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>332    </b>Chapter 11: IPv6 Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.60pt;">
<div class=paragraph style=" padding:0.00pt 49.20pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">In the previous example, the ACL name is <b>outside_acl, </b>and it is applied inbound to the FastEthernet 0/0 interface.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.32pt;">
<div class=paragraph style=" padding:0.00pt 73.20pt 0.00pt 35.76pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>Standard IPv6 ACLs are supported starting with Cisco IOS Version 12.2(2)T and</span></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 90.72pt; text-align:left;"><span class=font44>12.0(21)ST and later.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.24pt;">
<div class=paragraph style=" padding:0.00pt 39.60pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In the Cisco ASA and Cisco PIX security appliances, the IPv6 ACLs are similar to IOS. To create an IPv6 ACL to allow the same host to pass HTTP traffic on the Cisco ASA or Cisco PIX, use the <b>ipv6 access-list </b>command, as shown in the following example:</span></div>
<div class=paragraph style=" padding:6.48pt 42.72pt 0.00pt 97.68pt; text-align:justify;"><span class=font23 style=" line-height:8.16pt;">ipv6 access-list asa_outside_acl permit tcp 2001:1234:0300:0101::/32 any eq www -access-group asa_outside_acl in interface outside</span></div>
<div class=paragraph style=" padding:3.84pt 42.48pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.24pt;">Notice that the IPv6 access list is applied to the outside interface using the <b>access-group </b>command just as for IPv4 access lists.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.40pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>IPv6 has been supported on the Cisco PIX since Version 7.0. The Cisco ASA supports IPv6 in all versions, because the first version of Cisco ASA software is 7.0.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:240.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font8><b>ICMP Filtering</b></span></div>
<div class=paragraph style=" padding:3.12pt 52.32pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">You may also want to filter unnecessary ICMPv6 messages, just as with ICMPv4. It is recommended that you configure your ICMPv6 filters and policies in a manner that is similar to your ICMPv4 policies, with the following additions:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;ICMPv6 Type 2: </b>Packet too big</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;ICMPv6 Type 4: </b>Parameter problem</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;ICMPv6 Type 130-132: </b>Multicast listener</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;ICMPv6 Type 133/134: </b>Router solicitation and router advertisement</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;ICMPv6 Type 135/136: </b>Neighbor solicitation and neighbor advertisement</span></div>
<div class=paragraph style=" padding:2.16pt 38.64pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Make sure that, if you need to allow these options, you only allow trusted sources and deny everything else.</span></div>
<div class=paragraph style=" padding:24.48pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Extension Headers in IPv6</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In IPv6, IP options are replaced with extension headers. An attacker may use these extension headers to evade your security configuration. All devices running IPv6 must accept packets with a routing header. In some cases, it may be possible for end-host devices</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 262.80pt; text-align:justify;"><span class=font4>Header Manipulation and Fragmentation <b>333</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:497.04pt;">
<div class=paragraph style=" padding:0.00pt 54.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a name="bookmark85">t</a>o also process routing headers and forward the packet somewhere else. Attackers can take advantage of this and use routing headers to evade the ACLs configured on your routers and firewalls.</span></div>
<div class=paragraph style=" padding:6.00pt 38.16pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">As a best practice, you should designate specific devices that are allowed to act as Mobile IPv6 (MIPv6) home agents. MIPv6 is a protocol developed as a subset of IPv6 to support mobile connections. You should typically only assign the default router for a specific subnet to act as an MIPv6 home agent. If MIPv6 is not needed, packets with the routing header can easily be dropped at your firewalls and routers without relying on the end host not to forward the packets.</span></div>
<div class=paragraph style=" padding:23.52pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark86"><a name="bookmark87"><b>S</b></a><b>poofing</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">One of the most common techniques that attackers use is spoofing. <i>Spoofing </i>is the technique of modifying your source IP address or the ports to appear as your packets are initiated from another location. From a Layer 3 spoofing perspective, IPv6 presents a huge benefit because the allocations of IPv6 addresses are designed to easily be summarized allowing service providers to at least ensure that their own customers are not using addresses outside their allocated range. You can use filtering techniques such as those defined in RFC 2827.</span></div>
<div class=paragraph style=" padding:5.76pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The following are the most common best practices suggested to protect against IPv6 Layer 3 and Layer 4 spoofing:</span></div>
<div class=paragraph style=" padding:6.24pt 38.64pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Implement filtering techniques as defined in RFC 2827. In Chapter 2, &quot;Preparation Phase,&quot; you learned how to create antispoofing ACLs for your IPv4. You should do the same for your IPv6 addresses by denying all traffic from your own network range to be sourced from outside your networks.</span></div>
<div class=paragraph style=" padding:4.08pt 39.36pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;In an IPv6 subnet, an attacker has numerous options to select an IP address to spoof. It is critical to have tools to determine the true physical source of the traffic within your network. This generally entails some combination of Layer 2 and Layer 3 information gleaned from switches and routers.</span></div>
<div class=paragraph style=" padding:21.84pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font11><a href="#bookmark86"><b>Header Manipulation and Fragmentation</b></a></span></div>
<div class=paragraph style=" padding:3.12pt 50.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">IPv6 is susceptible to fragmentation and other header manipulation attacks. With these types of attacks, the attacker uses fragmentation to evade network intrusion detection systems (IDS), intrusion prevention systems (IPS), and firewalls.</span></div>
<div class=paragraph style=" padding:5.76pt 44.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">An attacker can also use out-of-order fragments to try to avoid an IDS/IPS device that is deployed to detect attacks based on the enabled signatures on the system. RFC 2460 prohibits fragmentation of IPv6 packets by intermediary network devices.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:79.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.48pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>334   </b>Chapter 11: IPv6 Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:493.20pt;">
<div class=paragraph style=" padding:0.00pt 43.44pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a name="bookmark88">A</a>s is the case with IPv4, you should always deny IPv6 fragments destined to an internetworking device whenever possible. On the other hand, you should test this in the lab and make sure that this does not cause problems with specific applications in your particular network environment.</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The combination of multiple extension headers and fragmentation in IPv6 creates the potential that the Layer 4 protocol will not be included in the first packet of a fragment set. Make sure that your IDS/IPS system or any other security monitoring device accounts for this possibility and reassembles fragments. Today, Cisco IPS/IDS devices support multiple extension headers and fragmentation.</span></div>
<div class=paragraph style=" padding:23.52pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark86"><a name="bookmark89"><b>B</b></a><b>roadcast Amplification or Smurf Attacks</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Broadcast amplification attacks are typically referred to as <i>smurf attacks. </i>These are denial of service (DoS) attacks where the attacker sends an echo-request message with a destination address of a subnet broadcast and a spoofed source address using the host IP address of the victim. This causes all the devices on the subnet to respond to the spoofed source IP address and flood the victim with echo-reply messages. RFC 2463 prohibits IP-directed broadcasts within IPv6. In addition, it states that an ICMPv6 message should not be generated as a response to a packet with an IPv6 multicast destination address, a link-layer multicast address, or a link-layer broadcast address.</span></div>
<div class=paragraph style=" padding:6.24pt 43.20pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Smurf attacks should not be a threat if all the devices within your network are compliant with RFC 2463. On the other hand, you should always implement ingress filtering of packets with IPv6 multicast source addresses.</span></div>
<div class=paragraph style=" padding:23.52pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark86"><b>IPv6 Routing Security</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 38.88pt 0.00pt 90.24pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Some routing protocols change in respect to security in IPv6; however; others do not. This section lists the routing protocols that change as well as those that remain the same.</span></div>
<div class=paragraph style=" padding:6.24pt 44.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Border Gateway Protocol (BGP) continues to have authentication mechanisms such as MD5 authentication but what, if anything, changes with IPv6? The Intermediate System-to-Intermediate System (IS-IS) protocol was extended in a draft specification to support IPv6. In IPv4, the simple password authentication of IS-IS was not encrypted. However, RFC 3567 defines the IS-IS cryptographic authentication. IS-IS in IPv6 also supports this cryptographic authentication mechanism.</span></div>
<div class=paragraph style=" padding:6.24pt 41.28pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Open Shortest Path First Version 3 (OSPFv3) protocol changed to support IPv6. The authentication fields were removed from the header of OSPF messages/packets. Another protocol that removed authentication capabilities was the Routing Information Protocol Next-Generation (RIPng). For this reason, it is recommended that you use traditional</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 362.88pt; text-align:justify;"><span class=font4>IPsec and IPv6 <b>335</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;"><a name="bookmark90">a</a>uthentication mechanisms for BGP and IS-IS. OSPF for IPv6 requires the use of IPsec to enable authentication. It is always a best practice to use OSPF in conjunction with IPsec to secure routing protocol updates in OSPF for IPv6.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.64pt;">
<div class=paragraph style=" padding:0.00pt 54.96pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>Cisco IOS routers support the use of IPv6 IPsec to authenticate OSPFv3 starting with Versions 12.3(4)T, 12.4, and later.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:175.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark86"><b>IPsec and IPv6</b></a></span></div>
<div class=paragraph style=" padding:3.84pt 38.16pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">IPsec is available with IPv6. IPv6 headers have no security mechanisms themselves, just as in IPv4. Administrators rely on the IPsec protocol suite for security. The same security risks for man-in-the-middle attacks in Internet Key Exchange (IKE) in IPv4 are present in IPv6. Most people recommend using IKE main mode negotiations when the use of preshared keys is required. On the other hand, IKE Version 2 (IKEv2) is expected to address this issue in the future. IKEv2 supports different peer authentication options with built-in support for asymmetric user authentication through the Extensible Authentication Protocol (EAP).</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The IPv6 IPsec packet format is basically the same as in IPv4. Figure 11-1 illustrates an IPv6 packet where Authentication Header (AH) and Encapsulation Security Payload (ESP) protocols are used. IPv6 AH and ESP extension headers are used to provide authentication and confidentiality to IPv6 packets.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 11-1 </b><span class=font43><i>IPv6 IPsec Packet</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.92pt; height:37.92pt; padding:0.00pt 62.88pt 0.00pt 61.20pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.92pt; height:37.92pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.68pt;">
<div class=block style=" width:49.68pt; height:18.72pt;">
<div class=paragraph style=" padding:9.36pt 0.00pt 0.00pt 1.68pt; text-align:center;"><span class=font4>IPv6</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.48pt;">
<div class=block style=" width:48.48pt; height:18.72pt;">
<div class=paragraph style=" padding:9.36pt 1.44pt 0.00pt 0.00pt; text-align:center;"><span class=font4>AH</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:18.72pt;">
<div class=paragraph style=" padding:9.36pt 1.44pt 0.00pt 0.00pt; text-align:center;"><span class=font4>ESP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.48pt;">
<div class=block style=" width:48.48pt; height:18.72pt;">
<div class=paragraph style=" padding:9.36pt 1.92pt 0.00pt 0.00pt; text-align:center;"><span class=font4>IPv6</span></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:70.08pt;">
<div class=block style=" width:70.08pt; height:37.92pt;">
<div class=paragraph style=" padding:14.16pt 0.00pt 0.00pt 21.36pt; text-align:left;"><span class=font4>Payload</span></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:37.92pt;">
<div class=paragraph style=" padding:14.16pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font4>Padding</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.96pt;">
<div class=block style=" width:48.96pt; height:18.72pt;">
<div class=paragraph style=" padding:9.36pt 0.00pt 0.00pt 17.04pt; text-align:left;"><span class=font4>ESP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.68pt;">
<div class=block style=" width:49.68pt; height:19.20pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.16pt; text-align:center;"><span class=font4>Header</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.48pt;">
<div class=block style=" width:48.48pt; height:19.20pt;">
<div class=paragraph style=" padding:0.24pt 0.48pt 0.00pt 0.00pt; text-align:center;"><span class=font4>Header</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:19.20pt;">
<div class=paragraph style=" padding:0.24pt 0.96pt 0.00pt 0.00pt; text-align:center;"><span class=font4>Header</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.48pt;">
<div class=block style=" width:48.48pt; height:19.20pt;">
<div class=paragraph style=" padding:0.24pt 1.92pt 0.00pt 0.00pt; text-align:center;"><span class=font4>Header</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.96pt;">
<div class=block style=" width:48.96pt; height:19.20pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 16.32pt; text-align:left;"><span class=font4>Auth</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.24pt;">
<div class=paragraph style=" padding:0.00pt 175.44pt 0.00pt 230.88pt; text-align:justify;"><span class=font1 style=" line-height:12.96pt;">-ESP Encrypted</span></div>
<div class=paragraph style=" padding:0.00pt 174.24pt 0.00pt 230.88pt; text-align:justify;"><span class=font1 style=" line-height:12.96pt;">ESP HMAC Authenticated — — AH Authenticated-</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:55.20pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Cisco IOS supports IPv6 IPsec for VPN tunnels starting with IOS Version 12.4(4)T. Figure 11-2 illustrates a topology where two Cisco IOS routers are configured to terminate a site-to-site IPv6 IPsec tunnel. The IPv6 address of the router in New York is 2EEE:1001::DCBA:BBAA:DDCC:4321, and the IPv6 address of the router in London is</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>2EEE:2002::ABCD:AABB:CCDD:1234.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:122.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.48pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>336    </b>Chapter 11: IPv6 Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 270.96pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 11-2 </b><span class=font43><i>IPv6 IPsec Configuration Example</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.32pt;">
<div class=paragraph style=" padding:0.00pt 137.52pt 0.00pt 246.96pt; text-align:justify;"><span class=font1>2EEE:2002::ABCD:AABB:CCDD:1234</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:359.52pt; height:69.12pt; padding:0.00pt 63.84pt 0.00pt 62.64pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-157.jpg" alt="" style=" width:359.52pt; height:69.12pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:281.76pt;">
<div class=paragraph style=" padding:0.00pt 39.12pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Virtual tunnel interfaces (VTI) are configured on each router in this example. Example 11-2 shows the configuration of the router in New York. Notice that the configuration is almost identical to the IPv4 VTI implementation. In this example, routers use preshared keys with SHA for hashing, and Diffie-Hellman group 1 for Phase 1. AH-SHA-HMAC and ESP-3DES are used for Phase 2.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 11-2 </b><span class=font43><i>New York Router Configuration</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 278.88pt 0.00pt 105.36pt; text-align:left; text-indent:-8.40pt;"><span class=font23 style=" line-height:9.60pt;">crypto isakmp policy 1 authentication pre-share</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>!</span></div>
<div class=paragraph style=" padding:2.40pt 73.20pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.40pt;">crypto isakmp key 1qaz2wsx address ipv6 2EEE:2002::ABCD:AABB:CCDD:1234/128 <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>crypto ipsec transform-set 3des ah-sha-hmac esp-3des</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 261.60pt 0.00pt 105.60pt; text-align:left; text-indent:-8.64pt;"><span class=font23 style=" line-height:9.60pt;">crypto ipsec profile myprofile set transform-set 3des</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.88pt 355.20pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">ipv6 cef <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 235.68pt 0.00pt 105.60pt; text-align:left; text-indent:-8.40pt;"><span class=font23 style=" line-height:9.60pt;">interface Tunnel0 ipv6 address 2EEE:1001::/64 eui-64 ipv6 enable ipv6 cef</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">tunnel source FastEthernet0</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">tunnel destination 2EEE:2002::ABCD:AABB:CCDD:1234</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">tunnel mode ipsec ipv6</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">tunnel protection ipsec profile myprofile</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 82.56pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Example 11-3 shows the configuration of the router in London. Notice that the configuration is almost identical for the exception of the IP addresses.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:135.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 384.24pt; text-align:justify;"><span class=font4>Summary <b>337</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:217.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><a name="bookmark91"><b>E</b></a><b>xample 11-3 </b><span class=font43><i>London Router Configuration</i></span></span></div>
<div class=paragraph style=" padding:5.76pt 278.88pt 0.00pt 105.36pt; text-align:left; text-indent:-8.40pt;"><span class=font23 style=" line-height:9.84pt;">crypto isakmp policy 1 authentication pre-share</span></div>
<div class=paragraph style=" padding:0.00pt 386.88pt 0.00pt 98.16pt; text-align:justify;"><span class=font23 style=" line-height:9.84pt;"><sub>! !</sub></span></div>
<div class=paragraph style=" padding:2.16pt 73.20pt 0.00pt 96.96pt; text-align:justify;"><span class=font23 style=" line-height:8.16pt;">crypto isakmp key 1qaz2wsx address ipv6 2EEE:1001::DCBA:BBAA:DDCC:4321/128 <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.88pt 167.52pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">crypto ipsec transform-set 3des ah-sha-hmac esp-3des <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 261.60pt 0.00pt 105.60pt; text-align:left; text-indent:-8.64pt;"><span class=font23 style=" line-height:9.84pt;">crypto ipsec profile myprofile set transform-set 3des</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.88pt 355.20pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">ipv6 cef <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">interface Tunnel0</span></div>
<div class=paragraph style=" padding:0.00pt 228.24pt 0.00pt 105.60pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ipv6 address 2EEE:2002::/64 eui-64 -ipv6 enable ipv6 cef</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">tunnel source FastEthernete</span></div>
<div class=paragraph style=" padding:0.00pt 172.56pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">tunnel destination 2EEE:1001::DCBA:BBAA:DDCC:4321 tunnel mode ipsec ipv6</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">tunnel protection ipsec profile myprofile</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:275.04pt;">
<div class=paragraph style=" padding:0.00pt 40.08pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The IKE and IPsec Security Associations (SA) are negotiated and established before the line protocol for the tunnel interface is changed to the UP state. The remote IKE peer is the same as the tunnel destination address; the local IKE peer will be the address picked from the tunnel source interface, which has the same IPv6 address scope as the tunnel destination address.</span></div>
<div class=paragraph style=" padding:23.52pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark86"><b>Summary</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This chapter introduced security topics in IPv6. Although it is assumed that you already have a basic understanding on IPv6, this chapter covered fundamental topics of IPv6 including how to filter IPv6 traffic in infrastructure devices such as the Cisco ASA and Cisco IOS routers. When deploying IPv6 on your network, you should pay attention to several security considerations. These considerations include the use of authorization for automatically assigned addresses and configurations, protection of IP packets, host protection from scanning and attacks, and control of traffic that is exchanged with the Internet. In many cases, these security considerations also exist for IPv4 traffic. Understanding the IPv6 security threats is a must for every security professional. This chapter included the most common IPv6 security threats and the best practices adopted by many organizations to protect their IPv6 infrastructure.</span></div>
<div class=paragraph style=" padding:6.24pt 40.08pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Many IPv6-enabled devices also support IPsec. This chapter covered how to configure Cisco IOS routers to terminate IPsec in IPv6 networks. It provided sample configurations to enhance the learning.</span></div>
</div>
</td>
]]></content:encoded>
			<wfw:commentRss>http://ciscoasa.org.ua/2010/03/chapter-11-ipv6-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter 10: Data Center Security</title>
		<link>http://ciscoasa.org.ua/2010/03/chapter-10-data-center-security/</link>
		<comments>http://ciscoasa.org.ua/2010/03/chapter-10-data-center-security/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 10:10:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[antivirus solutions]]></category>
		<category><![CDATA[application servers]]></category>
		<category><![CDATA[cisco security]]></category>
		<category><![CDATA[cisco unified callmanager]]></category>
		<category><![CDATA[critical application]]></category>
		<category><![CDATA[maintenance window]]></category>
		<category><![CDATA[security agent]]></category>
		<category><![CDATA[server traffic]]></category>
		<category><![CDATA[system vendor]]></category>
		<category><![CDATA[telephony servers]]></category>
		<category><![CDATA[voice services]]></category>

		<guid isPermaLink="false">http://ciscoasa.org.ua/2010/03/chapter-10-data-center-security/</guid>
		<description><![CDATA[

Protecting Cisco Unified CallManager
Server and operating system best practices apply when protecting the Cisco Unified CallManager. Just as with any other critical application, you should make major configuration changes within a maintenance window to avoid the disruption of voice services. However, some standard security policies for application servers might not be adequate for IP telephony [...]]]></description>
			<content:encoded><![CDATA[<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:218.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Protecting Cisco Unified CallManager</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Server and operating system best practices apply when protecting the Cisco Unified CallManager. Just as with any other critical application, you should make major configuration changes within a maintenance window to avoid the disruption of voice services. However, some standard security policies for application servers might not be adequate for IP telephony servers. For example, on e-mail and web servers, you can easily resend an e-mail message or refresh a web page. On the other hand, voice communications are real-time events. Consequently, your user population will quickly notice any disruption of service.</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The first step is to restrict activities on IP telephony servers (such as the Cisco Unified CallManager) that might be considered normal on application servers within a network. For instance, you should browse the Internet on CallManager servers. This sounds obvious, however, many administrators fail to do this.</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Patch management is one of the most crucial aspects of application security. Cisco provides a well-defined patch system for the Cisco Unified CallManager solution. You should apply only patches that Cisco provides and not patch the system using an operating system vendor patch (unless Cisco has approved it).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 142.80pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>You can download all Cisco Unified CallManager patches from <a href="http://www.cisco.com/kobayashi/sw-center/sw-voice.shtml">http://www.cisco.com/kobayashi/sw-center/sw-voice.shtml.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:159.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Additional information templates show you how to increase the hardening of the operating system in the Utils\SecurityTemplates directory on your Cisco Unified CallManager server.</span></div>
<div class=paragraph style=" padding:6.24pt 39.60pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">It is important to know that Cisco Unified CallManager 5.x does not support the use of antivirus software. However, an unmanaged version of the Cisco Security Agent provides security features above and beyond traditional antivirus solutions. As you learned in previous chapters, CSA looks at the server traffic and the way the running applications behave. It then enforces security mechanisms when something is considered abnormal. For instance, CSA prevents any virus or malware that tries to be installed on the system. It prevents the infection before it happens. You can also deploy the full version of CSA to provide granular configuration of security policies within the servers. In addition, you can monitor all CSA event logs from a centralized location (from the CSA Management Control, or CSA-MC).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>Use of CSA is highly recommended not only for Cisco Unified CallManager but to protect any servers and endpoints within your organization.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:61.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 267.60pt; text-align:justify;"><span class=font4>Securing the IP Telephony Applications <b>277</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.88pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In addition, you may want to protect all your servers in your data center with a firewall. The FWSM for the Cisco Catalyst 6500 series switches is typically deployed at the data center. You should configure strict policies on the specific traffic that is allowed to communicate to the Cisco Unified CallManager servers. As a best practice, only allow traffic from your voice VLANs/subnets and traffic from your administrative subnets.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 44.88pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>Detailed information on how to protect your data center is covered in Chapter 10, &quot;Data Center Security.&quot;</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:363.12pt;">
<div class=paragraph style=" padding:0.00pt 134.16pt 0.00pt 36.72pt; text-align:left;"><span class=font8 style=" line-height:15.12pt;"><b>Protecting Cisco Unified Communications Manager Express (CME)</b></span></div>
<div class=paragraph style=" padding:2.40pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">As previously discussed in this chapter, the Cisco Unified CME is an entry-level VoIP solution that runs on Cisco IOS Software routers. It is designed for small businesses and autonomous small enterprise branch offices. CME enables you to provide voice, data, and IP telephony services on a single platform. Because it is an integrated solution within Cisco IOS Software routers, all the best practices of router security that you learned in Chapter 2 apply when securing the Cisco Unified CME solution. These best practices include the following:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Configure enable secret passwords or encrypted passwords within the configuration.</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Configure administrator access privileges within Cisco IOS Software.</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Restrict access to VTY lines for remote administration access.</span></div>
<div class=paragraph style=" padding:2.16pt 75.60pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Use RADIUS or TACACS+ servers for authentication and authorization of administrative sessions.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Configure RADIUS or TACACS+ accounting.</span></div>
<div class=paragraph style=" padding:4.80pt 65.76pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Configure a fallback user account for administrative access when the external authentication server is not available.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Configure Secure Shell (SSH) access instead of Telnet.</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Control the access of Simple Network Management Protocol (SNMP) sessions.</span></div>
<div class=paragraph style=" padding:4.56pt 56.16pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Use all other best practices listed in Chapter 2 that protect the control plane and management plane.</span></div>
<div class=paragraph style=" padding:4.08pt 40.32pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In addition to the common infrastructure protection best practices, you should only allow IP phones in the trusted domain for registration. You can use the strict-match option in the <b>ip source-address </b>command if your local segment is a trusted domain. This allows only locally attached IP phones to register, as demonstrated in the following example:</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23>CME(configtelephony)#ip source-address 192.168.10.1 port 2000</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:71.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>278    </b><span class=font4>Chapter 9: IP Telephony Security</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:99.60pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Another good practice is to block port 2000 (from external untrusted networks) to prevent unauthorized Skinny Call Control Protocol (SCCP) phones from registering to your Cisco Unified CME. You can use an ACL as demonstrated in the following example:</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23>access-list 100 deny tcp any any eq 2000</span></div>
<div class=paragraph style=" padding:4.80pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Always use Secure Socket Layer (SSL) and HTTPS to access the web-based admin console, as shown in the following:</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23>ip http server</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23>ip http secure-server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.20pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 36.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;"><b>TIP&nbsp;</b>You can also use <b>ip http authentication </b>to perform external RADIUS or TACACS+ server</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">for HTTPS authentication.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:108.24pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Configure Class of Restrictions (COR) is used to prevent toll fraud. Typically, it is recommended that you configure different classes of service to control the destinations that users can call. For example, you can configure different levels of permissions that allow specific users to dial only local numbers and 911 for any emergencies. In the following example, two different types of users are configured (users and superusers). Superusers are allowed to dial any numbers, and regular users have access to all resources with the exception of toll (1-900 numbers), directory assistance (411), and international calling. This is achieved with the configuration shown in Example 9-4.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 9-4 </b><span class=font43><i>Protecting Against Toll Fraud Using COR</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:218.88pt;">
<div class=paragraph style=" padding:0.00pt 304.32pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dial-peer cor custom name 911 name 1800 name local-call name ld-call name 411 name int-call name 1900</span></div>
<div class=paragraph style=" padding:0.24pt 42.48pt 0.00pt 96.48pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">!different dial-peer names are assigned for the different services; additionally,</span></div>
<div class=paragraph style=" padding:0.00pt 196.80pt 0.00pt 96.48pt; text-align:left; text-indent:8.88pt;"><span class=font23 style=" line-height:8.88pt;">different COR !lists for each service are configured below. !</span></div>
<div class=paragraph style=" padding:1.92pt 280.08pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.88pt;">dial-peer cor list call911 member 911 <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 274.56pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.88pt;">dial-peer cor list call1800 member 1800 <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 270.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.88pt;">dial-peer cor list calllocal member local-call <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 278.88pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dial-peer cor list callint member int-call</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 267.60pt; text-align:justify;"><span class=font4>Securing the IP Telephony Applications <b>279</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:518.64pt;">
<div class=paragraph style=" padding:0.00pt 199.44pt 0.00pt 98.16pt; text-align:left; text-indent:-61.92pt;"><span class=font3 style=" line-height:13.92pt;"><b>Example 9-4 </b><span class=font43><i>Protecting Against Toll Fraud Using COR (Continued) </i></span><span class=font23><sub>!</sub></span></span></div>
<div class=paragraph style=" padding:0.00pt 283.20pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.88pt;">dial-peer cor list callld member ld-call <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 280.08pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.88pt;">dial-peer cor list call411 member 411 <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 274.56pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.88pt;">dial-peer cor list call1900 member 1900 <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.68pt 291.36pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dial-peer cor list user member 911 member 1800 member local-call member ld-call</span></div>
<div class=paragraph style=" padding:0.72pt 42.96pt 0.00pt 105.36pt; text-align:left; text-indent:-7.20pt;"><span class=font23 style=" line-height:8.16pt;">!the previous COR list allows regular users (user) to access/use 911, 1800, local calls, and !caller ID services</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;"><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 270.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dial-peer cor list superuser member 911 member 1800 member local-call member ld-call member 411 member int-call member 1900</span></div>
<div class=paragraph style=" padding:0.24pt 291.60pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dial-peer voice 9 pots corlist outgoing callld</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">destination-pattern 91..........</span></div>
<div class=paragraph style=" padding:0.00pt 355.92pt 0.00pt 96.96pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">port 1/0 prefix 1</span></div>
<div class=paragraph style=" padding:0.48pt 60.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:8.40pt;">!the previous COR list allows superusers to access/use all available services <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 287.28pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">dial-peer voice 911 pots corlist outgoing call911 destination-pattern 9911 port 1/0 prefix 911 <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.44pt 282.48pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">dial-peer voice 11 pots corlist outgoing callint destination-pattern 9011T port 2/0 prefix 011 <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.44pt 278.64pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dial-peer voice 732 pots corlist outgoing calllocal</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">destination-pattern 9732.......</span></div>
<div class=paragraph style=" padding:0.24pt 347.28pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">port 1/0 prefix 732</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:3.60pt 38.64pt 0.00pt 0.00pt; text-align:right;"><span class=font43><i>continues</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:59.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>280    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:355.20pt;">
<div class=paragraph style=" padding:0.00pt 199.44pt 0.00pt 36.24pt; text-align:justify;"><span class=font3><b>Example 9-4 </b><span class=font43><i>Protecting Against Toll Fraud Using COR (Continued)</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 283.20pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dial-peer voice 800 pots corlist outgoing call1800</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">destination-pattern 91800.......</span></div>
<div class=paragraph style=" padding:0.24pt 343.20pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">port 1/0 prefix 1800</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 283.20pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dial-peer voice 802 pots corlist outgoing call1800</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">destination-pattern 91877.......</span></div>
<div class=paragraph style=" padding:0.48pt 342.96pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.88pt;">port 1/0 prefix 1877 <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.68pt 283.20pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dial-peer voice 805 pots corlist outgoing call1800</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">destination-pattern 91888.......</span></div>
<div class=paragraph style=" padding:0.24pt 342.96pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">port 1/0 prefix 1888</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 287.52pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">dial-peer voice 411 pots corlist outgoing call411 destination-pattern 9411 port 1/0 prefix 411 <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.44pt 283.20pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">dial-peer voice 806 pots corlist outgoing call1800</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">destination-pattern 91866.......</span></div>
<div class=paragraph style=" padding:0.24pt 317.28pt 0.00pt 96.96pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">port 1/0 prefix 1866 ephone-dn 1 number 2000 cor incoming user Ephone-dn 2 number 2001</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">cor incoming superuser</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:93.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can configure the Cisco IOS Software Firewall on the same router that runs Cisco Unified CME. On the other hand, you must pay attention to certain requirements needed for Cisco Unified CME to work in your environment. For example, SCCP support is needed for locally generated Skinny traffic. SCCP is a Cisco proprietary lite-version of H.323 for call signaling, control, and media communication. H.323 uses Q.931, H.225, and H.245 for call setup, management, and control. H.323 requires a TCP connection for H.245 signaling that does not have a well-known port associated with it. The H.245 port is dynamically negotiated. NAT and stateful firewalls can break H.323.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:110.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 267.60pt; text-align:justify;"><span class=font4>Securing the IP Telephony Applications <b>281</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>Cisco IOS Software supports unidirectional firewall policy configurations between</span></span></div>
<div class=paragraph style=" padding:0.00pt 40.56pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">groups of interfaces which have been known as <i>zones </i>since Version 12.4(6)T. Previously, all inspect rules had to be applied to specific interfaces on routers running the Cisco IOS Firewall feature set. All inbound and outbound traffic was inspected based on the direction to which the inspect rule was applied.</span></div>
<div class=paragraph style=" padding:3.12pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Since Version 12.4(11)T, Cisco IOS Software Firewalls have supported H.225 Registration, Admission, and Status (RAS) signaling. H.323 uses the H.225 standard for call setup.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:122.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Protecting Cisco Unity</b></span></div>
<div class=paragraph style=" padding:2.88pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco Unity solution provides advanced voice mail and messaging features. In this section, you will learn tips for increasing the security of the Cisco Unity solution. Cisco Unity runs over the Microsoft Windows operating system (OS). The first step in protecting the Cisco Unity system is to have a good patch management procedure. Microsoft has different recommendations for installing and securing Windows Server 2003 and Windows 2000 Server systems. For Windows Server 2003, refer to the article <i>&quot;Checklists; Windows Server 2003, Standard Edition&quot; </i>at <a href="http://technet.microsoft.com/en-us/default.aspx">http://technet.microsoft.com/en-us/default.aspx. </a>For the Windows 2000 Server, refer to the article <i>&quot;Installing and Securing a New Windows 2000 System,&quot; </i>which is available on the same website.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>TIP&nbsp;</b><span class=font44>Make sure that the latest supported Cisco Unity service pack and all updates</span></span></div>
<div class=paragraph style=" padding:0.00pt 114.72pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">recommended by Microsoft are installed on the server. All supported service packs and recommended updates are listed at</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;"><a href="http://www.cisco.com/univercd/cc/td/doc/product/voice/c_unity/cmptblty/msupdate.htm">http://www.cisco.com/univercd/cc/td/doc/product/voice/c_unity/cmptblty/msupdate.htm.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:117.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can use security templates to help increase the security of the system. On the other hand, you should always apply all security policies to the Windows server only after the Cisco Unity installation is completed. Some security templates can affect the operation of Cisco Unity. The following Windows 2000 Server settings are recommended to restrict and audit access to the Cisco Unity server. To change these settings, go to <b>Start &gt; Programs &gt; Administrative Tools &gt; Local Security Policy </b>on the Windows 2000 server, and perform the following functions:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 1   </b><span class=font44>Set the <b>Audit account login events </b>option to <b>Failure.</b></span></span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 2   </b><span class=font44>Set the <b>Audit account management </b>option to <b>Success, Failure.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:99.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>282    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:252.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 3&nbsp;</b><span class=font44>Select <b>Failure </b>under <b>the Audit directory service access </b>option.</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 4&nbsp;</b><span class=font44>Set the <b>Audit login events </b>option to <b>Failure.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 5&nbsp;</b><span class=font44>Under <b>Audit object access, </b>select <b>No auditing.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 6&nbsp;</b><span class=font44>Under the <b>Audit policy change, </b>select <b>Success, Failure.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 7&nbsp;</b><span class=font44>Under the <b>Audit privilege use </b>option, select <b>Failure.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 8&nbsp;</b><span class=font44>Under <b>Audit system events, </b>select <b>No auditing.</b></span></span></div>
<div class=paragraph style=" padding:2.88pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 9  </b><span class=font44>Under the <b>Act as part of the operating system </b>option, enter the account used to install Cisco Unity.</span></span></div>
<div class=paragraph style=" padding:6.00pt 74.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 10 </b><span class=font44>Under the <b>Access this computer from the network, </b>select the following options: <b>Backup Operators, Power Users, Users, Administrators, servername\IWAM, domainname\ISUR_servername.</b></span></span></div>
<div class=paragraph style=" padding:5.76pt 108.00pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 11 </b><span class=font44>Only allow <b>Backup Operators and Administrators </b>under the <b>Shut down the system </b>option.</span></span></div>
<div class=paragraph style=" padding:6.00pt 43.20pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">It is important that you know the TCP and User Datagram Protocol (UDP) ports used by Cisco Unity. Table 9-1 lists all the TCP and UDP ports and their usage.</span></div>
<div class=paragraph style=" padding:9.84pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4><b>Table 9-1    </b><span class=font43><i>TCP and UDP Ports Used by Cisco Unity</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:234.00pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:234.00pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:117.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:22.56pt;">
<div class=paragraph style=" padding:7.44pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Protocols/Ports</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:22.56pt;">
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:22.56pt;">
<div class=paragraph style=" padding:8.40pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font4><b>Usage</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:52.08pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 25</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:52.08pt;">
<div class=paragraph style=" padding:3.60pt 33.84pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Simple Mail Transfer Protocol (SMTP)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:52.08pt;">
<div class=paragraph style=" padding:3.60pt 7.92pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Allowed inbound and outbound by Microsoft Exchange when installed on the Cisco Unity server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:96.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP and UDP 53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:96.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Domain Name System</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>(DNS)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:96.00pt;">
<div class=paragraph style=" padding:3.60pt 8.40pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:10.80pt;">Allowed outbound for access name resolution. Used inbound if the DNS server is running on the Cisco Unity server. It is recommended that for your DNS server, you use a server other than the system on which Cisco Unity is installed.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:63.36pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>UDP 67</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:63.36pt;">
<div class=paragraph style=" padding:3.60pt 16.80pt 0.00pt 6.48pt; text-align:left; text-indent:-0.24pt;"><span class=font43 style=" line-height:11.04pt;">DHCP/Bootstrap Protocol (BOOTP)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:63.36pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Allowed outbound if you are using</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>DHCP instead of static IP</span></div>
<div class=paragraph style=" padding:0.48pt 8.64pt 0.00pt 6.24pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">addresses. It is recommended that you use static addressing for the server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:117.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 267.60pt; text-align:justify;"><span class=font4>Securing the IP Telephony Applications <b>283</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.80pt;">
<div class=paragraph style=" padding:0.00pt 199.92pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>Table 9-1      </b><span class=font43><i>TCP and UDP Ports Used by Cisco Unity (Continued)</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:465.84pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:465.84pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:117.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:22.32pt;">
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Protocols/Ports</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:22.32pt;">
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:22.32pt;">
<div class=paragraph style=" padding:8.16pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font4><b>Usage</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:63.12pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>UDP 68</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:63.12pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>DHCP/BOOTP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:63.12pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Allowed inbound if you are using</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>DHCP instead of static IP</span></div>
<div class=paragraph style=" padding:0.96pt 18.24pt 0.00pt 6.24pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">addresses, which is used by the Cisco Unity server to receive</span></div>
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>DHCP or BOOTP replies.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.04pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 80</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.04pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>HTTP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.04pt;">
<div class=paragraph style=" padding:3.60pt 14.64pt 0.00pt 6.24pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Allowed bidirectional to access the Cisco Unity web console. HTTPS access is recommended.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:73.92pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 135</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:73.92pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Microsofts Remote</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Procedural Call (MS-RPC)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:73.92pt;">
<div class=paragraph style=" padding:3.60pt 10.32pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:10.80pt;">Used to negotiate access to the Media Master, Cisco Unity ViewMail for Microsoft Outlook, the Exchange server, and other Distributed Component Object Model (DCOM) services.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>UDP 137</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.04pt;">
<div class=paragraph style=" padding:3.60pt 8.40pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Network Basic Input/Output System (NetBIOS)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.04pt;">
<div class=paragraph style=" padding:3.60pt 8.16pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">NetBIOS Name Service. Used for NetBIOS name resolution or WINS resolution.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>UDP 138</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>NetBIOS</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.04pt;">
<div class=paragraph style=" padding:3.60pt 7.92pt 0.00pt 6.24pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">NetBIOS Datagram Service. Used when browsing Windows networks.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.04pt;">
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 139</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.04pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>NetBIOS</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.04pt;">
<div class=paragraph style=" padding:3.60pt 8.16pt 0.00pt 6.24pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:10.80pt;">Used to access Windows file shares and perform NetBIOS over TCP/IP connections.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:40.80pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>UDP 161</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:40.80pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>SNMP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:40.80pt;">
<div class=paragraph style=" padding:3.60pt 8.16pt 0.00pt 6.24pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:10.80pt;">Used to send SNMP notifications and to provide SNMP information when the host agent is queried.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:19.20pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>UDP 162</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:19.20pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>SNMP Trap</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:19.20pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Used to send SNMP traps.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:40.80pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 389</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:40.80pt;">
<div class=paragraph style=" padding:3.60pt 21.84pt 0.00pt 6.24pt; text-align:left; text-indent:-0.24pt;"><span class=font43 style=" line-height:10.80pt;">Lightweight Directory Access Protocol (LDAP)</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>with AD-DC</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:40.80pt;">
<div class=paragraph style=" padding:3.60pt 29.52pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:10.80pt;">Allowed outbound to access LDAP directory services.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.52pt;">
<div class=paragraph style=" padding:3.60pt 10.08pt 0.00pt 6.48pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Configurable (typically it is set to TCP 390 or any unused TCP port)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.52pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font43>LDAP with Exchange 5.5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.52pt;">
<div class=paragraph style=" padding:3.60pt 17.28pt 0.00pt 6.48pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Used to access LDAP directory services.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:117.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 41.52pt 0.00pt 410.16pt; text-align:justify;"><span class=font43><i>continues</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>284   </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.80pt;">
<div class=paragraph style=" padding:0.00pt 199.92pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>Table 9-1      </b><span class=font43><i>TCP and UDP Ports Used by Cisco Unity (Continued)</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:465.84pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:465.84pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:117.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:22.32pt;">
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Protocols/Ports</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:22.32pt;">
<div class=paragraph style=" padding:8.16pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:22.32pt;">
<div class=paragraph style=" padding:8.16pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font4><b>Usage</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:52.08pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 443</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:52.08pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>HTTP/SSL</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:52.08pt;">
<div class=paragraph style=" padding:3.60pt 26.40pt 0.00pt 6.24pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Used to perform system administration on a remote Cisco Unity server when it is configured for HTTP/SSL.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:73.92pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 445</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:73.92pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>SMB</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:73.92pt;">
<div class=paragraph style=" padding:3.60pt 7.92pt 0.00pt 6.00pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:10.80pt;">Used outbound to access Windows file shares and perform NetBIOS over TCP/IP connections. Used inbound to access Cisco Unity reports and Microsoft Windows file shares.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 636</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>LDAP/SSL</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:30.00pt;">
<div class=paragraph style=" padding:3.60pt 17.28pt 0.00pt 6.48pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Used to access LDAP directory services over SSL.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:52.08pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 691</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:52.08pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>SMTP/link-state</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>advertisement (LSA)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:52.08pt;">
<div class=paragraph style=" padding:3.60pt 8.40pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Used when the Exchange server is running on the Cisco Unity server and the Exchange server is</span></div>
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>accepting SMTP with LSA.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:52.08pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 1432</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:52.08pt;">
<div class=paragraph style=" padding:3.60pt 17.76pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Telecommunications Development Symposium (TDS) proxy (CiscoUnityTdsProxy)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:52.08pt;">
<div class=paragraph style=" padding:3.60pt 8.40pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Used by local processes to access the SQL Server or Microsoft SQL Server Desktop Engine (MSDE) database.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:51.84pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 1433 (default)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:51.84pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>MS-SQL-S</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:51.84pt;">
<div class=paragraph style=" padding:3.60pt 9.36pt 0.00pt 6.00pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:10.80pt;">Used to access the SQL Server or MSDE database and to perform replication when Cisco Unity failover is configured.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>UDP 1434</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>MS-SQL-M</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Used to access the SQL Server or</span></div>
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>MSDE database.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 2000</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:30.00pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>Skinny (SCCP)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:30.00pt;">
<div class=paragraph style=" padding:3.60pt 59.52pt 0.00pt 6.24pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Used to access Cisco CallManager.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 2443</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:30.00pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>Secure Skinny (SCCPS)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:30.00pt;">
<div class=paragraph style=" padding:3.60pt 7.44pt 0.00pt 6.24pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Used to access Cisco CallManager via an encrypted channel.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.52pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 3268</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.52pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>LDAP with AD-GC</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.52pt;">
<div class=paragraph style=" padding:3.60pt 13.92pt 0.00pt 6.48pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Used to access LDAP directory services when the global catalog server is on another server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:117.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:95.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 267.60pt; text-align:justify;"><span class=font4>Securing the IP Telephony Applications <b>285</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 200.40pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>Table 9-1      </b><span class=font43><i>TCP and UDP Ports Used by Cisco Unity (Continued)</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:484.80pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:484.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:117.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:22.32pt;">
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Protocols/Ports</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:22.32pt;">
<div class=paragraph style=" padding:8.16pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Service</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:22.32pt;">
<div class=paragraph style=" padding:8.16pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font4><b>Usage</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.04pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 3269</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.04pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>LDAP/SSL with AD-GC</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.04pt;">
<div class=paragraph style=" padding:3.60pt 6.48pt 0.00pt 6.24pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Used to access LDAP directory services over SSL when the global catalog server is on another server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.04pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 3372</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.04pt;">
<div class=paragraph style=" padding:3.60pt 23.04pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Microsoft Distributed Transaction Coordinator</span></div>
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>(MSDTC)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.04pt;">
<div class=paragraph style=" padding:3.60pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Used to access the SQL Server or</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">MSDE database when</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Cisco Unity failover is configured.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.04pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 3389</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.04pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Windows Terminal Services</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.04pt;">
<div class=paragraph style=" padding:3.60pt 9.60pt 0.00pt 6.48pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Used to remotely perform system administration on a Cisco Unity server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:62.88pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 3653</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:62.88pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Node Manager</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:62.88pt;">
<div class=paragraph style=" padding:3.60pt 12.72pt 0.00pt 6.00pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:10.80pt;">Used to send manual keepalive packets (or &quot;pings&quot;) between the primary and secondary servers when Cisco Unity failover is configured.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 4444</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>Kerberos authentication</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:30.00pt;">
<div class=paragraph style=" padding:3.60pt 36.48pt 0.00pt 6.48pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Used to perform Kerberos authentication.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.04pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 5060 (default)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.04pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>Session Initiation Protocol</span></div>
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>(SIP)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.04pt;">
<div class=paragraph style=" padding:3.60pt 7.92pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Used when the Cisco Unity server is connecting to SIP endpoints or SIP proxy servers.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 8005</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>Server Life Cycle (JMX)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Used to access the Tomcat server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 8009</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Apache JServ Protocol (AJP)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:30.00pt;">
<div class=paragraph style=" padding:3.60pt 24.96pt 0.00pt 6.48pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:11.04pt;">Used by Internet Information Server (IIS).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:63.12pt;">
<div class=paragraph style=" padding:3.60pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">TCP and UDP dynamic</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">(in the range of 1024</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">through 65535)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:63.12pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>DCOM</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:63.12pt;">
<div class=paragraph style=" padding:3.60pt 8.40pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Used by the Media Master to play and record voice messages, and used when the Cisco Unity server is a domain controller supporting member servers.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:52.08pt;">
<div class=paragraph style=" padding:3.60pt 25.92pt 0.00pt 6.48pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">Dynamic UDP ports (in the range of 1024</span></div>
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>through 65535)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:52.08pt;">
<div class=paragraph style=" padding:3.60pt 27.60pt 0.00pt 6.48pt; text-align:left; text-indent:-0.24pt;"><span class=font43 style=" line-height:11.04pt;">Messaging Application Programming Interface (MAPI) notifications</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:52.08pt;">
<div class=paragraph style=" padding:3.60pt 13.68pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:10.80pt;">Used in inbound direction to notify Cisco Unity of changes to subscriber mailboxes when Exchange is the message store.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt;">
<div class=block style=" width:107.52pt; height:41.28pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>UDP dynamic (in the</span></div>
<div class=paragraph style=" padding:0.48pt 16.56pt 0.00pt 6.48pt; text-align:left; text-indent:-0.24pt;"><span class=font43 style=" line-height:11.04pt;">range of 22800 through 32767)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:41.28pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font43>Real-Time Protocol (RTP)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:41.28pt;">
<div class=paragraph style=" padding:3.60pt 9.60pt 0.00pt 6.00pt; text-align:left; text-indent:0.24pt;"><span class=font43 style=" line-height:10.80pt;">Used when sending and receiving VoIP traffic with SCCP or SIP endpoints.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:117.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:76.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>286    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:237.12pt;">
<div class=paragraph style=" padding:0.00pt 40.56pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Use the information in Table 9-1 to restrict and allow access to firewalls that protect your Cisco Unity servers.</span></div>
<div class=paragraph style=" padding:6.24pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Cisco Unity uses Microsoft SQL Server. An important recommendation is to make sure that you increase the security of your Microsoft SQL Server 2000 installation. Make sure you select <b>Windows Authentication Mode </b>when you install Microsoft SQL Server, as documented in the Cisco Unity installation guide. In addition, make sure that you pay attention to the following guidelines:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Use a strong password for the SQL administrator (SA) account.</span></div>
<div class=paragraph style=" padding:5.04pt 38.40pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Restrict client access to Microsoft SQL Server 2000 by only allowing the Cisco Unity service accounts to access the Microsoft SQL Server 2000 directories, folders, and files. You can also grant this access to a highly privileged account designated for use by a system administrator.</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Detach the default Northwind and Pubs databases.</span></div>
<div class=paragraph style=" padding:5.28pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">At a minimum, Internet Explorer (IE) 6.0 with Service Pack 1 must be installed on the Cisco Unity server. Use IE on the Cisco Unity server for Cisco Unity administration only. It is not expected that you will use IE on the Cisco Unity server to browse the Internet and other external resources. On the other hand, in some cases, you may have to access the Microsoft or Cisco websites to obtain patches and hotfixes.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>TIP&nbsp;</b><span class=font44>As part of securing IE, refer to Microsoft Knowledge Base article 826955 at</span></span></div>
<div class=paragraph style=" padding:0.00pt 52.80pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;"><a href="http://support.microsoft.com/kb/826955">http://support.microsoft.com/kb/826955.</a> It includes instructions on how to reduce the chance of being exposed to a worm like Blaster or Nachi.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Cisco Unity uses IIS 5.0 and later. Always make sure that you install the latest cumulative update patches for IIS 5.0 on the Cisco Unity server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>TIP&nbsp;</b><span class=font44>You can also use the guidelines specified in the &quot;Secure Internet Information Services 5</span></span></div>
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Checklist,&quot; which is available on the Microsoft TechNet website, with one exception: grant Full Control access to Cisco Unity directories, folders, and files only to Cisco Unity service accounts and the local server administrators group.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:144.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 267.60pt; text-align:justify;"><span class=font4>Securing the IP Telephony Applications <span class=font44><b>287</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:98.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>In addition, it is recommended that you pay attention to the following best practices:</span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Delete all IIS default sample files, folders, and websites.</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Disable all default IIS COM objects.</span></div>
<div class=paragraph style=" padding:4.80pt 53.04pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Remove unused script mappings. Cisco Unity uses only the ASA and ASP script mappings.</span></div>
<div class=paragraph style=" padding:4.08pt 38.40pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Do not follow Microsoft recommendations regarding parent paths. The <b>Parent Paths </b>option should remain enabled on the Cisco Unity server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 36.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;"><b>TIP&nbsp;</b>Cisco Unity uses Microsoft Message Queuing (MSMQ) 2.0. It is recommended that you do</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">not change the default MSMQ setting of <b>Local Use Only.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 40.80pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Within Cisco Unity, each application has its own authentication capabilities and mechanisms, and you should become familiar with each of these authentication methods. Cisco has a detailed explanation of each application authentication mechanism at <a href="http://www.cisco.com/univercd/cc/td/doc/product/voice/c_unity/unity40/usg/ex/usg006.htm">http://www.cisco.com/univercd/cc/td/doc/product/voice/c_unity/unity40/usg/ex/usg006.htm.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:186.96pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Protecting Cisco Unity Express</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">As mentioned previously in this chapter, Cisco Unity Express is a Linux-based application that runs on Cisco IOS Software routers with either an NM or an AIM. No external interfaces exist on the Cisco Unity Express hardware. In reality, a physical Fast Ethernet interface does exist; however, it is software disabled. All traffic to the Cisco Unity Express hardware must pass through the router. On the other hand, you can access Cisco Unity Express via the router command-line interface (CLI) using the <b>service-module service-engine x/y session </b>command in enable mode. The Cisco Unity Express module also has a CLI, but you cannot configure a password on it.</span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">To protect the Cisco Unity Express application, you should first apply all router security best practices that you learned previously in this book to the router itself. In addition, you should only allow SSH access, instead of Telnet, to the router. Cisco Unity Express does not support SSH. However, the communication between the router and Cisco Unity Express is via the router backplane and is not exposed to external interfaces. Therefore, SSH access to the router is sufficient.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:133.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>288    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:472.32pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The initial versions of Cisco Unity Express did not support HTTPS. However, login to the Cisco Unity Express GUI is password protected. One major limitation is that the login information currently travels in cleartext across the IP network. To provide additional protection, you can use an IP Security (IPsec) tunnel to communicate to the router. However, HTTPS is supported on the Cisco Unified Communications Manager Express and Cisco Unity Express since Cisco IOS Software Version 12.2(15)ZJ2. To enable HTTPS access to the Cisco Unity Express application, you must enable the secure HTTP server on Cisco IOS Software with the following two commands:</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23>ip http server</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23>ip http secure-server</span></div>
<div class=paragraph style=" padding:4.56pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You should also use ACLs on the router to restrict access to only the protocols and ports that the Cisco Unity Express software uses. The following are the protocols and ports that Cisco Unity Express uses:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;SSH for administrative access: </b>TCP port 22</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;DNS: </b>UDP or TCP port 53</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;TFTP: </b>UDP port 69</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;FTP: </b>TCP port 21 for control and TCP port 20 for data (Active FTP only)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;HTTP: </b>TCP port 80 for the Cisco IP phones</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;HTTPS: </b>TCP port 443 for administrative access to the GUI</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Syslog: </b>UDP port 514</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;SIP: </b>UDP port 5060</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;RTP: </b>UDP port range from port 16384 to port 32767</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;NTP: </b>UDP port 123</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">Cisco Unity Express runs on Linux; however, access to the Linux operating system</span></div>
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">or to the Linux kernel is not direct. The Linux operating system is entirely embedded. Apply</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">only the patches that Cisco provides. The same goes for SQL and LDAP support.</span></div>
<div class=paragraph style=" padding:0.24pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Cisco Unity Express includes a SQL server and LDAP directory services; however, direct</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">access does not exist to the SQL server or the LDAP directory.</span></div>
<div class=paragraph style=" padding:5.76pt 37.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">As with the full version of Cisco Unity, you should also ensure that two servers are configured correctly: first, configuration of authentication to the FTP server that is used for software installation; and second, configuration of the FTP server that is used for backup and restore. Never leave the backup and restore FTP server password configured permanently on the Cisco Unity Express module. In addition, because mailbox PINs do not expire, a best practice is to change all passwords periodically, forcing users to reset their PINs to a new setting.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:104.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 267.60pt; text-align:justify;"><span class=font4>Securing the IP Telephony Applications <b>289</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:87.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Protecting Cisco Personal Assistant</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">This section covers the most common best practices to harden the Cisco Personal Assistant. The recommendations to increase the security of the Cisco Personal Assistant server can be summarized into two major areas:</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Operating environment</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Security policies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.80pt;">
<div class=paragraph style=" padding:0.00pt 49.20pt 0.00pt 89.76pt; text-align:left; text-indent:-54.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The Cisco Personal Assistant operating environment is made up of several third-party products. You should follow the security guidelines documented by each of these third-party product vendors. This chapter covers several general guidelines on securing the Cisco Personal Assistant operating environment.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font6>Hardening the Cisco Personal Assistant Operating Environment</span></div>
<div class=paragraph style=" padding:3.84pt 45.36pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco Personal Assistant operating environment third-party components needed are mainly Microsoft products. Other third-party components, such as Nuance ASR and Real-Speak TTS, are also needed.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:37.92pt;">
<div class=paragraph style=" padding:0.00pt 67.44pt 0.00pt 90.00pt; text-align:left; text-indent:-54.24pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The following site includes a detailed list of all Cisco Personal Assistant operating environment components:</span></span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44><a href="http://www.cisco.com/en/US/products/sw/voicesw/ps2026/prod_maintenance_guides_list.html">http://www.cisco.com/en/US/products/sw/voicesw/ps2026/prod_maintenance_guides_list.html</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:79.20pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.24pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Several of the Cisco Personal Assistant operating environment components are configured</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">by default with minimum security. It is extremely important that customers increase</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">the level of security protection for each of those systems. One of the major flaws is</span></div>
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">that Microsoft IIS is vulnerable until the Windows 2000 installation on the Cisco Personal</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Assistant server is complete. You have two options: disable IIS, or wait to install it</span></div>
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">until after Windows 2000 Service Pack 4 is installed. The recommended method is to install</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">a bundled Windows 2000 installation CD with Service Pack 4.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:150.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>290    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:93.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>It is recommended that you go query the Microsoft TechNet website</span></span></div>
<div class=paragraph style=" padding:0.00pt 57.60pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">(<a href="http://technet.microsoft.com/en-us/default.aspx">http://technet.microsoft.com/en-us/default.aspx)</a> for IIS vulnerabilities on a periodic basis. Also, you can always go to <a href="http://tools.cisco.com/security/center/home.x">http://tools.cisco.com/security/center/home.x </a>for a list of the latest (vendor-neutral) vulnerabilities.</span></div>
<div class=paragraph style=" padding:2.88pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can apply Microsoft-provided security policies to the Cisco Personal Assistant server; however, you should never apply any of these policies until the Cisco Personal Assistant installation is complete. Some security templates can affect the operation of the Cisco Personal Assistant.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:277.20pt;">
<div class=paragraph style=" padding:0.00pt 54.24pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The following are several general guidelines to use when you harden IIS on the Cisco Personal Assistant server:</span></div>
<div class=paragraph style=" padding:6.24pt 49.68pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Always make sure that the most current cumulative update patches for IIS 5.0 are installed on the server.</span></div>
<div class=paragraph style=" padding:4.32pt 38.64pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Always remove all IIS sample files, folders, and web applications. This is specified in the complete IIS 5.0 security checklist available on the Microsoft TechNet website.</span></div>
<div class=paragraph style=" padding:4.08pt 42.72pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Refer to the recommendations described in the complete IIS 5.0 security checklist available on the Microsoft TechNet website to disable all default IIS COM objects. However, do not disable the File System Object (FSO) and Parent Paths. These are enabled by default and are needed for the operation of the Cisco Personal Assistant server.</span></div>
<div class=paragraph style=" padding:4.08pt 38.64pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;You can also use the Microsoft IIS Lockdown and URLScan tools. However, it is extremely important that you not disable support for Active Server Pages (.asp) or the Scripts Virtual directory. You can download these tools from the Microsoft TechNet website.</span></div>
<div class=paragraph style=" padding:4.32pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">One of the requirements of the Cisco Personal Assistant is to have IE Version 6.0 with Service Pack 1. However, it is strongly recommended that you use IE on the server for the administration of the Cisco Personal Assistant only.</span></div>
<div class=paragraph style=" padding:6.24pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Microsoft recommends that you subscribe to the Security Notification Service; however, security experts advise against subscribing on the server. To subscribe to that service, drop IE security settings to a lower protection level.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:159.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 267.60pt; text-align:justify;"><span class=font4>Securing the IP Telephony Applications 291</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:488.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Cisco Personal Assistant Server Security Policies</span></div>
<div class=paragraph style=" padding:4.32pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">It is recommended that you change several security policies and server settings from their default values. It is also recommended that you enable auditing to track the way the Cisco Personal Assistant server is being accessed. The following values are recommended for the Audit Policies and User Rights Assignments under the Local Policies:</span></div>
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 1&nbsp;</b><span class=font44>Set <b>Audit account logon events </b>to <b>Failure.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 2&nbsp;</b><span class=font44>Set <b>Audit account management </b>to <b>Success, failure.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 3&nbsp;</b><span class=font44>Configure <b>Audit directory service access </b>to <b>Failure.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 4&nbsp;</b><span class=font44>Set <b>Audit logon events </b>to <b>Failure.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 5&nbsp;</b><span class=font44>Set <b>Audit object access </b>to <b>No auditing.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 6&nbsp;</b><span class=font44>Leave <b>Audit policy change </b>at its default value <b>(Success, failure).</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 7&nbsp;</b><span class=font44>Set <b>Audit privilege use </b>to <b>Failure.</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 8&nbsp;</b><span class=font44>Leave <b>Audit system events </b>at its default value <b>No auditing.</b></span></span></div>
<div class=paragraph style=" padding:2.64pt 77.76pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 9  </b><span class=font44>Under <b>Access this computer from the network, </b>allow only <b>Backup operators, Power users, Users, Administrators, uservername\IWAM, </b>and <b>domainname\ISUR_servername. </b>In other words, leave all default values except <b>Everyone.</b></span></span></div>
<div class=paragraph style=" padding:6.00pt 185.52pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 10 </b><span class=font44>Under <b>Shut down the system, </b>only allow <b>Backup operators and Administrators.</b></span></span></div>
<div class=paragraph style=" padding:5.76pt 63.84pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.24pt;">The following is the recommended list of settings that you can modify by using the Windows Local Security Policy utility on the Cisco Personal Assistant server.</span></div>
<div class=paragraph style=" padding:5.52pt 90.24pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 1   </b><span class=font44>Under <b>Additional restrictions for anonymous connections, </b>select <b>Do not allow enumeration of SAM accounts and shares.</b></span></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 2  </b><span class=font44>Disable the <b>Allow system to be shut down without having to log on</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:18.00pt;">option.</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 3  </b><span class=font44>Disable the <b>Audit use of Backup and Restore privilege </b>option.</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>Step 4  </b><span class=font44>Disable the <b>Clear virtual memory pagefile when system shuts down</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44>option.</span></div>
<div class=paragraph style=" padding:6.48pt 74.16pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 5  </b><span class=font44>Under <b>Digitally sign client communication (always), </b>select the default <b>Disabled </b>value.</span></span></div>
<div class=paragraph style=" padding:5.76pt 96.00pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 6  </b><span class=font44>Enable the <b>Digitally sign client communication (when possible) </b>option.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:88.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>292    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:461.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 7  </b><span class=font44>Disable the <b>Digitally sign server communication (always) </b>option.</span></span></div>
<div class=paragraph style=" padding:6.48pt 92.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 8  </b><span class=font44>Enable the <b>Digitally sign server communication (when possible) </b>option.</span></span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 9  </b><span class=font44>Disable <b>Ctrl-Alt-Del requirement for login.</b></span></span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 10 </b><span class=font44>Enable the <b>Do not display last user name in logon screen </b>option.</span></span></div>
<div class=paragraph style=" padding:6.48pt 114.96pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 11 </b><span class=font44>Under the <b>LAN manager authentication level </b>option, select <b>Send NTLM response only.</b></span></span></div>
<div class=paragraph style=" padding:6.00pt 74.64pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 12 </b><span class=font44>Set <b>Number of previous logons to cache (in case domain controller is not available) </b>to <b>5 </b>logons. This is strictly dependent on your security policy and your environment.</span></span></div>
<div class=paragraph style=" padding:5.76pt 103.68pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 13 </b><span class=font44>Enable the <b>Prevent system maintenance of computer account password </b>option.</span></span></div>
<div class=paragraph style=" padding:6.00pt 76.80pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 14 </b><span class=font44>Set the <b>Prompt user to change password before expiration </b>to <b>7 </b>days instead of the 14 days default value. This is strictly dependent on your security policy and your environment; however, as a rule of thumb, 7 days is appropriate for most environments.</span></span></div>
<div class=paragraph style=" padding:5.76pt 77.76pt 0.00pt 90.24pt; text-align:justify;"><span class=font4><b>Step 15 </b><span class=font44>Enable the <b>Restrict CD-ROM access to locally logged-on users only</b></span></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44>option.</span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 16 </b><span class=font44>Enable the <b>Restrict floppy access to locally logged-on users only</b></span></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44>option.</span></div>
<div class=paragraph style=" padding:6.72pt 74.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 17 </b><span class=font44>Enable the <b>Secure Channel: Digitally encrypt or sign secure channel data (always) </b>option.</span></span></div>
<div class=paragraph style=" padding:6.00pt 75.12pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 18 </b><span class=font44>Enable the <b>Secure Channel: Require strong (Windows 2000 or later) session key </b>option.</span></span></div>
<div class=paragraph style=" padding:6.00pt 84.48pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 19 </b><span class=font44>Disable the <b>Send unencrypted password to connect to third-party SMB [small and medium-sized business] servers </b>option.</span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 20 </b><span class=font44>Set the <b>Smart card removal behavior </b>option to <b>Lock workstation.</b></span></span></div>
<div class=paragraph style=" padding:6.48pt 131.52pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 21 </b><span class=font44>Under <b>Unsigned driver installation behavior, </b>select the <b>Do not allow installation </b>option.</span></span></div>
<div class=paragraph style=" padding:5.76pt 112.08pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 22 </b><span class=font44>Under <b>Unsigned non-driver installation behavior, </b>select the <b>Silently succeed / Warn but allow installation </b>option.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:117.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 256.56pt; text-align:justify;"><span class=font4>Protecting Against Eavesdropping Attacks <b>293</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:420.00pt;">
<div class=paragraph style=" padding:0.00pt 98.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">For any other Windows security-related information, see the Microsoft TechNet site.</span></div>
<div class=paragraph style=" padding:23.28pt 0.00pt 0.00pt 37.20pt; text-align:left;"><span class=font11><a href="#bookmark76"><a name="bookmark73"><b>P</b></a><b>rotecting Against Eavesdropping Attacks</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Eavesdropping attacks are also known as <i>phone tapping attacks. </i>The main goal is for an attacker to listen, copy, or record a conversation. An example of an eavesdropping attack is an incident reported back in 2006. The phones of about 100 Greek politicians and offices (including the U.S. embassy in Athens and the Greek prime minister) were compromised by a malicious code embedded in Vodafone mobile phone software. The attackers tapped into their conference call system. Basically, by using several prepaid mobile phones, the attackers &quot;joined the conference call&quot; and recorded their conversations.</span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Cisco ASA, Cisco PIX, and IOS Firewalls provide several features that support the stateful processing of signaling protocols, H.323, and SIP. These devices monitor the specific connection request and required resources and permit only what is specifically necessary for the operation of the system, thereby protecting against session hijacking and spoofing.</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco ASA and Cisco PIX security appliances support H.323 inspection by making sure that only compliant transactions are allowed between IP telephony devices, such as Cisco CallManager and other non-Cisco products. Cisco ASA and Cisco PIX support H.323 Versions 3 and 4. They also support multiple calls on the same call signaling channel. Example 9-5 demonstrates how you can configure an H.323 inspection policy map on a Cisco ASA or Cisco PIX security appliance running Version 7.2 or later.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 9-5 </b><span class=font43><i>Dynamic Port-Security</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 215.28pt 0.00pt 96.96pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">my_asa(config)# regex phonel &quot;5551234567&quot; my_asa(config)# regex phone2 &quot;5553213212&quot;</span></div>
<div class=paragraph style=" padding:0.00pt 103.44pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">my_asa(config)# class-map type inspect h323 match-all voice-traffic my_asa(configpmapc)# match called-party regex phone1 my_asa(configpmapc)# match calling-party regex phone2 my_asa(config)# policy-map type inspect h323 h323-policy-map my_asa(config-pmap)# parameters my_asa(configpmapp)# class voice_traffic my_asa(configpmapp)# rtp-conformance enforce-payloadtype my_asa(config-pmap-c)# drop</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ciscoasa(config)# service-policy h323-policy-map interface inside</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:156.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 289.92pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>294   </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:199.20pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Example 9-5, two regular expression entries are configured for two specific phone numbers (5551234567 and 5553213212). This is an optional step, but it gives you the flexibility to inspect traffic based on a specific caller or called party. A class map called <b>voice-traffic </b>is configured to inspect all traffic between the two previously defined phone numbers. The class map is applied to a policy map called <b>h323-policy-map. </b>All noncompliant traffic is dropped. The <b>rtp-conformance enforce-payloadtype </b>parameter is used to ensure that all transit RTP packets comply with protocol specifications. Finally, the policy map is applied to the inside interface using the <b>service-policy </b>command.</span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">IPS and IDS devices can also be placed in strategic areas within the network to detect unusual traffic, such as an attempt to execute an unusual command, or a malformed packet indicating some form of protocol manipulation.</span></div>
<div class=paragraph style=" padding:6.24pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">A good way to protect your voice traffic in untrusted environments is by the use of the voice- and video-enabled VPN (V3PN) solution. V3PN provides secure site-to-site connectivity to transport voice, video, and data. With V3PN, you can enable remote branch offices and teleworkers to use IP telephony services while reducing business operations costs.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:49.68pt;">
<div class=paragraph style=" padding:0.00pt 72.96pt 0.00pt 90.00pt; text-align:left; text-indent:-54.24pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The following white paper includes detailed information about V3PN design and implementation:</span></span></div>
<div class=paragraph style=" padding:3.12pt 119.28pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a href="http://www.cisco.com/application/pdf/en/us/guest/netsol/ns171/c649/ccmigration_09186a008074f2d8.pdf">http://www.cisco.com/application/pdff/en/us/guest/netsol/ns171/c649/ ccmigration_09186a008074f2d8.pdf</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:153.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Media encryption using Secure Real-Time Transport Protocol (SRTP) delivers protection by encrypting the voice conversation, rendering it unintelligible to internal or external eavesdroppers who have gained access to the voice domain. Designed for voice packets, SRTP supports the AES encryption algorithm and is an Internet Engineering Task Force (IETF) RFC 3711 standard. Media encryption on Cisco access routers works with both Cisco CallManager and the media encryption feature on Cisco IP phones, enabling customers to place secure analog phone or fax calls between an IP phone and the PSTN gateway depending on the gateway interface type. The SRTP-encrypted voice packets are almost indistinguishable from RTP voice packets, allowing features like QoS and compression to be implemented without additional development or manipulation. Voice encryption keys derived by Cisco Unified CallManager are securely sent by encrypted signaling path to Cisco Unified IP phones through the use of Transport Layer Security (TLS) and to gateways over IPsec-protected links.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:109.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.32pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 384.24pt; text-align:justify;"><span class=font4>Summary <b>295</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:125.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark76"><a name="bookmark74"><b>S</b></a><b>ummary</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">IP telephony solutions are being deployed at a fast rate in many organizations. The cost savings introduced with VoIP are significant. On the other hand, these benefits can be heavily impacted if you do not have the appropriate security mechanisms in place. This chapter covers several best practices for securing IP telephony networks. It discusses how to protect voice-enabled networks by protecting infrastructure components. It also covered how to secure different IP telephony components, such as the Cisco Unified CallManager, Cisco Unified CME, Cisco Unity, Cisco Unity Express, and Cisco Unified Personal Assistant. Finally, it covered several mechanisms that are used to combat voice eavesdropping and other attacks.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:451.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:111.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:74.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>This chapter covers the following topics:</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Protecting the Data Center Against Denial of Service (DoS) Attacks and Worms</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Data Center Segmentation and Tiered Access Control</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Deploying Network Intrusion Detection and Prevention Systems</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Deploying the Cisco Security Agent (CSA) in the Data Center</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:226.80pt; height:389.76pt; padding:0.00pt 65.76pt 0.00pt 193.44pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-135.jpg" alt="" style=" width:226.80pt; height:389.76pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:49.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:190.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:295.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:190.08pt;">
<div class=block style=" width:179.04pt; height:18.96pt; padding:11.52pt 11.04pt 5.04pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-136.jpg" alt="" style=" width:179.04pt; height:18.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:295.92pt;">
<div class=block style=" width:295.92pt; height:35.52pt;">
<div class=paragraph style=" padding:0.00pt 246.96pt 0.00pt 0.00pt; text-align:justify;"><span class=font18 style=" line-height:35.52pt; letter-spacing:-2.50pt; font-variant: small-caps;"><a href="#bookmark76"><b>10</b></a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:90.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:190.08pt;">
<div class=block style=" width:190.08pt; height:24.96pt;">
<div class=paragraph style=" padding:0.00pt 9.60pt 0.00pt 37.44pt; text-align:justify;"><span class=font16 style=" line-height:19.68pt;"><a name="bookmark75"><b>D</b></a><a name="bookmark77"><b>a</b></a><b>ta Center</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:295.92pt;">
<div class=block style=" width:295.92pt; height:24.96pt;">
<div class=paragraph style=" padding:0.00pt 195.60pt 0.00pt 0.00pt; text-align:justify;"><span class=font16 style=" line-height:24.96pt;"><b>Security</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:104.88pt;">
<div class=paragraph style=" padding:0.00pt 37.20pt 0.00pt 90.96pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Data centers comprise some of the most critical assets within any organization. Typically, applications, databases, and management servers reside in the data center. For this reason, it is extremely important to have the appropriate defense mechanisms in place to protect the data center against security threats. Attacks against data center assets can result in lost business applications and the theft of confidential information. This chapter covers several best practices and recommendations used to increase the security of your data center. These topics include protecting against denial of service (DoS) attacks, worms, information theft, and other security threats. The recommendations in earlier chapters are put into action in this chapter to provide an in-depth defense mechanism against existing and new threats.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.36pt;">
<div class=paragraph style=" padding:0.00pt 51.60pt 0.00pt 36.96pt; text-align:justify;"><span class=font11 style=" line-height:18.00pt;"><a href="#bookmark76"><b>Protecting the Data Center Against Denial of Service </b></a><b>(DoS) Attacks and Worms</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:114.96pt;">
<div class=paragraph style=" padding:0.00pt 39.36pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can implement different mechanisms and technologies on infrastructure components to help mitigate the effects of DoS and worms on your network. The following are some examples:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;SYN cookies in firewalls and load balancers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Intrusion Prevention Systems (IPSs) and Intrusion Detection Systems (IDSs)</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco NetFlow in the data center</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Guard</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Data center infrastructure protection</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 167.52pt 0.00pt 37.44pt; text-align:justify;"><span class=font8><b>SYN Cookies in Firewalls and Load Balancers</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 36.96pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">A commonly used distributed denial of service (DDoS) attack is known as <i>SYN-flooding. </i>In this type of attack, the attacker sends a series of TCP SYN packets that typically originate from spoofed IP addresses. The constant flood of SYN packets can prevent servers within the data center from handling legitimate connection requests. You can use firewalls and</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:78.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:190.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:295.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>298    </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:89.28pt;">
<div class=paragraph style=" padding:0.00pt 42.96pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">security appliances such as the Cisco ASA and the Cisco PIX enabled with the SYN cookies algorithm to combat SYN flood attacks. In large data centers, the Cisco Firewall Services Module (FWSM), for the Catalyst 6500 series switches, is typically used for this same purpose. Figure 10-1 demonstrates how TCP synchronization message (SYN) cookies work in the Cisco Adaptive Security Appliance (ASA), the Cisco PIX, and the FWSM for the Cisco Catalyst 6500 switches. In this example, a Cisco FWSM is used.</span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 10-1 </b><span class=font43><i>SYN Cookies in FWSM</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:300.24pt; height:58.56pt; padding:0.00pt 93.60pt 0.00pt 92.16pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-137.jpg" alt="" style=" width:300.24pt; height:58.56pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:314.40pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.68pt; text-align:center;"><span class=font4>Client&nbsp;FWSM Server</span></div>
<div class=paragraph style=" padding:14.88pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following steps are illustrated in Figure 10-1:</span></div>
<div class=paragraph style=" padding:6.48pt 39.36pt 0.00pt 111.84pt; text-align:justify; text-indent:-12.00pt;"><span class=font4 style=" line-height:12.24pt;"><b>1&nbsp;</b><span class=font44>A client machine attempts a TCP connection to a web server behind the FWSM and sends the initial SYN packet to the firewall.</span></span></div>
<div class=paragraph style=" padding:3.60pt 38.88pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>2&nbsp;</b><span class=font44>When the embryonic (half-open) connection limit is reached, the Cisco ASA, Cisco PIX, or Cisco FWSM can act as a proxy for the server and generate a SYN-ACK response to the client SYN request. The SYN-ACK reply has a &quot;cookie&quot; in the sequence (SEQ) field of the TCP header. The cookie is a message digest 5 algorithm (MD5) authentication of the source and destination IP addresses and port numbers. All the connection requests are rebuilt from these cookies.</span></span></div>
<div class=paragraph style=" padding:6.24pt 38.88pt 0.00pt 111.36pt; text-align:justify; text-indent:-12.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>3&nbsp;</b><span class=font44>The acknowledgement (ACK) packet SEQ field has the value of the cookie+1. In this case, when the FWSM receives an ACK from the client, it &quot;authenticates&quot; the client and allows the connection to the server.</span></span></div>
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 99.60pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>4&nbsp;</b><span class=font44>The FWSM sends its own SYN packet to the server.</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 99.36pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>5&nbsp;</b><span class=font44>The server replies with an ACK.</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 99.36pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>6&nbsp;</b><span class=font44>The FWSM sends its SYN-ACK to the server, and the connection is built.</span></span></div>
<div class=paragraph style=" padding:2.88pt 43.20pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">On the Cisco FWSM, you can use the <b>show np </b>command to view SYN cookie statistics. Example 10-1 shows the output of the <b>show np 2 syn </b>command on an FWSM.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-1 </b><span class=font43><i>Output of </i><b>show np 2 syn </b><i>Command</i></span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23>FWSM# show np 2 syn</span></div>
<div class=paragraph style=" padding:11.52pt 0.00pt 0.00pt 152.88pt; text-align:left;"><span class=font23>Fast Path Syn Cookie Statistics Counters (NP-2)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">SYN_COOKIE:&nbsp;Syn cookie secret wheel index&nbsp;:&nbsp;16</span></div>
<div class=paragraph style=" padding:0.24pt 64.56pt 0.00pt 97.20pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">SYN_COOKIE:&nbsp;Total number of SYNs intercepted&nbsp;:&nbsp;231356987</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">SYN_COOKIE:&nbsp;Total number of ACKs intercepted&nbsp;:&nbsp;204</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">SYN_COOKIE:&nbsp;Total number of ACKs dropped after&nbsp;lookup                   :&nbsp;0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 108.24pt; text-align:justify;"><span class=font4>Protecting the Data Center Against Denial of Service (DoS) Attacks and Worms <span class=font44><b>299</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 221.76pt 0.00pt 36.24pt; text-align:justify;"><span class=font3><b>Example 10-1 </b><span class=font43><i>Output of </i><b>show np 2 syn </b><i>Command (Continued)</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:306.24pt; height:67.92pt; padding:0.00pt 84.24pt 0.00pt 95.52pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:306.24pt; height:67.92pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:24.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:32.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:92.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:66.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt;">
<div class=block style=" width:49.20pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>SYN_COOKIE:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.72pt;">
<div class=block style=" width:24.72pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>Total</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:32.88pt;">
<div class=block style=" width:32.88pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.72pt; text-align:center;"><span class=font23>number</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>of</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:159.12pt;">
<div class=block style=" width:159.12pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>ACKs successfully validated</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.28pt;">
<div class=block style=" width:29.28pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font23>: 193</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt;">
<div class=block style=" width:49.20pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>SYN_COOKIE:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.72pt;">
<div class=block style=" width:24.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>Total</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:32.88pt;">
<div class=block style=" width:32.88pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.72pt; text-align:center;"><span class=font23>number</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>of</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:92.40pt;">
<div class=block style=" width:92.40pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>ACKs Dropped: Secret</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>Expired</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.28pt;">
<div class=block style=" width:29.28pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font23>: 11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt;">
<div class=block style=" width:49.20pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>SYN_COOKIE:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.72pt;">
<div class=block style=" width:24.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>Total</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:32.88pt;">
<div class=block style=" width:32.88pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 0.72pt; text-align:center;"><span class=font23>number</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>of</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:92.40pt;">
<div class=block style=" width:92.40pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>ACKs Dropped: Invalid</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font23>Sequence</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.28pt;">
<div class=block style=" width:29.28pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font23>: 0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt;">
<div class=block style=" width:49.20pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>SYN_COOKIE:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.72pt;">
<div class=block style=" width:24.72pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>Total</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:32.88pt;">
<div class=block style=" width:32.88pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 0.72pt; text-align:center;"><span class=font23>number</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:11.04pt;">
<div class=block style=" width:11.04pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font23>of</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:159.12pt;">
<div class=block style=" width:159.12pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font23>Syn Cookie Entries inserted by NP3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.28pt;">
<div class=block style=" width:29.28pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font23>: 12</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt;">
<div class=block style=" width:49.20pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>SYN_COOKIE:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.72pt;">
<div class=block style=" width:24.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>ACKs</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:32.88pt;">
<div class=block style=" width:32.88pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.72pt 0.00pt 0.00pt; text-align:center;"><span class=font23>dropped:</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:103.44pt;">
<div class=block style=" width:103.44pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font23>Syn cookie ses not yet</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font23>established</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.28pt;">
<div class=block style=" width:29.28pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font23>: 0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt;">
<div class=block style=" width:49.20pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>SYN_COOKIE:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.72pt;">
<div class=block style=" width:24.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font23>Leaf</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:43.92pt;">
<div class=block style=" width:43.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font23>allocation</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:92.40pt;">
<div class=block style=" width:92.40pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>failed</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.28pt;">
<div class=block style=" width:29.28pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font23>: 0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt;">
<div class=block style=" width:49.20pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>SYN_COOKIE:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.72pt;">
<div class=block style=" width:24.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font23>Leaf</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:43.92pt;">
<div class=block style=" width:43.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font23>insertion</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:92.40pt;">
<div class=block style=" width:92.40pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>failed</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.28pt;">
<div class=block style=" width:29.28pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font23>: 2088</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:24.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:32.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:92.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:66.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:107.28pt;">
<div class=paragraph style=" padding:0.00pt 43.68pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the highlighted line in Example 10-1, you can see that the total number of intercepted SYN packets is 231356987. This is most definitely indicative of a SYN flood.</span></div>
<div class=paragraph style=" padding:6.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Load-balancing solutions such as the Cisco Content Switching Module (CSM) also support SYN cookies. You can deploy the CSM in inline mode or one-arm mode. Figure 10-2 illustrates a CSM configured in inline mode. Traffic from certain applications cannot be load-balanced because of the nature of those applications. In Figure 10-2, the traffic that cannot be load-balanced is labeled as direct traffic.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 10-2 </b><span class=font43><i>CSM in Inline Mode</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:352.32pt; height:61.20pt; padding:0.00pt 67.44pt 0.00pt 66.24pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-138.jpg" alt="" style=" width:352.32pt; height:61.20pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:2.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:234.96pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 351.36pt; text-align:left;"><span class=font4>Web Servers</span></div>
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 154.56pt; text-align:left;"><span class=font49 style=" line-height:39.84pt;"><b>4</b></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 151.44pt; text-align:left;"><span class=font4>Client</span></div>
<div class=paragraph style=" padding:14.88pt 40.56pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">In Figure 10-2, the CSM is configured with both physical interfaces that are connected to the network with all traffic passing through the CSM. Figure 10-3 illustrates the one-arm</span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>CSM design.</span></div>
<div class=paragraph style=" padding:6.96pt 36.72pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The CSM uses a virtual IP address. In a &quot;one-arm&quot; design, you can combine it with a Cisco FWSM. One of the major benefits of using a CSM one-arm design in combination with the Cisco FWSM is that the CSM protects against DoS attacks directed at its virtual IP address, and the Cisco FWSM protects against attacks directed at non-load-balanced servers.</span></div>
<div class=paragraph style=" padding:5.76pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The use of SYN cookies has certain limitations. For example, SYN cookies cannot carry TCP options that are set up in SYN packets; SYN cookies can carry only an encoding of the maximum segment size (MSS) value of the server. Some TCP options are used for performance and scalability (for example, large windows, selective acknowledgement, and so on). Another limitation of SYN cookies is that they do not protect against established connection attacks.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>300    </b><span class=font4>Chapter 10: Data Center Security</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:382.08pt; height:162.00pt; padding:0.00pt 67.44pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-139.jpg" alt="" style=" width:382.08pt; height:162.00pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>Established connection attacks are attacks that exploit vulnerabilities after a connection has been established such as a buffer overflow to a specific application.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:201.84pt;">
<div class=paragraph style=" padding:0.00pt 148.56pt 0.00pt 36.72pt; text-align:left;"><span class=font8 style=" line-height:15.12pt;"><b>Intrusion Prevention Systems (IPS) and Intrusion Detection Systems (IDS)</b></span></div>
<div class=paragraph style=" padding:2.40pt 54.24pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In earlier chapters, you learned the difference between IDS and IPS devices. IDS and IPS appliances and modules are usually placed in the data center distribution center not only to alert an administrator when a security threat has been detected, but also to take action and protect the data center assets. In small environments, one or more IDS/IPS appliances (such as the Cisco 4200 sensors) can be placed in the data center. The Cisco Catalyst 6500 IDS/IPS module (IDSM) is used in larger environments.</span></div>
<div class=paragraph style=" padding:5.76pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco Security Agent (CSA) provides host-based prevention services that help you protect the servers in the data center from attacks that exploit OS and application vulnerabilities. These two technology solutions (network and host-based) complement each other. Despite the fact that both solutions provide intrusion prevention mechanisms that guard against direct attacks, the technologies are different in numerous ways. Later sections in this chapter cover the deployment of both network and host-based IPS solutions. The benefits and limitations of each solution are discussed in their respective sections.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:120.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 108.24pt; text-align:justify;"><span class=font4>Protecting the Data Center Against Denial of Service (DoS) Attacks and Worms <b>301</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:98.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Cisco NetFlow in the Data Center</b></span></div>
<div class=paragraph style=" padding:3.84pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Cisco NetFlow provides network traffic visibility that can help in identifying and classifying potential DDoS attempts and other security threats. In addition, it provides valuable information about application usage that can be beneficial for network planning and traffic engineering. You can enable NetFlow in data center infrastructure devices, such as your distribution switches or routers. A new version of NetFlow called <i>Flexible </i>NetFlow is now available on Cisco IOS routers starting with IOS Version 12.4(9)T. Cisco is working to provide this functionality in other platforms such as the Catalyst 6500 series switches.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 41.28pt 0.00pt 36.24pt; text-align:center;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>You can use the Cisco Feature Navigator tool to find information about platform support. To access this tool, go to <a href="http://tools.cisco.com/ITDIT/CFN/jsp/index.jsp">http://tools.cisco.com/ITDIT/CFN/jsp/index.jsp.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:324.72pt;">
<div class=paragraph style=" padding:0.00pt 47.04pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">With Flexible NetFlow, you can configure a range of parameters for traffic analysis and data export on a networking device. For instance, you can define your own records by specifying the key and nonkey fields to customize the data collection to your specific requirements. In previous versions of NetFlow, a flow was based on a set of seven IP packet attributes:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Source IP</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Destination IP</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Source port</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Destination port</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Layer 3 Protocol</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Type of Service (ToS) byte</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Input interface</span></div>
<div class=paragraph style=" padding:1.92pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Flexible NetFlow adds the ability to check other information, such as the number of bytes and packets in a flow. You can also create custom records for functions like quality of service (QoS), bandwidth monitoring, application and end user traffic profiling, and security monitoring.</span></div>
<div class=paragraph style=" padding:6.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The main limitation is that, currently, Flexible NetFlow is not supported in the Cisco Catalyst 6500. In most cases, it is recommended that you enable NetFlow at the data center distribution switches. In large data centers, Cisco Catalyst 6500 switches are used as distribution switches. However, the benefits of NetFlow Versions 5 and 9 are still extremely valuable, because NetFlow is one of the most helpful tools for identifying and classifying security threats. In addition, you can use network monitoring tools such as the Cisco Security Monitoring, Analysis, and Response System (CS-MARS) to analyze NetFlow and other telemetry data from many different network devices.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:67.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>302    </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:89.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Cisco Guard</b></span></div>
<div class=paragraph style=" padding:2.88pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco Detector and Cisco Guard provide anomaly detection and attack mitigation features. You can place them in large data centers to divert traffic directed at the target host for analysis and filtering, so that legitimate transactions can still be processed while illegitimate traffic is dropped. On the other hand, in most cases small, medium, and large enterprises place their Cisco Guard at their Internet edge or subscribe to managed services provided by service providers.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 63.60pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The managed service solution is called Clean Pipes. Cisco has detailed information about the Clean Pipes solution at <a href="http://www.cisco.com/en/US/netsol/ns615/networking_solutions_sub_solution.html">http://www.cisco.com/en/US/netsol/ns615/ networking_solutions_sub_solution.html.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:113.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Data Center Infrastructure Protection</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The infrastructure protection best practices that you learned in Chapter 2, &quot;Preparation Phase,&quot; also apply in the data center. For example, you should harden control protocols as a basic security precaution on all applicable devices in the data center. In addition, you should disable unnecessary services on infrastructure components and implement device protection mechanisms, such as infrastructure access control lists (iACLs) and Control Plane Policing (CoPP). These device protection mechanisms will help you greatly in case of worm outbreaks, DDoS, or even in case of an anomaly other than a security threat (that is, a misconfigured application).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>TIP&nbsp;</b><span class=font44>Remember to implement basic best-practice recommendations such as hardening device</span></span></div>
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">authentication, hardening Simple Network Management Protocol (SNMP), using Network Time Protocol (NTP), and all others that you learned in Chapter 2.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:127.92pt;">
<div class=paragraph style=" padding:0.00pt 39.36pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can also develop configuration templates for data center access switch ports where servers reside. Basic Layer 2 security mechanisms, such as limits on the number of MAC addresses that the server can originate on a port, can be included in the configuration template. You can also disable the Cisco Discovery Protocol (CDP) when it is not needed; be careful, however, because certain applications use CDP for legitimate transactions. Example 10-2 shows a basic template.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-2 </b><span class=font43><i>Data Center Access Switch Port Template</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 270.00pt 0.00pt 101.28pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">interface GigabitEthernet2/4 no ip address switchport</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">switchport access vlan 100</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.32pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 208.80pt; text-align:justify;"><span class=font4>Data Center Segmentation and Tiered Access Control <b>303</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:73.20pt;">
<div class=paragraph style=" padding:0.00pt 200.64pt 0.00pt 36.24pt; text-align:justify;"><span class=font3><b>Example 10-2 </b><span class=font43><i>Data Center Access Switch Port Template (Continued)</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 201.60pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">switchport mode access spanning-tree portfast switchport port-security maximum 2 switchport port-security violation shutdown spanning-tree bpduguard enable no cdp enable</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.20pt;">
<div class=paragraph style=" padding:0.00pt 48.00pt 0.00pt 90.00pt; text-align:justify;"><span class=font44>The highlighted commands in Example 10-2 enable port security and BPDU guard and</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>disable CDP.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:55.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><a name="bookmark78"><b>N</b></a><b>OTE        </b><span class=font44>An important point about port security is that it does not interoperate well with virtual</span></span></div>
<div class=paragraph style=" padding:0.00pt 39.60pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">servers because they may carry multiple MAC addresses of virtual hosts. You should also be careful when implementing port security with certain server failover mechanisms. In some environments, servers with multiple network interface cards (NIC) may share the same MAC address between interfaces when a failover occurs.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:278.16pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">For antispoofing protection, you can also enable Unicast Reverse Path Forwarding (Unicast RPF) in routers, security appliances such as the Cisco ASA, or in the Cisco FWSM. In the data center, it is most common to deploy Unicast RPF on the firewalls (Cisco ASA or FWSM). With Unicast RPF, if traffic enters the outside or untrusted interface from an address that is known to the routing table, but it resides on the inside interface, the firewall drops the packet. Similarly, if traffic enters the inside interface from an unknown source address, the firewall drops the packet to prevent spoofed attacks. You can enable Unicast RPF on the Cisco ASA, Cisco PIX, or Cisco FWSM with the <b>ip verify reverse-path </b>command, as shown in the following example:</span></div>
<div class=paragraph style=" padding:6.48pt 162.72pt 0.00pt 97.68pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">FWSM(config)#ip verify reverse-path interface outside FWSM(config)#ip verify reverse-path interface inside</span></div>
<div class=paragraph style=" padding:4.56pt 44.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the previous example, Unicast RPF is enabled in the outside and inside interfaces. Because firewalls require traffic path symmetry, in most cases, Unicast RPF can provide great benefits without impacting traffic flow.</span></div>
<div class=paragraph style=" padding:22.32pt 167.52pt 0.00pt 36.24pt; text-align:left;"><span class=font11 style=" line-height:18.24pt;"><a href="#bookmark76"><b>Data Center Segmentation and Tiered </b></a><b>Access Control</b></span></div>
<div class=paragraph style=" padding:2.88pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">By isolating different types of servers and services, you can use segmentation and tiered access control in your data center to provide a multilayered architecture while adding security. The easiest way to segment your data center is to configure different Layer 2 domains or VLANs. In addition, you can use firewalls for policy enforcement between each</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:64.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>304   </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">segment. By using private VLANs, you can also use segmentation that is local to the VLAN. This helps in preventing a compromised or infected server from affecting adjacent systems. In a multitier architecture, you separate systems based on the different functions they handle. For example, you can separate the presentation, business logic, and database layers, as illustrated in Figure 10-4.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 254.16pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 10-4 </b><span class=font43><i>Multitier Server Segmentation Example</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:343.20pt; height:354.72pt; padding:0.00pt 71.76pt 0.00pt 71.04pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-140.jpg" alt="" style=" width:343.20pt; height:354.72pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:63.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Figure 10-4, a web server farm is separated from the application and the database servers. This is done to protect the application and the database in case the web servers are compromised.</span></div>
<div class=paragraph style=" padding:6.00pt 40.32pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">You can also segment the data center by separating other types of application servers and devices. It is a best practice to separate all your management servers. For example,</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 208.80pt; text-align:justify;"><span class=font4>Data Center Segmentation and Tiered Access Control <b>305</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:61.20pt;">
<div class=paragraph style=" padding:0.00pt 64.56pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">your management segment can include your TACACS+, RADIUS, SNMP, and any configuration management servers such as CiscoWorks, Cisco Security Manager,</span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>CS-MARS, and others.</span></div>
<div class=paragraph style=" padding:7.20pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Figure 10-5 shows how management servers can also be separated from the rest of the data center.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 279.36pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 10-5 </b><span class=font43><i>Management Servers Segmented</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:411.84pt; height:344.64pt; padding:0.00pt 37.20pt 0.00pt 36.96pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-141.jpg" alt="" style=" width:411.84pt; height:344.64pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">As previously mentioned, you can segment your data center simply by configuring separate VLANs; however, this does not truly provide a complete solution that allows you to enforce your security policies between each boundary. Therefore, you can configure firewalls to provide additional security while allowing the necessary traffic to pass between segments.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:61.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>306    </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:68.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>You can also segment your data center by configuring Virtual Routing and Forwarding</span></span></div>
<div class=paragraph style=" padding:0.24pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">(VRF) interfaces with Multiprotocol Label Switching (MPLS) or by using VRF-Lite. This is more suitable for large environments and requires your staff to be familiar with more advanced routing features such as MPLS. The next section explains how to achieve segmentation using separate VLANs and the Cisco FWSM for policy enforcement and additional protection.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><b>Segmenting the Data Center with the Cisco FWSM</b></span></div>
<div class=paragraph style=" padding:3.36pt 39.12pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In this section, you will learn how to take advantage of some of the Cisco FWSM features to segment your data center. It covers the modes of operation of the FWSM, design considerations, and configuration steps.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:190.56pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Cisco FWSM Modes of Operation and Design Considerations</span></div>
<div class=paragraph style=" padding:4.08pt 49.20pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can use the Cisco FWSM not only to segment your data center, but also to enforce policy and to provide additional security benefits such as stateful and deep packet inspection. You can configure the Cisco FWSM in two different modes:</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 111.12pt; text-align:left; text-indent:-13.68pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Routed mode: </b>The default behavior. The Cisco FWSM in routed mode acts as a Layer 3 device supporting features such as Network Address Translation (NAT) and routing protocols. In most cases, when a Cisco FWSM is deployed in routed mode in the data center, it becomes the default gateway for a majority of the servers.</span></div>
<div class=paragraph style=" padding:3.84pt 38.40pt 0.00pt 111.12pt; text-align:left; text-indent:-13.68pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Transparent mode: </b>The Cisco FWSM acts as a Layer 2 device. One of the major benefits of transparent mode is that you do not have to worry about readdressing your infrastructure when deploying a new firewall within your data center, because the firewall acts as a bridge between the external and internal network. On the other hand, when you are operating in transparent mode, the FWSM does not support features such as NAT routing protocols and some specific inspections engines that depend</span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 111.60pt; text-align:left;"><span class=font44>on NAT.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:67.20pt;">
<div class=paragraph style=" padding:0.00pt 52.08pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>Routed and transparent modes are also supported in the Cisco ASA and the Cisco PIX security appliances. In smaller environments, you can deploy the Cisco ASA at the data center. The configuration is identical except that the Cisco FWSM runs in the Catalyst 6500 series switches or in the Cisco 7600 series routers; therefore, specific configuration steps are needed in the switch or the router. This subject is covered later in this section.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 128.88pt 0.00pt 89.76pt; text-align:justify;"><span class=font44>Figure 10-6 shows a Cisco FWSM configured in transparent mode.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:49.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 208.80pt; text-align:justify;"><span class=font4>Data Center Segmentation and Tiered Access Control <b>307</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 270.96pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 10-6 </b><span class=font43><i>Cisco FWSM in Transparent Mode</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:111.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:47.52pt; height:20.40pt; padding:0.00pt 189.12pt 0.00pt 249.36pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-142.jpg" alt="" style=" width:47.52pt; height:20.40pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.72pt;">
<div class=paragraph style=" padding:0.00pt 173.04pt 0.00pt 276.48pt; text-align:justify;"><span class=font1 style=" line-height:7.20pt;">(Outside) Vlan 100 10.10.10.0/24</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:140.16pt; height:177.60pt; padding:0.00pt 173.04pt 0.00pt 172.80pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-143.jpg" alt="" style=" width:140.16pt; height:177.60pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:111.12pt;">
<div class=paragraph style=" padding:0.00pt 44.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Figure 10-6, the Cisco FWSM outside interface resides on VLAN 100, and the inside interface resides on VLAN 101. Both interfaces belong to the same network subnet (10.10.10.0/24). The Cisco FWSM must have a management IP address configured for traffic to pass through it when configured in transparent mode. In this example, the management IP address is 10.10.10.123.</span></div>
<div class=paragraph style=" padding:6.00pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can take advantage of the virtualization capabilities of the Cisco FWSM to segment your data center. You can partition the Cisco FWSM into multiple virtual firewalls, known as <i>security contexts. </i>Each of these virtual firewalls has its own configuration enforcing separate security policies to each segment in the data center.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:79.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:137.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:180.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>308    </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:69.84pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>When you have multiple virtual security contexts configured, it is similar to having multiple standalone firewalls. Many features are supported when you configure the Cisco FWSM with multiple contexts, including routing tables, firewall features, and management. However, certain features are not supported, including dynamic routing protocols.</span></span></div>
<div class=paragraph style=" padding:2.88pt 51.12pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Cisco ASA and Cisco PIX security appliances also support virtual firewalls. Their behavior is similar to the Cisco FWSM.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:109.44pt;">
<div class=paragraph style=" padding:0.00pt 105.84pt 0.00pt 0.00pt; text-align:right;"><span class=font44>Figure 10-7 illustrates the four modes of operations of the Cisco FWSM:</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Single context routed mode</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Single context transparent mode</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Multiple context routed mode</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Multiple context transparent mode</span></div>
<div class=paragraph style=" padding:8.40pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 10-7 </b><span class=font43><i>Cisco FWSM Modes of Operation</i></span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 233.28pt; text-align:left;"><span class=font4>FWSM</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:166.08pt; height:52.80pt; padding:0.00pt 160.32pt 0.00pt 159.60pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-144.jpg" alt="" style=" width:166.08pt; height:52.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:274.32pt;">
<div class=block style=" width:274.32pt; height:15.60pt;">
<div class=paragraph style=" padding:3.36pt 92.88pt 0.00pt 137.76pt; text-align:justify;"><span class=font4>Single Mode</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:211.68pt;">
<div class=block style=" width:211.68pt; height:15.60pt;">
<div class=paragraph style=" padding:0.00pt 138.72pt 0.00pt 30.72pt; text-align:center;"><span class=font4 style=" line-height:9.60pt;">Multicontext Mode</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:137.76pt;">
<div class=block style=" width:137.76pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 5.28pt 0.00pt 107.76pt; text-align:justify;"><span class=font4>Routed</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:136.56pt;">
<div class=block style=" width:136.56pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 54.24pt 0.00pt 39.84pt; text-align:justify;"><span class=font4>Transparent</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 6.24pt 0.00pt 0.00pt; text-align:justify;"><span class=font4>Routed</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.72pt;">
<div class=block style=" width:180.72pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 99.36pt 0.00pt 38.88pt; text-align:justify;"><span class=font4>Transparent</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:68.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 40.80pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Figure 10-8 shows a Cisco FWSM configured with three different contexts. Each context includes its own configuration to protect each data center segment.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:123.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:137.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:136.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:180.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:195.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:132.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:158.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 208.80pt; text-align:justify;"><span class=font4>Data Center Segmentation and Tiered Access Control <b>309</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 315.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 10-8 </b><span class=font43><i>Cisco FWSM Contexts</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 196.32pt 0.00pt 195.12pt; text-align:justify;"><span class=font3>Outside Interface VLAN 40</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:348.48pt; height:193.44pt; padding:0.00pt 69.36pt 0.00pt 68.16pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-145.jpg" alt="" style=" width:348.48pt; height:193.44pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:195.12pt;">
<div class=block style=" width:195.12pt; height:39.36pt;">
<div class=paragraph style=" padding:0.00pt 35.04pt 0.00pt 87.84pt; text-align:left; text-indent:13.44pt;"><span class=font3 style=" line-height:19.68pt;">Web Servers Context Webservers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 53.04pt; text-align:center;"><span class=font3>VLAN 10</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:132.48pt;">
<div class=block style=" width:132.48pt; height:39.36pt;">
<div class=paragraph style=" padding:0.00pt 49.44pt 0.00pt 11.76pt; text-align:justify;"><span class=font3 style=" line-height:19.68pt;">Application Servers Context APPservers</span></div>
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 0.00pt; text-align:center;"><span class=font3>VLAN 20</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:158.40pt;">
<div class=block style=" width:158.40pt; height:39.36pt;">
<div class=paragraph style=" padding:0.00pt 93.60pt 0.00pt 0.96pt; text-align:justify;"><span class=font3>Database Servers</span></div>
<div class=paragraph style=" padding:11.28pt 91.92pt 0.00pt 17.28pt; text-align:left; text-indent:-17.28pt;"><span class=font3 style=" line-height:9.60pt;">Context DBservers VLAN 30</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 42.72pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">In Figure 10-8, the Cisco FWSM contexts separate the web servers, applications servers, and database servers. The following are the context names:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.80pt;">
<div class=paragraph style=" padding:0.00pt 328.32pt 0.00pt 111.60pt; text-align:justify;"><span class=font44 style=" line-height:15.84pt;">Webservers APPservers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.48pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>• DBservers</span></div>
<div class=paragraph style=" padding:4.56pt 36.72pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.24pt;">The inside interface of context Webservers resides in VLAN 10. The inside interface of context APPservers is in VLAN 20, and the context DBserver inside interface is in VLAN 30.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring the Cisco Catalyst Switch</span></div>
<div class=paragraph style=" padding:4.08pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the Cisco Catalyst switch, you must create the necessary VLANs and assign those to the Cisco FWSM. Example 10-3 shows the commands used to create VLANs 10, 20, 30, and 40 in the Cisco Catalyst 6500 switch.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:113.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:195.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:132.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:158.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>310   </b><span class=font4>Chapter 10: Data Center Security</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 275.52pt 0.00pt 36.24pt; text-align:justify;"><span class=font3><b>Example 10-3 </b><span class=font43><i>Creating the VLANs in the Switch</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:107.76pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:107.76pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:335.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.92pt;">
<div class=block style=" width:25.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>vlan</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:335.28pt;">
<div class=block style=" width:335.28pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>10</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.92pt;">
<div class=block style=" width:25.92pt; height:14.16pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>name</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>!</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:335.28pt;">
<div class=block style=" width:335.28pt; height:14.16pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>webservers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.92pt;">
<div class=block style=" width:25.92pt; height:14.88pt;">
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>vlan</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:335.28pt;">
<div class=block style=" width:335.28pt; height:14.88pt;">
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>20</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.92pt;">
<div class=block style=" width:25.92pt; height:14.64pt;">
<div class=paragraph style=" padding:0.00pt 2.64pt 0.00pt 7.68pt; text-align:left; text-indent:-0.24pt;"><span class=font23 style=" line-height:7.92pt;">name !</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:335.28pt;">
<div class=block style=" width:335.28pt; height:14.64pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>appservers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.92pt;">
<div class=block style=" width:25.92pt; height:14.16pt;">
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>vlan</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:335.28pt;">
<div class=block style=" width:335.28pt; height:14.16pt;">
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>30</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.92pt;">
<div class=block style=" width:25.92pt; height:14.64pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>name</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:335.28pt;">
<div class=block style=" width:335.28pt; height:14.64pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>dbservers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.92pt;">
<div class=block style=" width:25.92pt; height:14.64pt;">
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>vlan</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:335.28pt;">
<div class=block style=" width:335.28pt; height:14.64pt;">
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>40</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.92pt;">
<div class=block style=" width:25.92pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>name</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:335.28pt;">
<div class=block style=" width:335.28pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>tocorpnetwork</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:335.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:82.56pt;">
<div class=paragraph style=" padding:0.00pt 39.12pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Each VLAN entry is configured with a descriptive name based on the data center segment. You then have to assign the VLANs to the Cisco FWSM. Example 10-4 shows how you can create firewall VLAN groups and then assign the group to the Cisco FWSM.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-4 </b><span class=font43><i>Assigning the VLANs to the Cisco FWSM</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 248.88pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">firewall multiple-vlan-interfaces firewall module 2 vlan-group 1 firewall vlan-group 1 10,20,30,40</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 64.80pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Example 10-4, a VLAN group with ID of 1 is configured. This VLAN group includes VLANs 10, 20, 30, and 40 and is applied to the Cisco FWSM with the <b>firewall module 2 vlan-group 1 </b>command. The number 2 indicates that the Cisco FWSM resides on the second slot in the Cisco Catalyst 6500 switch.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:67.20pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 36.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;"><b>TIP&nbsp;</b>For security reasons, by default, only one switch virtual interface (SVI) can exist between</span></div>
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">the switch and the Cisco FWSM. You might also choose to use multiple SVIs in routed mode so that you do not have to share a single VLAN for the outside interface. You can use the <b>firewall multiple-vlan-interfaces </b>command to allow you to add more than one SVI to the Cisco FWSM. In this example, the outside interfaces of each context reside on</span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>VLAN 40.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:37.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:74.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Creating Security Contexts in the Cisco FWSM</span></div>
<div class=paragraph style=" padding:4.08pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">When you configure the Cisco FWSM in multiple context modes, you add and manage all security contexts in the system space or system configuration mode. By default, a context named <i>admin </i>is created. The admin context is just like any other context, except that when a user logs into the admin context, that user has system administrator rights and can access the system and all other contexts. The admin context is not restricted in any</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:77.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 208.80pt; text-align:justify;"><span class=font4>Data Center Segmentation and Tiered Access Control <span class=font44><b>311</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">way and can be used as a regular context. However, because logging into the admin context grants you administrator privileges over all contexts, you might need to restrict access to the admin context for appropriate users.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.88pt;">
<div class=paragraph style=" padding:0.00pt 39.12pt 0.00pt 36.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;"><b>TIP&nbsp;</b>The admin context configuration must reside on flash memory and not on a remote system.</span></div>
<div class=paragraph style=" padding:0.24pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">If your system is already in multiple context mode, or if you convert from single mode, the admin context is created automatically as a file on the internal flash memory called &quot;admin.cfg.&quot; This context is named &quot;admin.&quot; If you do not want to use admin.cfg as the admin context, you can change the admin context.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.48pt;">
<div class=paragraph style=" padding:0.00pt 37.20pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Because the default mode in the Cisco FWSM is single routed mode, to start creating security context, you need to change the FWSM to multiple mode. You can use the <b>mode multiple </b>command from configuration mode to enable multiple mode, as shown here:</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23>FWSM(config)# mode multiple</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.20pt;">
<div class=paragraph style=" padding:0.00pt 78.96pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>NOTE        </b>After you enter the <b>mode multiple </b>command, you are prompted to reboot the</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>Cisco FWSM.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:206.88pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Example 10-5 shows the context configuration on the Cisco FWSM that was pictured in the previous example.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-5 </b><span class=font43><i>Creating the Security Contexts</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">context webservers</span></div>
<div class=paragraph style=" padding:0.24pt 248.64pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">description Webserver segment allocate-interface vlan40 int1 allocate-interface vlan10 int2 config-url disk:/webservers.cfg</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">context appservers</span></div>
<div class=paragraph style=" padding:0.24pt 218.88pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">description Application server segment allocate-interface vlan50 int1 allocate-interface vlan20 int2 config-url disk:/appservers.cfg</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">context dbservers</span></div>
<div class=paragraph style=" padding:0.24pt 227.52pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">description Database servers segment allocate-interface vlan60 int1 allocate-interface vlan30 int2 config-url disk:/dbservers.cfg</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:82.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:207.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:158.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>312    </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:114.48pt;">
<div class=paragraph style=" padding:0.00pt 49.44pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The contexts webservers, appservers, and dbservers are defined in Example 10-5. Each security context or virtual firewall has two interfaces.</span></div>
<div class=paragraph style=" padding:6.00pt 42.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In this example, the configuration of each security context is stored locally and not on an external server. After the contexts have been created, you can change to any of them by using the <b>changeto context </b>command, as shown here:</span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23>FWSM(config)# changeto context webservers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23>FWSM/webservers(config)#</span></div>
<div class=paragraph style=" padding:4.56pt 42.24pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Notice that the prompt changes with the hostname followed by the context name you are currently configuring.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring the Interfaces on Each Security Context</span></div>
<div class=paragraph style=" padding:4.32pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The interface identifiers on each security context that were previously created were int1 for the outside interface and int 2 for the inside interface. Figure 10-9 shows the IP address configuration of the interfaces on each security context (virtual firewall).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.28pt;">
<div class=paragraph style=" padding:0.00pt 213.60pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 10-9 </b><span class=font43><i>IP Address Configuration on Each Virtual Firewall</i></span></span></div>
<div class=paragraph style=" padding:7.44pt 0.00pt 0.00pt 231.84pt; text-align:left;"><span class=font4>MSFC</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:360.48pt; height:57.12pt; padding:0.00pt 63.12pt 0.00pt 62.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-146.jpg" alt="" style=" width:360.48pt; height:57.12pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:207.12pt;">
<div class=block style=" width:207.12pt; height:18.72pt;">
<div class=paragraph style=" padding:0.00pt 60.00pt 0.00pt 111.12pt; text-align:left; text-indent:-9.12pt;"><span class=font1 style=" line-height:7.20pt;">Outside Interface 10.10.10.1 VLAN 40</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.48pt;">
<div class=block style=" width:120.48pt; height:18.72pt;">
<div class=paragraph style=" padding:0.00pt 62.40pt 0.00pt 22.08pt; text-align:left; text-indent:-9.12pt;"><span class=font1 style=" line-height:7.20pt;">Outside Interface 10.10.10.2 VLAN 50</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:158.40pt;">
<div class=block style=" width:158.40pt; height:18.72pt;">
<div class=paragraph style=" padding:0.00pt 102.48pt 0.00pt 19.68pt; text-align:left; text-indent:-9.12pt;"><span class=font1 style=" line-height:7.20pt;">Outside Interface 10.10.10.3</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 21.12pt; text-align:left;"><span class=font1>VLAN 60</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:207.12pt;">
<div class=block style=" width:26.88pt; height:51.84pt; padding:0.00pt 69.36pt 0.00pt 110.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-147.jpg" alt="" style=" width:26.88pt; height:51.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:120.48pt;">
<div class=block style=" width:27.36pt; height:51.84pt; padding:0.00pt 71.28pt 0.00pt 21.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-148.jpg" alt="" style=" width:27.36pt; height:51.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:158.40pt;">
<div class=block style=" width:26.88pt; height:51.84pt; padding:0.00pt 111.60pt 0.00pt 19.92pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-149.jpg" alt="" style=" width:26.88pt; height:51.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:207.12pt;">
<div class=block style=" width:207.12pt; height:38.40pt;">
<div class=paragraph style=" padding:0.00pt 62.16pt 0.00pt 104.64pt; text-align:center;"><span class=font1 style=" line-height:7.20pt;">Inside Interface 192.168.10.1</span></div>
<div class=paragraph style=" padding:0.00pt 46.80pt 0.00pt 88.56pt; text-align:left; text-indent:24.00pt;"><span class=font1 style=" line-height:18.00pt;">VLAN 10 <span class=font4>Context Webservers</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.48pt;">
<div class=block style=" width:120.48pt; height:38.40pt;">
<div class=paragraph style=" padding:0.00pt 64.80pt 0.00pt 15.36pt; text-align:center;"><span class=font1 style=" line-height:7.20pt;">Inside Interface 192.168.20.1</span></div>
<div class=paragraph style=" padding:0.00pt 49.20pt 0.00pt 0.00pt; text-align:left; text-indent:23.52pt;"><span class=font1 style=" line-height:18.00pt;">VLAN 20 <span class=font4>Context APPservers</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:158.40pt;">
<div class=block style=" width:158.40pt; height:38.40pt;">
<div class=paragraph style=" padding:0.00pt 104.88pt 0.00pt 13.20pt; text-align:center;"><span class=font1 style=" line-height:7.20pt;">Inside Interface 192.168.30.1</span></div>
<div class=paragraph style=" padding:0.00pt 91.92pt 0.00pt 0.00pt; text-align:left; text-indent:21.12pt;"><span class=font1 style=" line-height:18.00pt;">VLAN 30 <span class=font4>Context DBservers</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:145.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:207.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:158.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.32pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 208.80pt; text-align:justify;"><span class=font4>Data Center Segmentation and Tiered Access Control <b>313</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:393.60pt;">
<div class=paragraph style=" padding:0.00pt 36.96pt 0.00pt 0.00pt; text-align:right;"><span class=font44>Example 10-6 shows the configuration of the interfaces on the Webservers security context.</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-6 </b><span class=font43><i>webservers Security Context IP Address Configuration</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 317.28pt 0.00pt 101.28pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">interface int1 nameif outside security-level 0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 10.10.10.1 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 308.64pt 0.00pt 101.28pt; text-align:justify; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">interface int2 nameif inside security-level 100</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 192.168.10.1 255.255.255.0</span></div>
<div class=paragraph style=" padding:19.92pt 36.96pt 0.00pt 0.00pt; text-align:right;"><span class=font44>Example 10-7 shows the configuration of the interfaces on the APPservers security context.</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-7 </b><span class=font43><i>appservers Security Context IP Address Configuration</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 317.28pt 0.00pt 101.28pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">interface int1 nameif outside security-level 0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 10.10.10.2 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 308.64pt 0.00pt 101.28pt; text-align:justify; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">interface int2 nameif inside security-level 100</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 192.168.20.1 255.255.255.0</span></div>
<div class=paragraph style=" padding:19.92pt 36.96pt 0.00pt 0.00pt; text-align:right;"><span class=font44>Example 10-8 shows the configuration of the interfaces on the DBservers security context.</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-8 </b><span class=font43><i>dbservers Security Context IP Address Configuration</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 317.28pt 0.00pt 101.28pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">interface int1 nameif outside security-level 0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 10.10.10.3 255.255.255.0</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 308.64pt 0.00pt 101.28pt; text-align:justify; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.60pt;">interface int2 nameif inside security-level 100</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">ip address 192.168.30.1 255.255.255.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Configuring Network Address Translation</span></div>
<div class=paragraph style=" padding:4.08pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The goal is to configure static NAT for each server residing on each security context. Three systems reside in the web server segment (context webservers). This is illustrated in</span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44>Figure 10-10.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:102.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>314   </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 260.88pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 10-10 </b><span class=font43><i>webserver IP Address Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:155.28pt; height:105.12pt; padding:0.00pt 164.88pt 0.00pt 165.84pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:155.28pt; height:105.12pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:77.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.16pt;">
<div class=block style=" width:56.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:77.52pt;">
<div class=block style=" width:77.52pt; height:9.84pt;">
<div class=paragraph style=" padding:3.60pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font1>Outside Interface</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.16pt;">
<div class=block style=" width:56.16pt; height:7.20pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:7.20pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:77.52pt;">
<div class=block style=" width:77.52pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font1>10.10.10.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.16pt;">
<div class=block style=" width:56.16pt; height:8.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:8.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:77.52pt;">
<div class=block style=" width:77.52pt; height:8.88pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font1>VLAN 40</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.16pt;">
<div class=block style=" width:56.16pt; height:36.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:36.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:77.52pt;">
<div class=block style=" width:77.52pt; height:36.48pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font31 style=" letter-spacing:-0.50pt;">ESJi</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.16pt;">
<div class=block style=" width:56.16pt; height:42.72pt;">
<div class=paragraph style=" padding:19.44pt 7.92pt 0.00pt 6.24pt; text-align:left;"><span class=font4 style=" line-height:9.60pt;">Context Webservers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:42.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:77.52pt;">
<div class=block style=" width:77.52pt; height:42.72pt;">
<div class=paragraph style=" padding:20.16pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font1>Inside Interface</span></div>
<div class=paragraph style=" padding:0.72pt 40.56pt 0.00pt 3.12pt; text-align:left; text-indent:0.48pt;"><span class=font1 style=" line-height:7.20pt;">192.168.10.1 VLAN 10</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:77.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:119.04pt; height:59.04pt; padding:0.00pt 182.64pt 0.00pt 184.32pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-150.jpg" alt="" style=" width:119.04pt; height:59.04pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.24pt;">
<div class=paragraph style=" padding:0.00pt 170.64pt 0.00pt 173.76pt; text-align:justify;"><span class=font27 style=" line-height:30.24pt;"><b><i>Щ   Щ Щ</i></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.64pt;">
<div class=paragraph style=" padding:0.00pt 160.80pt 0.00pt 159.60pt; text-align:justify;"><span class=font4>Web-Server 1 Web-Server 2   Web-Server 3</span></div>
<div class=paragraph style=" padding:0.96pt 0.24pt 0.00pt 0.00pt; text-align:center;"><span class=font1>192.168.10.51      192.168.10.52 192.168.10.53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:42.24pt;">
<div class=paragraph style=" padding:0.00pt 39.36pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Table 10-1 lists the physical IP addresses of each web server with the statically translated address.</span></div>
<div class=paragraph style=" padding:11.28pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4><b>Table 10-1    </b><span class=font43><i>Web Servers NAT Mapping</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.44pt; height:76.80pt; padding:0.00pt 35.04pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.44pt; height:76.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:126.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:115.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:126.24pt;">
<div class=block style=" width:126.24pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Web Server Name</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.28pt;">
<div class=block style=" width:119.28pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Translated IP Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:115.92pt;">
<div class=block style=" width:115.92pt; height:19.44pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Physical IP Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:126.24pt;">
<div class=block style=" width:126.24pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Web-Server 1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.28pt;">
<div class=block style=" width:119.28pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font43>10.10.10.51</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:115.92pt;">
<div class=block style=" width:115.92pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font43>192.168.10.51</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:126.24pt;">
<div class=block style=" width:126.24pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Web-Server 2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.28pt;">
<div class=block style=" width:119.28pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font43>10.10.10.52</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:115.92pt;">
<div class=block style=" width:115.92pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font43>192.168.10.52</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:126.24pt;">
<div class=block style=" width:126.24pt; height:19.44pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Web-Server 3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.28pt;">
<div class=block style=" width:119.28pt; height:19.44pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font43>10.10.10.53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:115.92pt;">
<div class=block style=" width:115.92pt; height:19.44pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font43>192.168.10.53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:126.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:115.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph style=" padding:0.00pt 60.96pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Example 10-9 shows the static NAT configuration for each server on the webservers security context.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-9 </b><span class=font43><i>webservers Context NAT Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:30.00pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:30.00pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:51.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:60.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:34.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt;">
<div class=block style=" width:35.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23>static</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.24pt;">
<div class=block style=" width:72.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>(inside,outside)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.84pt;">
<div class=block style=" width:51.84pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>10.10.10.51</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:60.00pt;">
<div class=block style=" width:60.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>192.168.10.51</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:34.32pt;">
<div class=block style=" width:34.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>netmask</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:107.76pt;">
<div class=block style=" width:107.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt;">
<div class=block style=" width:35.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23>static</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.24pt;">
<div class=block style=" width:72.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>(inside,outside)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.84pt;">
<div class=block style=" width:51.84pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>10.10.10.52</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:60.00pt;">
<div class=block style=" width:60.00pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>192.168.10.52</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:34.32pt;">
<div class=block style=" width:34.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>netmask</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:107.76pt;">
<div class=block style=" width:107.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt;">
<div class=block style=" width:35.04pt; height:10.80pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23>static</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.24pt;">
<div class=block style=" width:72.24pt; height:10.80pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>(inside,outside)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.84pt;">
<div class=block style=" width:51.84pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>10.10.10.53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:60.00pt;">
<div class=block style=" width:60.00pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>192.168.10.53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:34.32pt;">
<div class=block style=" width:34.32pt; height:10.80pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>netmask</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:107.76pt;">
<div class=block style=" width:107.76pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:51.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:60.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:34.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:59.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:167.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:156.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:162.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 208.80pt; text-align:justify;"><span class=font4>Data Center Segmentation and Tiered Access Control <b>315</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph style=" padding:0.00pt 57.84pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Two application servers are in the data center as illustrated in Figure 10-11. They are protected by the virtual firewall (context) called APPservers.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 10-11 </b><span class=font43><i>Application Servers IP Address Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:167.76pt;">
<div class=block style=" width:167.76pt; height:162.48pt;layout-flow:vertical-ideographic;">
</div>
</td>
<td class=cell valign="top" style=" width:156.24pt;">
<div class=block style=" width:156.24pt; height:162.48pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:156.24pt; height:162.48pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:78.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:78.00pt;">
<div class=block style=" width:78.00pt; height:34.32pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 59.76pt; text-align:left;"><span class=font48 style=" letter-spacing:4.50pt;">1*</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:34.32pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.96pt; text-align:left;"><span class=font49 style=" line-height:19.20pt;"><b>p</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:9.12pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:9.12pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:9.12pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font1>Outside Interface</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:7.20pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:7.20pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font1>10.10.10.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:8.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:8.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:8.88pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font1>VLAN 40</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:36.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:36.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:36.72pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font48 style=" letter-spacing:-0.50pt;">si</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:42.00pt;">
<div class=paragraph style=" padding:19.44pt 8.16pt 0.00pt 6.48pt; text-align:left;"><span class=font4 style=" line-height:9.60pt;">Context APPservers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:42.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:42.00pt;">
<div class=paragraph style=" padding:19.20pt 33.84pt 0.00pt 3.60pt; text-align:left; text-indent:0.48pt;"><span class=font1 style=" line-height:7.20pt;">Inside Interface 192.168.20.1</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font1>VLAN 20</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:78.00pt;">
<div class=block style=" width:78.00pt; height:24.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:24.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:78.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:162.00pt;">
<div class=block style=" width:162.00pt; height:162.48pt;layout-flow:vertical-ideographic;">
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:155.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 176.64pt; text-align:left;"><span class=font29 style=" line-height:7.68pt; letter-spacing:-16.00pt;"><b><i>A,</i></b></span></div>
<div class=paragraph style=" padding:0.48pt 3.12pt 0.00pt 0.00pt; text-align:center;"><span class=font4 style=" line-height:7.68pt;">APP-Server 1&nbsp;APP-Server 2</span></div>
<div class=paragraph style=" padding:0.00pt 3.12pt 0.00pt 0.00pt; text-align:center;"><span class=font1 style=" line-height:7.68pt;">192.168.20.71 192.168.20.72</span></div>
<div class=paragraph style=" padding:12.48pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Table 10-2 lists the physical IP addresses of each application server along with the statically translated address.</span></div>
<div class=paragraph style=" padding:11.28pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4><b>Table 10-2   </b><span class=font43><i>Application Servers NAT Mapping</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.92pt; height:58.08pt; padding:0.00pt 34.80pt 0.00pt 89.28pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.92pt; height:58.08pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:127.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:127.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:127.68pt;">
<div class=block style=" width:127.68pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Server Name</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:127.20pt;">
<div class=block style=" width:127.20pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font4><b>Translated IP Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:107.04pt;">
<div class=block style=" width:107.04pt; height:19.44pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Physical IP Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:127.68pt;">
<div class=block style=" width:127.68pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>APP-Server 1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:127.20pt;">
<div class=block style=" width:127.20pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font43>10.10.20.71</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:107.04pt;">
<div class=block style=" width:107.04pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font43>192.168.20.71</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:127.68pt;">
<div class=block style=" width:127.68pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>APP-Server 2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:127.20pt;">
<div class=block style=" width:127.20pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font43>10.10.20.72</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:107.04pt;">
<div class=block style=" width:107.04pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font43>192.168.20.72</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:127.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:127.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph style=" padding:0.00pt 58.32pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Example 10-10 shows the static NAT configuration for each server on the appservers security context.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-10 </b><span class=font43><i>appservers Context NAT Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:20.40pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:20.40pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:51.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:59.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:34.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt;">
<div class=block style=" width:35.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23>static</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.24pt;">
<div class=block style=" width:72.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>(inside,outside)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.84pt;">
<div class=block style=" width:51.84pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>10.10.20.71</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.76pt;">
<div class=block style=" width:59.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>192.168.20.71</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:34.56pt;">
<div class=block style=" width:34.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>netmask</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:107.76pt;">
<div class=block style=" width:107.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt;">
<div class=block style=" width:35.04pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23>static</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.24pt;">
<div class=block style=" width:72.24pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>(inside,outside)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.84pt;">
<div class=block style=" width:51.84pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>10.10.20.72</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.76pt;">
<div class=block style=" width:59.76pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>192.168.20.72</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:34.56pt;">
<div class=block style=" width:34.56pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>netmask</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:107.76pt;">
<div class=block style=" width:107.76pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:51.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:59.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:34.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:107.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:63.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:167.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:156.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:162.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>316    </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The data center has two database servers, as illustrated in Figure 10-12. They are protected by the virtual firewall (context) called DBservers.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 10-12 </b><span class=font43><i>Database Servers IP Address Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:35.76pt; height:22.56pt; padding:0.00pt 223.68pt 0.00pt 226.56pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-151.jpg" alt="" style=" width:35.76pt; height:22.56pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:156.24pt; height:128.64pt; padding:0.00pt 163.44pt 0.00pt 166.32pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:156.24pt; height:128.64pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:24.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:78.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.00pt;">
<div class=block style=" width:54.00pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.00pt;">
<div class=block style=" width:24.00pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:9.60pt;">
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font1>Outside Interface</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.00pt;">
<div class=block style=" width:54.00pt; height:7.20pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.00pt;">
<div class=block style=" width:24.00pt; height:7.20pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:7.20pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font1>10.10.10.3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.00pt;">
<div class=block style=" width:54.00pt; height:8.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.00pt;">
<div class=block style=" width:24.00pt; height:8.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:8.88pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font1>VLAN 40</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.00pt;">
<div class=block style=" width:54.00pt; height:36.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.00pt;">
<div class=block style=" width:24.00pt; height:36.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:36.72pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font48 style=" letter-spacing:-0.50pt;">si</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.00pt;">
<div class=block style=" width:54.00pt; height:42.00pt;">
<div class=paragraph style=" padding:19.44pt 10.56pt 0.00pt 6.72pt; text-align:left;"><span class=font4 style=" line-height:9.60pt;">Context DBservers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.00pt;">
<div class=block style=" width:24.00pt; height:42.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:42.00pt;">
<div class=paragraph style=" padding:20.16pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font1>Inside Interface</span></div>
<div class=paragraph style=" padding:0.72pt 41.28pt 0.00pt 3.12pt; text-align:left; text-indent:0.48pt;"><span class=font1 style=" line-height:7.20pt;">192.168.30.1 VLAN 20</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:78.00pt;">
<div class=block style=" width:78.00pt; height:24.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.24pt;">
<div class=block style=" width:78.24pt; height:24.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:24.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:78.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:82.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:73.68pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 163.44pt; text-align:left;"><span class=font4>DB-Server 1&nbsp;DB-Server 2</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 164.64pt; text-align:left;"><span class=font1>192.168.30.101 192.168.30.102</span></div>
<div class=paragraph style=" padding:13.44pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Table 10-3 lists the physical IP addresses of each application server along with the statically translated address.</span></div>
<div class=paragraph style=" padding:11.28pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4><b>Table 10-3   </b><span class=font43><i>Database Servers NAT Mapping</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.92pt; height:58.08pt; padding:0.00pt 34.80pt 0.00pt 89.28pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.92pt; height:58.08pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:118.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:123.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:118.32pt;">
<div class=block style=" width:118.32pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Server Name</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.60pt;">
<div class=block style=" width:123.60pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font4><b>Translated IP Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.00pt;">
<div class=block style=" width:120.00pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Physical IP Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:118.32pt;">
<div class=block style=" width:118.32pt; height:18.96pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>DB-Server 1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.60pt;">
<div class=block style=" width:123.60pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font43>10.10.30.101</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.00pt;">
<div class=block style=" width:120.00pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font43>192.168.30.101</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:118.32pt;">
<div class=block style=" width:118.32pt; height:19.68pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>DB-Server 2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.60pt;">
<div class=block style=" width:123.60pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font43>10.10.30.102</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:120.00pt;">
<div class=block style=" width:120.00pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font43>192.168.30.102</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:118.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:123.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Example 10-11 shows the static NAT configuration for each server on the DBservers security context.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-11 </b><span class=font43><i>dbservers Context NAT Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:20.40pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:20.40pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:55.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:64.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:34.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:99.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt;">
<div class=block style=" width:35.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23>static</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.24pt;">
<div class=block style=" width:72.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>(inside,outside)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:55.92pt;">
<div class=block style=" width:55.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>10.10.30.101</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:64.32pt;">
<div class=block style=" width:64.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>192.168.30.101</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:34.32pt;">
<div class=block style=" width:34.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>netmask</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:99.36pt;">
<div class=block style=" width:99.36pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt;">
<div class=block style=" width:35.04pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23>static</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.24pt;">
<div class=block style=" width:72.24pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>(inside,outside)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:55.92pt;">
<div class=block style=" width:55.92pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>10.10.30.102</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:64.32pt;">
<div class=block style=" width:64.32pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>192.168.30.102</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:34.32pt;">
<div class=block style=" width:34.32pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>netmask</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:99.36pt;">
<div class=block style=" width:99.36pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:55.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:64.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:34.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:99.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:63.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 208.80pt; text-align:justify;"><span class=font4>Data Center Segmentation and Tiered Access Control <b>317</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:125.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Controlling Access with ACLs</span></div>
<div class=paragraph style=" padding:4.08pt 49.44pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">It is recommended that you configure ACLs on both interfaces of each security context for more granular security policy enforcement. You can tune the ACLs based on your security policies and application usage. The ACLs that are configured on each of the security contexts in this example only allow the necessary traffic for each server and application.</span></div>
<div class=paragraph style=" padding:6.24pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Table 10-4 lists the protocols and ports that need to be allowed on the webservers security context.</span></div>
<div class=paragraph style=" padding:11.28pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4><b>Table 10-4   </b><span class=font43><i>Protocols and Ports Used by the webservers</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.68pt; height:137.04pt; padding:0.00pt 34.80pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.68pt; height:137.04pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:122.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt;">
<div class=block style=" width:125.04pt; height:17.52pt;">
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Usage/Application</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:122.16pt;">
<div class=block style=" width:122.16pt; height:17.52pt;">
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Protocol or Port</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:114.48pt;">
<div class=block style=" width:114.48pt; height:17.52pt;">
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Allowed by ACL</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt;">
<div class=block style=" width:125.04pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>HTTP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:122.16pt;">
<div class=block style=" width:122.16pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 80</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:114.48pt;">
<div class=block style=" width:114.48pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt;">
<div class=block style=" width:125.04pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>HTTPS</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:122.16pt;">
<div class=block style=" width:122.16pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 443</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:114.48pt;">
<div class=block style=" width:114.48pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt;">
<div class=block style=" width:125.04pt; height:17.04pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>SSH<sup>1</sup>/SCP<sup>2</sup></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:122.16pt;">
<div class=block style=" width:122.16pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>TCP 22</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:114.48pt;">
<div class=block style=" width:114.48pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt;">
<div class=block style=" width:125.04pt; height:16.80pt;">
<div class=paragraph style=" padding:3.60pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Mgmt-App</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:122.16pt;">
<div class=block style=" width:122.16pt; height:16.80pt;">
<div class=paragraph style=" padding:3.60pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 890</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:114.48pt;">
<div class=block style=" width:114.48pt; height:16.80pt;">
<div class=paragraph style=" padding:3.60pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt;">
<div class=block style=" width:125.04pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>App-X</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:122.16pt;">
<div class=block style=" width:122.16pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>TCP 987</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:114.48pt;">
<div class=block style=" width:114.48pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>outbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt;">
<div class=block style=" width:125.04pt; height:17.04pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>DNS<sup>3</sup></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:122.16pt;">
<div class=block style=" width:122.16pt; height:17.04pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>UDP<sup>4</sup> 53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:114.48pt;">
<div class=block style=" width:114.48pt; height:17.04pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>outbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt;">
<div class=block style=" width:125.04pt; height:17.52pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>SYSLOG</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:122.16pt;">
<div class=block style=" width:122.16pt; height:17.52pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>UDP 514</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:114.48pt;">
<div class=block style=" width:114.48pt; height:17.52pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>outbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:122.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:240.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.48pt; text-align:left;"><span class=font43 style=" line-height:13.92pt;">1&nbsp;SSH = Secure Shell</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font43 style=" line-height:13.92pt;">2&nbsp;SCP = Secure Copy Protocol</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font43 style=" line-height:13.92pt;">3&nbsp;DNS = Domain Name System</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font43 style=" line-height:13.92pt;">4&nbsp;UDP = User Datagram Protocol</span></div>
<div class=paragraph style=" padding:4.32pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Users connect to the web servers via HTTP and HTTPS; therefore, this traffic is allowed on the outside interface in the webservers context. The web servers are Linux-based machines. The administrator transfers files over SCP and connects to the server command-line interface (CLI) via SSH. In addition, the administrator uses a custom management application to install software and patches on the systems (Mgmt-App). This traffic from the management network (10.10.100.0/24) needs to be allowed.</span></div>
<div class=paragraph style=" padding:5.76pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The web servers themselves need to access an application called App-X running on the servers in the APPservers context over TCP port 987. DNS resolution and SYSLOG must also be allowed to external servers. Example 10-12 shows the ACLs configured in the Webservers context allowing the previously mentioned ports and protocols.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-12 </b><span class=font43><i>webservers Context ACL Configuration</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 60.24pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list inbound-traffic remark INBOUND TRAFFIC TO WEBSERVERS access-list inbound-traffic extended permit tcp any host 10.10.10.51 eq www access-list inbound-traffic extended permit tcp any host 10.10.10.51 eq https</span></div>
<div class=paragraph style=" padding:1.68pt 38.64pt 0.00pt 0.00pt; text-align:right;"><span class=font43><i>continues</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:216.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:269.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>318    </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 203.52pt 0.00pt 36.24pt; text-align:justify;"><span class=font3><b>Example 10-12 </b><span class=font43><i>webservers Context ACL Configuration (Continued)</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:216.96pt;">
<div class=block style=" width:216.96pt; height:350.16pt;">
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list inbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.84pt;">10.10.10.51 eq ssh access-list inbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.10.51&nbsp;eq 890 access-list inbound-traffic access-list inbound-traffic access-list inbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.10.52&nbsp;eq ssh access-list inbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.10.52&nbsp;eq 890 access-list inbound-traffic access-list inbound-traffic access-list inbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.84pt;">10.10.10.53&nbsp;eq ssh access-list inbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.10.53 eq 890 access-group inbound-traffic</span></div>
<div class=paragraph style=" padding:9.60pt 1.44pt 0.00pt 96.96pt; text-align:justify;"><span class=font23 style=" line-height:9.84pt;">access-list outbound-traffic access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.20.71&nbsp;eq 987 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.20.72&nbsp;eq 987 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.84pt;">10.10.111.11&nbsp;eq 53 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.111.12&nbsp;eq 53 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.100.100 eq 514 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.84pt;">10.10.20.71&nbsp;eq 987 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.20.72&nbsp;eq 987 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.111.11&nbsp;eq 53 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.84pt;">10.10.111.12&nbsp;eq 53 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.100.100 eq 514</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:269.04pt;">
<div class=block style=" width:269.04pt; height:350.16pt;">
<div class=paragraph style=" padding:0.00pt 56.16pt 0.00pt 0.00pt; text-align:justify;"><span class=font23>extended permit tcp 10.10.100.0 255.255.255.0 host</span></div>
<div class=paragraph style=" padding:10.08pt 56.16pt 0.00pt 0.00pt; text-align:justify;"><span class=font23>extended permit tcp 10.10.100.0 255.255.255.0 host</span></div>
<div class=paragraph style=" padding:8.88pt 56.16pt 0.00pt 0.00pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">extended permit tcp any host 10.10.10.52 eq www extended permit tcp any host 10.10.10.52 eq https extended permit tcp 10.10.100.0 255.255.255.0 host</span></div>
<div class=paragraph style=" padding:9.12pt 56.16pt 0.00pt 0.00pt; text-align:justify;"><span class=font23>extended permit tcp 10.10.100.0 255.255.255.0 host</span></div>
<div class=paragraph style=" padding:9.12pt 56.16pt 0.00pt 0.00pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">extended permit tcp any host 10.10.10.53 eq www extended permit tcp any host 10.10.10.53 eq https extended permit tcp 10.10.100.0 255.255.255.0 host</span></div>
<div class=paragraph style=" padding:9.12pt 56.16pt 0.00pt 0.00pt; text-align:justify;"><span class=font23>extended permit tcp 10.10.100.0 255.255.255.0 host</span></div>
<div class=paragraph style=" padding:9.84pt 0.00pt 0.00pt 4.56pt; text-align:left;"><span class=font23>in interface outside</span></div>
<div class=paragraph style=" padding:10.32pt 77.52pt 0.00pt 4.32pt; text-align:left;"><span class=font23 style=" line-height:9.84pt;">remark OUTBOUND TRAFFIC FROM WEBSERVERS extended permit tcp   host 192.168.10.51 host</span></div>
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font23 style=" line-height:17.76pt;">extended&nbsp;permit&nbsp;tcp&nbsp;host&nbsp;192.168.10.51 host</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font23 style=" line-height:17.76pt;">extended&nbsp;permit&nbsp;udp&nbsp;host&nbsp;192.168.10.51 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font23 style=" line-height:17.76pt;">extended&nbsp;permit&nbsp;udp&nbsp;host&nbsp;192.168.10.51 host</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font23 style=" line-height:17.76pt;">extended&nbsp;permit&nbsp;udp&nbsp;host&nbsp;192.168.10.51 host</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font23 style=" line-height:17.76pt;">extended&nbsp;permit&nbsp;tcp&nbsp;host&nbsp;192.168.10.52 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font23 style=" line-height:17.76pt;">extended&nbsp;permit&nbsp;tcp&nbsp;host&nbsp;192.168.10.52 host</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font23 style=" line-height:17.76pt;">extended&nbsp;permit&nbsp;udp&nbsp;host&nbsp;192.168.10.52 host</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font23 style=" line-height:17.76pt;">extended&nbsp;permit&nbsp;udp&nbsp;host&nbsp;192.168.10.52 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font23 style=" line-height:17.76pt;">extended&nbsp;permit&nbsp;udp&nbsp;host&nbsp;192.168.10.52 host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:95.76pt;">
<div class=paragraph style=" padding:0.00pt 77.52pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list outbound-traffic extended permit tcp   host 192.168.10.53 host</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.20.71&nbsp;eq 987</span></div>
<div class=paragraph style=" padding:1.92pt 77.52pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list outbound-traffic extended permit tcp   host 192.168.10.53 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.20.72&nbsp;eq 987</span></div>
<div class=paragraph style=" padding:1.68pt 77.52pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list outbound-traffic extended permit udp   host 192.168.10.53 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.111.11&nbsp;eq 53</span></div>
<div class=paragraph style=" padding:1.92pt 77.52pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list outbound-traffic extended permit udp   host 192.168.10.53 host</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.111.12&nbsp;eq 53</span></div>
<div class=paragraph style=" padding:1.92pt 77.52pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list outbound-traffic extended permit udp   host 192.168.10.53 host</span></div>
<div class=paragraph style=" padding:0.00pt 180.00pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.100.100 eq 514 access-group outbound-traffic in interface inside</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 47.04pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">In Example 10-12, ACLs are configured to allow the traffic specified in Table 10-4. The ACL named <b>inbound-traffic </b>is applied to the outside interface, and the ACL named</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:60.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:216.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:269.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 208.80pt; text-align:justify;"><span class=font4>Data Center Segmentation and Tiered Access Control <b>319</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:120.00pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><b>outbound-traffic </b>is applied to the inside interface. Notice that the web server IP addresses in the <b>inbound-traffic </b>ACL are the translated addresses. However, because the <b>outbound-traffic </b>ACL is applied to the inside interface, the physical IP addresses are used as the source. The web servers must access two DNS servers. The primary DNS server is 10.10.111.11, and the secondary is 10.10.111.12. The IP address of the SYSLOG server is</span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 90.72pt; text-align:left;"><span class=font44>10.10.100.100.</span></div>
<div class=paragraph style=" padding:6.96pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Table 10-5 lists the necessary protocols and ports that need to be allowed on the appservers security context.</span></div>
<div class=paragraph style=" padding:11.28pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4><b>Table 10-5   </b><span class=font43><i>Protocols and Ports Used by the appservers</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.92pt; height:134.16pt; padding:0.00pt 34.56pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.92pt; height:134.16pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:123.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.52pt;">
<div class=block style=" width:119.52pt; height:19.68pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Usage/Application</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:19.68pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Protocol and/or port</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.36pt;">
<div class=block style=" width:123.36pt; height:19.68pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font4><b>Allowed by ACL</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.52pt;">
<div class=block style=" width:119.52pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>App-X</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>TCP 987</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.36pt;">
<div class=block style=" width:123.36pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.52pt;">
<div class=block style=" width:119.52pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>SSH/SCP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>TCP 22</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.36pt;">
<div class=block style=" width:123.36pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.52pt;">
<div class=block style=" width:119.52pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Mgmt-App</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>TCP 890</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.36pt;">
<div class=block style=" width:123.36pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.52pt;">
<div class=block style=" width:119.52pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>MySQL</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>TCP 3306</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.36pt;">
<div class=block style=" width:123.36pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>outbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.52pt;">
<div class=block style=" width:119.52pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>DNS</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>UDP 53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.36pt;">
<div class=block style=" width:123.36pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>outbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.52pt;">
<div class=block style=" width:119.52pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>SYSLOG</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:119.04pt;">
<div class=block style=" width:119.04pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>UDP 514</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.36pt;">
<div class=block style=" width:123.36pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>outbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:119.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:123.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:128.40pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The web servers communicate with the application (App-X) running on the servers in the APPservers context over TCP port 987. Similar to the web servers, the administrator transfers files over SCP and connects to the server CLI via SSH. In addition, the administrator uses a custom management application to install software and patches on the systems (Mgmt-App). This management traffic from the management network (10.10.100.0/24) needs to be allowed. The application servers connect to the database servers running MySQL over TCP port 3306. DNS resolution and SYSLOG must also be allowed to external servers.</span></div>
<div class=paragraph style=" padding:6.24pt 38.16pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Example 10-13 shows the ACLs configured in the appservers context allowing the ports and protocols listed in Table 10-6.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-13 </b><span class=font43><i>appservers Context ACL Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.04pt;">
<div class=paragraph style=" padding:0.00pt 115.44pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list inbound-traffic remark INBOUND TRAFFIC TO APPSERVERS</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:348.96pt; height:106.56pt; padding:0.00pt 41.52pt 0.00pt 95.52pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:348.96pt; height:106.56pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:68.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:38.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:17.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:51.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 2.88pt 0.00pt 9.84pt; text-align:justify; text-indent:-8.40pt;"><span class=font23 style=" line-height:8.16pt;">access-list eq 987</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:68.40pt;">
<div class=block style=" width:68.40pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>extended</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>permit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:17.28pt;">
<div class=block style=" width:17.28pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.36pt;">
<div class=block style=" width:51.36pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.10.51</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.20.71</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:17.76pt;">
<div class=paragraph style=" padding:0.00pt 2.88pt 0.00pt 9.84pt; text-align:justify; text-indent:-8.40pt;"><span class=font23 style=" line-height:8.16pt;">access-list eq 987</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:68.40pt;">
<div class=block style=" width:68.40pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>extended</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>permit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:17.28pt;">
<div class=block style=" width:17.28pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.36pt;">
<div class=block style=" width:51.36pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.10.52</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.20.71</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:18.00pt;">
<div class=paragraph style=" padding:0.24pt 2.88pt 0.00pt 9.84pt; text-align:justify; text-indent:-8.40pt;"><span class=font23 style=" line-height:8.16pt;">access-list eq 987</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:68.40pt;">
<div class=block style=" width:68.40pt; height:18.00pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:18.00pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>extended</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:18.00pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>permit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:17.28pt;">
<div class=block style=" width:17.28pt; height:18.00pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:18.00pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.36pt;">
<div class=block style=" width:51.36pt; height:18.00pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.10.53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:18.00pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:18.00pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.20.71</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:17.76pt;">
<div class=paragraph style=" padding:0.00pt 2.88pt 0.00pt 9.84pt; text-align:justify; text-indent:-8.40pt;"><span class=font23 style=" line-height:8.16pt;">access-list eq 987</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:68.40pt;">
<div class=block style=" width:68.40pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>extended</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>permit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:17.28pt;">
<div class=block style=" width:17.28pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.36pt;">
<div class=block style=" width:51.36pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.10.51</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.20.72</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:17.76pt;">
<div class=paragraph style=" padding:0.00pt 2.88pt 0.00pt 9.84pt; text-align:justify; text-indent:-8.40pt;"><span class=font23 style=" line-height:8.16pt;">access-list eq 987</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:68.40pt;">
<div class=block style=" width:68.40pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>extended</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>permit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:17.28pt;">
<div class=block style=" width:17.28pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.36pt;">
<div class=block style=" width:51.36pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.10.52</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.20.72</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 2.88pt 0.00pt 9.84pt; text-align:justify; text-indent:-8.40pt;"><span class=font23 style=" line-height:8.16pt;">access-list eq 987</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:68.40pt;">
<div class=block style=" width:68.40pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.64pt;">
<div class=block style=" width:38.64pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>extended</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>permit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:17.28pt;">
<div class=block style=" width:17.28pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.36pt;">
<div class=block style=" width:21.36pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:51.36pt;">
<div class=block style=" width:51.36pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.10.53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:50.16pt;">
<div class=block style=" width:50.16pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>10.10.20.72</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:68.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:38.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:17.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:51.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:2.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 413.28pt; text-align:justify;"><span class=font43><i>continues</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>320   </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.24pt; text-align:justify;"><span class=font3><b>Example 10-13 </b><span class=font43><i>appservers Context ACL Configuration (Continued)</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:285.60pt;">
<div class=paragraph style=" padding:0.00pt 56.16pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list inbound-traffic extended permit tcp 10.10.100.0 255.255.255.0 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.20.71&nbsp;eq 22</span></div>
<div class=paragraph style=" padding:1.92pt 56.16pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list inbound-traffic extended permit tcp 10.10.100.0 255.255.255.0 host</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.20.72&nbsp;eq 22</span></div>
<div class=paragraph style=" padding:1.92pt 56.16pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list inbound-traffic extended permit tcp 10.10.100.0 255.255.255.0 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.20.71&nbsp;eq 890</span></div>
<div class=paragraph style=" padding:1.68pt 56.16pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>access-list inbound-traffic extended permit tcp 10.10.100.0 255.255.255.0 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.20.72&nbsp;eq 890</span></div>
<div class=paragraph style=" padding:1.44pt 180.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">access-group inbound-traffic in interface outside <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.40pt 77.52pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list outbound-traffic remark OUTBOUND TRAFFIC FROM APPSERVERS access-list outbound-traffic extended permit tcp   host 192.168.20.71 host</span></div>
<div class=paragraph style=" padding:0.00pt 77.52pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.30.101 eq 3306 access-list outbound-traffic extended permit tcp   host 192.168.20.72 host</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.30.101&nbsp;eq 3306</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>access-list outbound-traffic extended permit tcp   host 192.168.20.71 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.30.102&nbsp;eq 3306</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>access-list outbound-traffic extended permit tcp   host 192.168.20.72 host</span></div>
<div class=paragraph style=" padding:0.00pt 77.52pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.30.102 eq 3306 access-list outbound-traffic extended permit udp   host 192.168.20.71 host</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.111.11 eq 53</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>access-list outbound-traffic extended permit udp   host 192.168.20.72 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.111.11&nbsp;eq 53</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>access-list outbound-traffic extended permit udp   host 192.168.20.71 host</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.111.12&nbsp;eq 53</span></div>
<div class=paragraph style=" padding:1.44pt 77.52pt 0.00pt 105.60pt; text-align:left; text-indent:-8.64pt;"><span class=font23 style=" line-height:8.16pt;">access-list outbound-traffic extended permit udp   host 192.168.20.72 host 10.10.111.12 eq 53</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>access-list outbound-traffic extended permit tcp   host 192.168.20.71 host</span></div>
<div class=paragraph style=" padding:0.00pt 77.52pt 0.00pt 96.96pt; text-align:justify; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.100.100 eq 514 access-list outbound-traffic extended permit tcp   host 192.168.20.72 host</span></div>
<div class=paragraph style=" padding:0.00pt 180.00pt 0.00pt 96.96pt; text-align:justify; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.100.100 eq 514 access-group outbound-traffic in interface inside</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.24pt;">
<div class=paragraph style=" padding:0.00pt 47.04pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Example 10-13, ACLs are configured to allow the traffic specified in Table 10-5. The ACL named <b>inbound-traffic </b>is applied to the outside interface, and the ACL named <b>outbound-traffic </b>is applied to the inside interface.</span></div>
<div class=paragraph style=" padding:5.76pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Table 10-6 lists the necessary protocols and ports that need to be allowed on the DBservers security context.</span></div>
<div class=paragraph style=" padding:11.28pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4><b>Table 10-6   </b><span class=font43><i>Protocols and Ports Used by the dbservers</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:360.96pt; height:114.96pt; padding:0.00pt 35.52pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:360.96pt; height:114.96pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:123.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:113.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.08pt;">
<div class=block style=" width:124.08pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Usage/Application</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.84pt;">
<div class=block style=" width:123.84pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font4><b>Protocol and/or port</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:113.04pt;">
<div class=block style=" width:113.04pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Allowed by ACL</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.08pt;">
<div class=block style=" width:124.08pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>MySQL</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.84pt;">
<div class=block style=" width:123.84pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>TCP 3306</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:113.04pt;">
<div class=block style=" width:113.04pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.08pt;">
<div class=block style=" width:124.08pt; height:18.96pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>SSH)/SCP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.84pt;">
<div class=block style=" width:123.84pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>TCP 22</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:113.04pt;">
<div class=block style=" width:113.04pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.08pt;">
<div class=block style=" width:124.08pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Mgmt-App</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.84pt;">
<div class=block style=" width:123.84pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>TCP 890</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:113.04pt;">
<div class=block style=" width:113.04pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.08pt;">
<div class=block style=" width:124.08pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>DNS</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.84pt;">
<div class=block style=" width:123.84pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>UDP 53</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:113.04pt;">
<div class=block style=" width:113.04pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>outbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.08pt;">
<div class=block style=" width:124.08pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>SYSLOG</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.84pt;">
<div class=block style=" width:123.84pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>UDP 514</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:113.04pt;">
<div class=block style=" width:113.04pt; height:19.68pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>outbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:123.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:113.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:221.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:81.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:183.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 208.80pt; text-align:justify;"><span class=font4>Data Center Segmentation and Tiered Access Control <b>321</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:141.60pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The application servers communicate with the MySQL database running on the servers in the DBservers context over TCP port 3306. Linux-based servers also exist, and the administrator transfers files over SCP and connects to the server CLI via SSH. As with the other servers, the administrator uses the custom management application to install software and patches on the systems (Mgmt-App). This management traffic from the management network (10.10.100.0/24) needs to be allowed. DNS resolution and SYSLOG must also be allowed to external servers.</span></div>
<div class=paragraph style=" padding:6.24pt 42.96pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Example 10-14 shows the ACLs configured in the APPservers context allowing the ports and protocols listed in Table 10-6.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 10-14 </b><span class=font43><i>dbservers Context ACL Configuration</i></span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 89.52pt; text-align:left;"><span class=font3>I <span class=font23>access-list inbound-traffic remark INBOUND TRAFFIC TO DATABASE SERVERS</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:349.68pt; height:62.64pt; padding:0.00pt 40.80pt 0.00pt 95.52pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:349.68pt; height:62.64pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:67.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:38.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:20.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.92pt;">
<div class=block style=" width:49.92pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 2.64pt 0.00pt 1.20pt; text-align:center;"><span class=font23 style=" line-height:8.16pt;">access-list eq 3306</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:67.92pt;">
<div class=block style=" width:67.92pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.16pt;">
<div class=block style=" width:38.16pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>extended</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>permit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.12pt;">
<div class=block style=" width:21.12pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:50.88pt;">
<div class=block style=" width:50.88pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>10.10.20.71</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.88pt;">
<div class=block style=" width:20.88pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:54.48pt;">
<div class=block style=" width:54.48pt; height:17.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>10.10.30.101</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.92pt;">
<div class=block style=" width:49.92pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 1.20pt; text-align:center;"><span class=font23 style=" line-height:8.16pt;">access-list eq 3306</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:67.92pt;">
<div class=block style=" width:67.92pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.16pt;">
<div class=block style=" width:38.16pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>extended</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>permit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.12pt;">
<div class=block style=" width:21.12pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:50.88pt;">
<div class=block style=" width:50.88pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>10.10.20.72</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.88pt;">
<div class=block style=" width:20.88pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:54.48pt;">
<div class=block style=" width:54.48pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>10.10.30.101</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.92pt;">
<div class=block style=" width:49.92pt; height:17.76pt;">
<div class=paragraph style=" padding:0.24pt 2.64pt 0.00pt 1.20pt; text-align:center;"><span class=font23 style=" line-height:8.16pt;">access-list eq 3306</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:67.92pt;">
<div class=block style=" width:67.92pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.16pt;">
<div class=block style=" width:38.16pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>extended</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>permit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.12pt;">
<div class=block style=" width:21.12pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:50.88pt;">
<div class=block style=" width:50.88pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>10.10.20.71</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.88pt;">
<div class=block style=" width:20.88pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:54.48pt;">
<div class=block style=" width:54.48pt; height:17.76pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>10.10.30.102</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.92pt;">
<div class=block style=" width:49.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 1.44pt 0.00pt 0.00pt; text-align:center;"><span class=font23>access-list</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:67.92pt;">
<div class=block style=" width:67.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>inbound-traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:38.16pt;">
<div class=block style=" width:38.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>extended</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>permit</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.12pt;">
<div class=block style=" width:21.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:50.88pt;">
<div class=block style=" width:50.88pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>10.10.20.72</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.88pt;">
<div class=block style=" width:20.88pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font23>host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:54.48pt;">
<div class=block style=" width:54.48pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>10.10.30.102</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:67.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:38.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:20.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23>eq 3306</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:302.88pt;">
<div class=block style=" width:302.88pt; height:68.16pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>access-list inbound-traffic extended permit tcp</span></div>
<div class=paragraph style=" padding:0.00pt 5.52pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.30.101&nbsp;eq 22 access-list inbound-traffic extended permit tcp</span></div>
<div class=paragraph style=" padding:0.00pt 5.52pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.60pt;">10.10.30.102&nbsp;eq 22 access-list inbound-traffic extended permit tcp</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">10.10.30.101</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">eq 890</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list inbound-traffic extended permit tcp</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:183.12pt;">
<div class=block style=" width:183.12pt; height:68.16pt;">
<div class=paragraph style=" padding:0.00pt 56.16pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:17.76pt;">10.10.100.0&nbsp;255.255.255.0&nbsp;host</span></div>
<div class=paragraph style=" padding:0.00pt 56.16pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:17.76pt;">10.10.100.0&nbsp;255.255.255.0&nbsp;host</span></div>
<div class=paragraph style=" padding:0.00pt 56.16pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:17.76pt;">10.10.100.0&nbsp;255.255.255.0&nbsp;host</span></div>
<div class=paragraph style=" padding:14.88pt 56.16pt 0.00pt 0.00pt; text-align:justify;"><span class=font23>10.10.100.0&nbsp;255.255.255.0&nbsp;host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23>10.10.30.102</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>eq 890</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:221.28pt;">
<div class=block style=" width:221.28pt; height:124.56pt;">
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">access-group inbound-traffic <sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 5.76pt 0.00pt 96.96pt; text-align:justify;"><span class=font23 style=" line-height:9.84pt;">access-list outbound-traffic access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.12pt;">10.10.111.11 eq 53 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.12pt;">10.10.111.11&nbsp;eq 53 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.12pt;">10.10.111.12&nbsp;eq 53 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.12pt;">10.10.111.12 eq 53 access-list outbound-traffic</span></div>
<div class=paragraph style=" padding:0.00pt 5.76pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.12pt;">10.10.100.100 eq 514 access-list outbound-traffic</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:264.72pt;">
<div class=block style=" width:264.72pt; height:124.56pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font23>in interface outside</span></div>
<div class=paragraph style=" padding:10.32pt 72.96pt 0.00pt 0.24pt; text-align:justify;"><span class=font23 style=" line-height:9.84pt;">remark OUTBOUND&nbsp;TRAFFIC FROM DATABASE SERVERS</span></div>
<div class=paragraph style=" padding:0.00pt 73.20pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:9.84pt;">extended permit&nbsp;udp&nbsp;host&nbsp;192.168.30.101 host</span></div>
<div class=paragraph style=" padding:3.84pt 73.20pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:17.76pt;">extended permit&nbsp;udp&nbsp;host&nbsp;192.168.30.102 host</span></div>
<div class=paragraph style=" padding:0.00pt 73.20pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:17.76pt;">extended permit&nbsp;udp&nbsp;host&nbsp;192.168.30.101 host</span></div>
<div class=paragraph style=" padding:0.24pt 73.20pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:17.76pt;">extended permit&nbsp;udp&nbsp;host&nbsp;192.168.30.102 host</span></div>
<div class=paragraph style=" padding:0.00pt 73.20pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:17.76pt;">extended permit&nbsp;tcp&nbsp;host&nbsp;192.168.30.101 host</span></div>
<div class=paragraph style=" padding:0.00pt 73.20pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:17.76pt;">extended permit&nbsp;tcp&nbsp;host&nbsp;192.168.30.102 host</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph style=" padding:0.00pt 180.00pt 0.00pt 96.96pt; text-align:left; text-indent:8.64pt;"><span class=font23 style=" line-height:9.84pt;">10.10.100.100 eq 514 access-group outbound-traffic in interface inside</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 47.04pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Example 10-14, ACLs are configured to allow the traffic specified in Table 10-6. The ACL named <b>inbound-traffic </b>is applied to the outside interface, and the ACL named <b>outbound-traffic </b>is applied to the inside interface.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:72.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:221.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:81.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:183.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>322   </b><span class=font4>Chapter 10: Data Center Security</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:121.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font6><a name="bookmark79">V</a>irtual Fragment Reassembly</span></div>
<div class=paragraph style=" padding:4.08pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Cisco FWSM, Cisco ASA, and Cisco PIX security appliances drop fragments. However, many different applications generate fragments. If you enable fragment forwarding, you open yourself to fragment attacks (like the ones defined in RFC 1858). You can use the Virtual Fragment Reassembly feature to protect against this type of attack. You enable Virtual Fragment Reassembly with the <b>fragment </b>command. In the following example, the Cisco FWSM is limiting its fragment buffer size to 200 packets on its outside and inside interfaces.</span></div>
<div class=paragraph style=" padding:6.48pt 282.48pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">fragment size 200 outside fragment size 200 inside</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph style=" padding:0.00pt 45.12pt 0.00pt 36.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;"><b>TIP&nbsp;</b>By using the <b>chain </b>and <b>timeout </b>options in the <b>fragment </b>command, you can also define</span></div>
<div class=paragraph style=" padding:0.00pt 58.56pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">the maximum number of fragments to be chained together and the length of time the Cisco FWSM waits for the fragments to arrive before discarding them.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:168.00pt;">
<div class=paragraph style=" padding:0.00pt 156.96pt 0.00pt 36.24pt; text-align:left;"><span class=font11 style=" line-height:18.24pt;"><a href="#bookmark76"><b>Deploying Network Intrusion Detection </b></a><b>and Prevention Systems</b></span></div>
<div class=paragraph style=" padding:2.88pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can use network IDS/IPS appliances in small-to-medium organizations or the Cisco IDSM-2 for the Cisco Catalyst 6500 series switches in larger organizations. The implementation of each solution depends on the size of your data center and its requirements. When designing a network IDS/IPS solution for the data center, for both scalability and manageability, you should reduce the amount of traffic that is sent to the sensor. You should also avoid sending duplicate frames to the IDS/IPS sensors or modules. At the same time, you should avoid the situation in which you must change existing ACLs or VACLs before being able to implement an IDS/IPS solution. In most cases, you want to create several SPAN sessions to be able to send the traffic to multiple IDS/IPS devices. This section includes several best practices to use when you deploy an IDS/IPS solution in your data center.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><b>Sending Selective Traffic to the IDS/IPS Devices</b></span></div>
<div class=paragraph style=" padding:2.88pt 42.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Depending on the size of your data center, you may use one or more IPS/IDS devices. In large data centers, you can use several IDSMs to monitor the activity within your server farms. Figure 10-13 illustrates a data center with three different IDSMs installed on each Cisco Catalyst 6500 along with the Cisco FWSM.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:102.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 171.12pt; text-align:justify;"><span class=font4>Deploying Network Intrusion Detection and Prevention Systems <b>323</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:385.44pt; height:222.00pt; padding:0.00pt 64.08pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-152.jpg" alt="" style=" width:385.44pt; height:222.00pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:342.24pt; height:117.60pt; padding:0.00pt 72.48pt 0.00pt 71.28pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:342.24pt; height:117.60pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:131.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:6.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:80.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:6.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:81.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.20pt;">
<div class=block style=" width:37.20pt; height:44.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font21><b>Г</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:131.04pt;">
<div class=block style=" width:131.04pt; height:44.64pt;">
<div class=paragraph style=" text-align:left;"><span class=font28 style=" line-height:51.84pt; letter-spacing:-0.50pt;">т<span style=" letter-spacing:0.00pt;"> </span>rf</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:6.00pt;">
<div class=block style=" width:6.00pt; height:44.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:44.64pt;">
<div class=paragraph style=" padding:0.00pt 10.56pt 0.00pt 0.00pt; text-align:right;"><span class=font19 style=" line-height:57.60pt; letter-spacing:4.00pt;"><b>ft</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:6.00pt;">
<div class=block style=" width:6.00pt; height:44.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:81.12pt;">
<div class=block style=" width:81.12pt; height:44.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.20pt;">
<div class=block style=" width:37.20pt; height:72.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:131.04pt;">
<div class=block style=" width:131.04pt; height:72.96pt;">
<div class=paragraph style=" padding:57.12pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font4>Web/Front-End Servers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:6.00pt;">
<div class=block style=" width:6.00pt; height:72.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:72.96pt;">
<div class=paragraph style=" padding:56.88pt 6.24pt 0.00pt 0.00pt; text-align:right;"><span class=font4>Application Servers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:6.00pt;">
<div class=block style=" width:6.00pt; height:72.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:81.12pt;">
<div class=block style=" width:81.12pt; height:72.96pt;">
<div class=paragraph style=" padding:27.60pt 0.00pt 0.00pt 10.80pt; text-align:left;"><span class=font24>те</span></div>
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 9.12pt; text-align:left;"><span class=font4>Database Servers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:131.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:6.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:80.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:6.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:81.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:117.12pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In some cases, exposing IPS/IDS sensors to all the traffic that flows within a data center can oversubscribe the IPS/IDS devices. To avoid performance problems in the data center, some administrators prefer to use only IDS features (promiscuous inspection) instead of inline IPS services. Others prefer to limit the number of protocols or the type of traffic to which a sensor is assigned. For example, in the high-level data center topology illustrated in Figure 10-13, you can selectively send traffic from each data center segment to specific IDSMs. For instance, you may want to send all web-related traffic on the webservers segment to the first IDSM. Similarly, you may want to send all traffic that traverses the application server segment to the second IDSM, and traffic destined and originated by the database servers to the third IDSM. This is illustrated in Figure 10-14.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:72.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:252.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:144.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>324   </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 218.64pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 10-14 </b><span class=font43><i>Sending Selective Traffic to the IDS/IPS Devices</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:322.08pt; height:193.44pt; padding:0.00pt 72.24pt 0.00pt 91.68pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-153.jpg" alt="" style=" width:322.08pt; height:199.20pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:252.00pt;">
<div class=block style=" width:24.96pt; height:24.96pt; padding:0.00pt 145.92pt 4.80pt 81.12pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-154.jpg" alt="" style=" width:24.96pt; height:24.96pt;"></div>
</td>
<td class=cell colspan="2" valign="top" style=" width:234.00pt;">
<div class=block style=" width:234.00pt; height:29.76pt;">
<div class=paragraph style=" padding:0.00pt 174.96pt 0.00pt 11.04pt; text-align:justify;"><span class=font37 style=" line-height:31.68pt; letter-spacing:17.50pt;"><b><i>ii</i></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:252.00pt;">
<div class=block style=" width:252.00pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 54.72pt 0.00pt 113.76pt; text-align:justify;"><span class=font4>Web/Front-End Servers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:89.76pt;">
<div class=block style=" width:89.76pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 21.36pt 0.00pt 0.00pt; text-align:justify;"><span class=font4>Application Servers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:144.24pt;">
<div class=block style=" width:144.24pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 81.12pt 0.00pt 0.00pt; text-align:justify;"><span class=font4>Database Servers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:237.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Based on VLAN information, you can use a SPAN session to differentiate traffic on multiple ports. This is supported on the Cisco Catalyst 6500 starting from Cisco IOS Versions 12.2(18)SXD and 12.1(24)E. You can configure a single SPAN session to capture traffic from the three VLANs and send traffic from each VLAN to a specific IDSM or external sensor. With this configuration, the IDS/IPS devices can inspect client-to-server traffic, locally switched traffic, and server-to-server routed traffic.</span></div>
<div class=paragraph style=" padding:6.00pt 39.12pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Alternatively, you can use VACL capture. You do this by simply configuring three VACLs with the <b>forward capture </b>action and assigning them to the three different segments. You assign IDSM-A to the web servers segment, IDSM-B to the application servers segment, and IDSM-C to the database segment.</span></div>
<div class=paragraph style=" padding:6.24pt 37.92pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">In certain trunk environments, the use of VACLs achieves half the goal of this design. The IDSMs may still experience substantial noise traffic. In addition to this, you have to modify the security VACLs that might already be in place in the data center to include the capture action for the traffic that you want to monitor. To address this problem, you can use RSPAN and VACL redirect together. You can configure RSPAN to create a copy of the traffic from all the ports connecting the Catalyst 6500 to the core and to the server farms. All these frames are locally copied onto an RSPAN VLAN which is a special VLAN that is equally visible to three IDSMs. Then you configure VACL redirection. This does not permit or deny the traffic, it simply redirects the traffic to the desired IDSM. One VACL entry specifies that</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:252.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:144.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 180.00pt; text-align:justify;"><span class=font4>Deploying the Cisco Security Agent (CSA) in the Data Center <b>325</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 44.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">traffic to the web servers on the RSPAN VLAN be redirected to IDSM-1; another VACL entry specifies that traffic destined to the application servers on the RSPAN VLAN be redirected to IDSM-2; the same applies for the database server traffic to IDSM-3.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 36.48pt; text-align:right;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>You can find a detailed white paper on how to use RSPAN with VACLs for granular traffic analysis at <a href="http://www.cisco.com/warp/public/cc/pd/si/casi/ca6000/prodlit/rspan_wp.pdf">http://www.cisco.com/warp/public/cc/pd/si/casi/ca6000/prodlit/rspan_wp.pdf.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:146.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><a name="bookmark80"><b>M</b></a><b>onitoring and Tuning</b></span></div>
<div class=paragraph style=" padding:3.12pt 39.60pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Monitoring tools such as CS-MARS help not only to identify and detect security threads, but also to reduce steps in the tuning process. <i>Tuning </i>is the process of managing and minimizing the number of false positives and false negatives that the network IDS/IPS device reports. As you learned in previous chapters, a <i>false positive </i>is a benign network activity mistakenly identified as malicious by the sensor. A <i>false negative </i>is malicious network activity mistakenly identified as benign or not detected by the sensor. To tune sensors, you enable, disable, or modify the signatures used in the network. The tuning process is one of the most crucial operational tasks that you perform when increasing the security of your data center. In Chapter 3, &quot;Identifying and Classifying Security Threats,&quot; you learned best practices to use when deploying IDS/IPS devices. These same best practices apply in the data center.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:25.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:72.00pt;">
<div class=paragraph style=" padding:0.00pt 131.04pt 0.00pt 36.96pt; text-align:left;"><span class=font11 style=" line-height:18.00pt;"><a href="#bookmark76"><b>Deploying the Cisco Security Agent (CSA) </b></a><b>in the Data Center</b></span></div>
<div class=paragraph style=" padding:3.36pt 37.44pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">CSA provides several security features that are more robust than a traditional antivirus or a personal firewall. CSA not only protects against viruses, worms, and direct attacks, but it also protects against day-zero threats. CSA plays an important role in data center security.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:74.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>CSA Architecture</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the CSA solution architecture, a central management center maintains a database of policies and information about the workstations and servers on which the CSA software is installed. Agents register with the Cisco Security Agent Management Center (CSA-MC). Subsequently, the CSA-MC checks its configuration database and deploys a configured policy for that particular system.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt;">
<div class=block style=" width:89.76pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 29.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:396.24pt;">
<div class=block style=" width:396.24pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 40.56pt 0.00pt 0.24pt; text-align:justify;"><span class=font44 style=" line-height:12.24pt;">Starting with CSA Version 5.1, the CSA-MC is a standalone system. Prior to Version 5.1, CSA-MC was part of the Cisco Works VPN and Security Management System (VMS).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:60.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>326    </b>Chapter 10: Data Center Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 41.04pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The CSA software constantly monitors all activity on the end host and polls to the CSA-MC at configurable intervals for policy updates. The agent sends events and alerts to the global event manager of the CS-AMC. The global event manager inspects the event logs and then alerts the administrator or triggers the agent to take action based on the specific alert.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>All the communication between the agents and the CSA-MC is via Secure Socket Layer (SSL).</span></span></div>
<div class=paragraph style=" padding:1.92pt 41.76pt 0.00pt 0.00pt; text-align:right;"><span class=font44>The administrator also connects to the CSA-MC via SSL to manage and monitor the agents.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:411.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Configuring Agent Kits</b></span></div>
<div class=paragraph style=" padding:3.12pt 41.28pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">As previously mentioned, CSA-MC comes with preconfigured agent kits that can be used to fulfill initial security needs. However, CSA-MC allows you to create custom agent kits to fit your specific requirements. For example, you can create different agent kits for the various servers within your data center. To create a new agent kit, complete the following steps:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 1   </b><span class=font44>Choose <b>Systems </b>&gt; <b>Agent Kits </b>from the CSA-MC console.</span></span></div>
<div class=paragraph style=" padding:6.96pt 72.72pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 2 </b><span class=font44>Click <b>New </b>at the bottom of the page displayed. A dialog box appears asking you to specify the operating system on which the agent kit will be applied.</span></span></div>
<div class=paragraph style=" padding:6.24pt 74.40pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 3 </b><span class=font44>Enter a name and description for the new agent kit. For example, you can create agent kits for the web servers, application, and database servers in the examples in the previous sections.</span></span></div>
<div class=paragraph style=" padding:5.76pt 89.28pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.24pt;"><b>Step 4  </b><span class=font44>Select the groups that will be associated with this agent kit. You can select from predefined groups designed for different type of servers.</span></span></div>
<div class=paragraph style=" padding:5.76pt 74.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 5  </b><span class=font44>Optionally, you can select to reboot the system after the CSA installation is complete. You can also select a quiet install to avoid end-user interaction.</span></span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 6  </b><span class=font44>Click <b>Make Kit </b>to create the new agent kit.</span></span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 7  </b><span class=font44>Click <b>Generate Rules </b>to generate all pending rules. A new window</span></span></div>
<div class=paragraph style=" padding:0.72pt 74.16pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">appears with information about the rule generation. After you have made the appropriate selections, click <b>Generate.</b></span></div>
<div class=paragraph style=" padding:6.24pt 74.64pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 8 </b><span class=font44>All rules and configuration changes are applied at this point. A summary window appears if the rule generation completes successfully.</span></span></div>
<div class=paragraph style=" padding:22.08pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Phased Deployment</b></span></div>
<div class=paragraph style=" padding:3.36pt 60.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">When you start your CSA deployment, select the initial hosts on which CSA will be installed based on the following guidelines:</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Select at least one host per each distinct application or server environment.</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;During the pilot, make the test host a mirror sample of the production systems.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:37.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.32pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 384.24pt; text-align:justify;"><span class=font4>Summary <b>327</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:54.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:311.28pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 110.64pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;When installing CSA on servers, use a test machine for each server type to ensure that there is no negative impact from the CSA agent software installation.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font44>•&nbsp;Create a group for each type of application environment to be protected.</span></div>
<div class=paragraph style=" padding:5.04pt 38.64pt 0.00pt 89.28pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a name="bookmark81">B</a>uilding and tuning of CSA policies is a continuous task. You need to have the proper staff and procedures to minimize the administrative burden. The security staff is responsible not only for maintaining the CSAMC policies, but also for creating and organizing appropriate exception rules and for monitoring user activity. You can organize the exception rules as follows:</span></div>
<div class=paragraph style=" padding:6.00pt 42.00pt 0.00pt 110.64pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Create a global exception policy to allow legitimate traffic and application behavior that is required on all the systems within the organization. Subsequently, add these global exception rules to this exception policy.</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font44>•&nbsp;Create one exception policy for each group.</span></div>
<div class=paragraph style=" padding:4.80pt 60.96pt 0.00pt 110.64pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Apply these policies to their respective groups and collect all necessary data to complete any additional tuning.</span></div>
<div class=paragraph style=" padding:4.32pt 39.36pt 0.00pt 89.28pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The following summarizes the steps that your security staff should use when deploying the agent kits throughout the organization:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 89.52pt; text-align:left;"><span class=font4><b>Step 1  </b><span class=font44>Deploy the CSA agents in test mode throughout your organization.</span></span></div>
<div class=paragraph style=" padding:6.72pt 103.68pt 0.00pt 125.04pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 2  </b><span class=font44>Collect and analyze results. Subsequently, start policy tuning (as needed).</span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 89.52pt; text-align:left;"><span class=font4><b>Step 3  </b><span class=font44>Enable protection mode.</span></span></div>
<div class=paragraph style=" padding:6.96pt 75.60pt 0.00pt 125.28pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 4 </b><span class=font44>Make sure that your security, operations, and engineering staff members are comfortable with the support of your deployment.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:25.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:144.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font11><a href="#bookmark76"><b>Summary</b></a></span></div>
<div class=paragraph style=" padding:3.84pt 43.68pt 0.00pt 89.04pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In most cases, data centers are equipped with surveillance cameras, biometric locks, authorization-based access policies, strict security personnel, and other physical security options. However, data centers that use such precautions, and are therefore prepared for physical intrusions, often do not deploy the necessary technologies and tools to combat cyberattacks. A good balance between physical and network security is crucial.</span></div>
<div class=paragraph style=" padding:6.00pt 38.88pt 0.00pt 89.04pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This chapter covered several best practices to use when deploying Defense-in-Depth strategies to secure the data center. It discussed several tools and mechanisms to help you protect the data center against DoS, worms, and other security outbreaks. You learned several tips for segmenting your data center in a multilayered architecture. This chapter also covered some tips for deploying network IDS/IPS solutions and CSA in the data center.</span></div>
</div>
</td>
]]></content:encoded>
			<wfw:commentRss>http://ciscoasa.org.ua/2010/03/chapter-10-data-center-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter 9: IP Telephony Security</title>
		<link>http://ciscoasa.org.ua/2010/03/chapter-9-ip-telephony-security/</link>
		<comments>http://ciscoasa.org.ua/2010/03/chapter-9-ip-telephony-security/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 10:03:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[cisco unity]]></category>
		<category><![CDATA[custom tool]]></category>
		<category><![CDATA[defense in depth]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[ip phones]]></category>
		<category><![CDATA[ip telephony networks]]></category>
		<category><![CDATA[network elements]]></category>
		<category><![CDATA[network infrastructure]]></category>
		<category><![CDATA[network intelligence]]></category>
		<category><![CDATA[severity level]]></category>
		<category><![CDATA[video terminals]]></category>
		<category><![CDATA[voice systems]]></category>

		<guid isPermaLink="false">http://ciscoasa.org.ua/?p=264</guid>
		<description><![CDATA[

Cisco alone has sold more than 4.5 million IP phones and 3 million Cisco Unity unified messaging licenses. The company has more than 20,000 IP Communications customers. IP telephony or Voice over IP (VoIP) deployments are growing dramatically on a daily basis. Consequently, the need to secure IP telephony networks is also growing by the [...]]]></description>
			<content:encoded><![CDATA[<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:331.20pt;">
<div class=paragraph style=" padding:0.00pt 37.20pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Cisco alone has sold more than 4.5 million IP phones and 3 million Cisco Unity unified messaging licenses. The company has more than 20,000 IP Communications customers. IP telephony or Voice over IP (VoIP) deployments are growing dramatically on a daily basis. Consequently, the need to secure IP telephony networks is also growing by the minute. IP telephony security threats generally fall into one of two categories. The first category includes risks that are aimed to hijack listening or unauthorized listening to voice conversations (phone tapping). The second category includes risks that can compromise IP telephony communications with direct attacks to the network infrastructure, servers, and other systems, such as denial of service (DoS) attacks.</span></div>
<div class=paragraph style=" padding:6.00pt 42.48pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This chapter covers several best practices and strategies for building your infrastructure to successfully identify threats and react to them in a manner that is appropriate to each severity level. It shows how integrated security features must be implemented from end to end across all network elements to increase voice security. IP telephony security has four major elements:</span></div>
<div class=paragraph style=" padding:6.24pt 59.52pt 0.00pt 112.56pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Network infrastructure: </b>Routers, switches, firewalls, and other infrastructure components</span></div>
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44><b>•&nbsp;Call processing systems: </b>Call management, control, and accounting</span></div>
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44><b>•&nbsp;Endpoints: </b>IP phones, IP communicator software, video terminals, and so on</span></div>
<div class=paragraph style=" padding:5.04pt 37.20pt 0.00pt 112.56pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Applications: </b>Unified messaging software, conferencing applications, contact, and a custom tool</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 91.20pt; text-align:left;"><span class=font44>This chapter offers you different techniques to protect each element.</span></div>
<div class=paragraph style=" padding:6.72pt 38.40pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">IP telephony security requires the collaboration of security, network intelligence, and other services to minimize the impact of attacks and risks. With the collaboration of security technologies and network services, you can deploy Defense-in-Depth security that encompasses the entire network, including voice systems.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:121.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:84.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:311.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>262    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:391.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 41.76pt; text-align:left;"><span class=font11><a href="#bookmark60"><a name="bookmark71"><b>P</b></a><b>rotecting the IP Telephony Infrastructure</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The first step in IP telephony security is to make sure that you apply the best practices learned in previous chapters to protect the infrastructure as a whole. As previously mentioned, all the infrastructure components are networking devices deployed within your organization, such as:</span></div>
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Routers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Switches</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Firewalls</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Voice gateways</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Gatekeepers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">Figure 9-1 illustrates a common IP telephony deployment in a medium-to-large enterprise.</span></div>
<div class=paragraph style=" padding:3.84pt 41.52pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Figure 9-1, several infrastructure components are depicted within a headquarters main office topology, which demonstrates a layered approach. Within the main office segment of the figure, notice the different access, distribution, and core layers. A group of application servers, a Cisco Unified CallManager cluster, and Cisco Unity servers are deployed to provide different VoIP services to the organization. Within the illustrated topology, IP telephony endpoints include both regular IP phones and wireless phones, as well as IP conferencing systems. A voice gateway is deployed to connect to the public switched telephone network (PSTN).</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In this figure, voice services are also provided to branch offices, telecommuters, and remote access users. Although Figure 9-1 provides a high-level topology, it represents a highly available, fault-tolerant infrastructure that is based on common infrastructure guidelines. A well-designed infrastructure is essential for easier deployment of IP telephony and its integration with applications such as video streaming and video conferencing. As you learned in previous chapters, resiliency and high availability are crucial for security. As a best practice when designing your network infrastructure, always think about high availability, connectivity options for phones (such as in-line power), and quality of service (QoS) mechanisms. Make sure that you understand the call patterns for your organization.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph style=" padding:0.00pt 65.28pt 0.00pt 35.76pt; text-align:justify;"><span class=font4 style=" line-height:12.00pt;"><b>TIP&nbsp;</b><span class=font44>You can obtain VoIP provisioning recommendations and best practices listed in the</span></span></div>
<div class=paragraph style=" padding:0.24pt 99.84pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">whitepaper at <a href="http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_implementation_design_guide_chapter09186a008063743a.html">http://www.cisco.com/en/US/products/sw/voicesw/ps556/ products_implementation_design_guide_chapter09186a008063743a.html.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:121.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 258.72pt; text-align:justify;"><span class=font4>Protecting the IP Telephony Infrastructure <b>263</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:384.72pt; height:454.80pt; padding:0.00pt 64.80pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-126.jpg" alt="" style=" width:384.72pt; height:454.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:122.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>264   </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.28pt;">
<div class=paragraph style=" padding:0.00pt 39.12pt 0.00pt 36.48pt; text-align:left; text-indent:53.28pt;"><span class=font44 style=" line-height:20.16pt;">Figure 9-2 illustrates a typical regional site, branch office, or small enterprise deployment. <span class=font4><b>Figure 9-2   </b></span><span class=font43><i>Branch or Small Enterprise IP Telephony Deployment</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:356.16pt; height:296.64pt; padding:0.00pt 65.28pt 0.00pt 64.56pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-127.jpg" alt="" style=" width:356.16pt; height:296.64pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:91.20pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Figure 9-2, a Cisco IOS Software router running Cisco Unified Communications Manager Express is deployed. The Cisco Unified Communications Manager Express (formerly known as the Cisco CallManager Express) is an optional software feature that enables Cisco routers to deliver Key System or Hybrid PBX functionality for branch offices or small businesses. Also deployed is Cisco Unity Express, which is a Linux-based application that runs on Cisco IOS Software routers, using either Network Module (NM) or Advanced Integration Module (AIM) hardware to provide basic automated attendant and voice mail features.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:132.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 258.72pt; text-align:justify;"><span class=font4>Protecting the IP Telephony Infrastructure <b>265</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>Best practices to secure Cisco Unified CallManager, Cisco Unified Communications</span></span></div>
<div class=paragraph style=" padding:0.00pt 42.24pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Manager Express, Cisco Unity, and Unity Express are covered later in this chapter in the section &quot;Securing the IP Telephony Applications.&quot;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:348.96pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">All the infrastructure security recommendations you learned in previous chapters (such as Chapter 2, &quot;Preparation Phase&quot;) apply to IP telephony networks. It is, therefore, important that you follow those guidelines. For example, disable unnecessary services, implement infrastructure access control lists (ACL), and protect the control plane. This section shows you several other best practices and outline recommendations that are applicable strictly to voice implementations.</span></div>
<div class=paragraph style=" padding:6.24pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You should take a layered approach when securing your IP telephony infrastructure. Build security layer upon layer starting at the ports that your workstations and IP phones connect (access layer), and work your way to the distribution, core, and data center. Figure 9-3 illustrates the different layers within an enterprise network.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following layers are illustrated in Figure 9-3:</span></div>
<div class=paragraph style=" padding:6.96pt 56.16pt 0.00pt 111.84pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>1&nbsp;</b><span class=font44><b>Access layer: </b>Access switches provide connectivity to user workstations and IP phones. The access layer can also include wireless access points with wireless handsets or workstations with voice software.</span></span></div>
<div class=paragraph style=" padding:4.08pt 40.80pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>2&nbsp;</b><span class=font44><b>Distribution layer: </b>This is the segment of the network where LAN-based routers and Layer 3 switches reside. These devices ensure that packets are properly routed between subnets and VLANs in your enterprise.</span></span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>3&nbsp;</b><span class=font44><b>Core: </b>The core typically consists of two or more high-end Layer 3 switches or routers that glue the network together as a whole.</span></span></div>
<div class=paragraph style=" padding:5.76pt 46.32pt 0.00pt 111.60pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>4&nbsp;</b><span class=font44><b>Data center distribution layer: </b>The distribution layer at the data center typically includes firewall or other security components (that is, intrusion detection systems [IDS] or intrusion prevention systems [IPS]). In Figure 9-3, two Catalyst 6500 switches with Firewall Services Modules (FWSM) are depicted.</span></span></div>
<div class=paragraph style=" padding:5.76pt 38.40pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>5&nbsp;</b><span class=font44><b>Data center access layer: </b>This layer includes access switches to which all the servers are connected. Figure 9-3 shows applications, Cisco Unified CallManager, and Cisco Unity servers connected to access switches at the data center.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:150.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:200.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:142.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:142.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>266    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 181.68pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 9-3   </b><span class=font43><i>Layered Approach to Securing IP Telephony Infrastructures</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style="position:relative;  width:356.16pt; height:181.44pt; padding:0.00pt 65.52pt 0.00pt 64.32pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-128.jpg" alt="" style=" width:356.16pt; height:181.44pt;">
<div class=block style=" width:42.72pt; height:7.68pt; position:absolute; left:88.80pt; top:5.76pt;">
<div class=paragraph style=" text-align:justify;"><span class=font4>Applications</span></div>
</div>
<div class=block style=" width:74.16pt; height:17.28pt; position:absolute; left:343.68pt; top:141.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 12.24pt; text-align:left; text-indent:-12.24pt;"><span class=font4 style=" line-height:9.60pt;">4  Data Center Distribution Layer</span></div>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:200.40pt;">
<div class=block style=" width:56.88pt; height:25.68pt; padding:0.00pt 0.00pt 21.60pt 143.52pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-129.jpg" alt="" style=" width:56.88pt; height:76.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:142.80pt;">
<div class=block style=" width:53.04pt; height:47.28pt; padding:0.00pt 89.76pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-130.jpg" alt="" style=" width:53.04pt; height:50.64pt;"></div>
</td>
<td class=cell valign="top" style=" width:142.80pt;">
<div class=block style=" width:142.80pt; height:47.28pt;">
<div class=paragraph style=" padding:36.00pt 113.76pt 0.00pt 0.00pt; text-align:justify;"><span class=font4>3 Core</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:385.44pt; height:173.04pt; padding:0.00pt 36.72pt 0.00pt 63.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-131.jpg" alt="" style=" width:385.44pt; height:173.04pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font8><b>Access Layer</b></span></div>
<div class=paragraph style=" padding:3.60pt 41.76pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The first recommendation, and one of the most important, is that you enable two VLANs at the access layer—one VLAN for data traffic and another VLAN for voice traffic.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:200.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:142.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:142.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:153.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:167.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:164.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 258.72pt; text-align:justify;"><span class=font4>Protecting the IP Telephony Infrastructure <span class=font44><b>267</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph style=" padding:0.00pt 40.32pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The voice VLAN in the Catalyst Switches that are running Catalyst Operating System (CatOS) is also known as an <i>Auxiliary VLAN. </i>Figure 9-4 illustrates this recommendation.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 9-4   </b><span class=font43><i>Access Layer and VLAN Assignment</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="2" valign="top" style=" width:153.60pt;">
<div class=block style=" width:153.60pt; height:108.48pt;">
<div class=paragraph style=" padding:77.04pt 5.52pt 0.00pt 125.04pt; text-align:justify;"><span class=font3>3750-1</span></div>
</div>
</td>
<td class=cell rowspan="4" valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:233.76pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-132.jpg" alt="" style=" width:167.52pt; height:233.76pt;"></div>
</td>
<td class=cell valign="top" style=" width:164.88pt;">
<div class=block style=" width:164.88pt; height:78.00pt;">
<div class=paragraph style=" padding:11.52pt 125.76pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>Distribution Switches</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:164.88pt;">
<div class=block style=" width:164.88pt; height:30.48pt;">
<div class=paragraph style=" padding:0.00pt 137.76pt 0.00pt 2.88pt; text-align:justify;"><span class=font3>3750-2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:153.60pt;">
<div class=block style=" width:153.60pt; height:69.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 132.72pt; text-align:justify;"><span class=font1>Voice VLAN 10</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:164.88pt;">
<div class=block style=" width:164.88pt; height:69.84pt;">
<div class=paragraph style=" padding:0.00pt 147.12pt 0.00pt 0.00pt; text-align:justify;"><span class=font1>Voice VLAN 11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:153.60pt;">
<div class=block style=" width:153.60pt; height:55.44pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 132.00pt; text-align:justify;"><span class=font1>Data VLAN 100</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:164.88pt;">
<div class=block style=" width:164.88pt; height:55.44pt;">
<div class=paragraph style=" padding:0.00pt 145.44pt 0.00pt 0.00pt; text-align:justify;"><span class=font1>Data VLAN 101</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.40pt;">
<div class=paragraph style=" padding:0.00pt 42.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Figure 9-4, several IP phones are connected to two Cisco Catalyst 3750 switches. User workstations are then connected to the IP phones. The voice VLAN in the 3750-1 switch is VLAN 10, and the data VLAN is VLAN 100. Similarly, the voice VLAN in the 3750-2 switch is VLAN 11, and the data VLAN is VLAN 101.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:90.00pt;">
<div class=paragraph style=" padding:0.00pt 58.32pt 0.00pt 36.00pt; text-align:justify;"><span class=font4 style=" line-height:11.76pt;"><b>TIP&nbsp;</b><span class=font44>When deploying access switches for voice networks, it is recommended that you use</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">switches capable of running the following features:</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>•&nbsp;</b><span class=font44>Inline power or Power over Ethernet (PoE)</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>•&nbsp;</b><span class=font44>Multiple queue support</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>•&nbsp;</b><span class=font44>802.1p and 802.1Q</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>•&nbsp;</b><span class=font44>Fast link convergence</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The separation of voice and data VLANs is recommended for many reasons. One of the major reasons is for address space conservation as well as for voice device protection from external networks. It is strongly recommended that voice endpoints be addressed using</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:47.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:153.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:167.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:164.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>268    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:511.68pt;">
<div class=paragraph style=" padding:0.00pt 46.80pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.24pt;">RFC 1918 private subnet addresses. By separating voice and data VLANs, you can also implement QoS trust boundary configurations that are strictly for voice devices.</span></div>
<div class=paragraph style=" padding:5.52pt 38.64pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In addition, the use of separate voice and data VLANs can help you dramatically when responding to security incidents. This is why previous chapters stressed the importance of good addressing schemes. For example, if you are responding to a security incident such as a worm or a DoS attack, you can easily identify what addresses represent IP phones and what addresses represent user workstations. Subsequently, you can use VLAN access tagging control mechanisms such as VLAN access control lists (VACL), 802.1Q, and 802.1p to provide protection for voice devices from malicious traffic. Last, but not least, are the ease of management and configuration benefits (that is, simplified QoS configuration schemes).</span></div>
<div class=paragraph style=" padding:6.00pt 45.60pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Another recommendation is that you enable root guard or the PortFast bridge protocol data unit (BPDU) guard feature on all access switches. This rules out the possibility of someone introducing a rogue switch that might attempt to become the Spanning Tree root. You can enable PortFast BPDU guard on a global basis on Cisco switches running CatOS, as shown in the following example.</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23>Console&gt; (enable) set spantree portfast bpdu-guard enable</span></div>
<div class=paragraph style=" padding:4.56pt 41.28pt 0.00pt 90.00pt; text-align:justify;"><span class=font44>The next example shows how to enable PortFast BPDU guard on Cisco switches running</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>Cisco IOS Software.</span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23>myswitch(config)# spanning-tree portfast bpduguard</span></div>
<div class=paragraph style=" padding:4.56pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">When a switch running BPDU guard disables one of its ports, it remains disabled until it is manually enabled. On the other hand, you can configure a port to re-enable itself automatically from the &quot;errdisable&quot; state on CatOS-enabled switches, as shown in the following example.</span></div>
<div class=paragraph style=" padding:6.48pt 141.12pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">Console&gt; (enable) set errdisable-timeout interval 450 Console&gt; (enable) set errdisable-timeout enable bpdu-guard</span></div>
<div class=paragraph style=" padding:4.56pt 41.28pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The timeout interval in this example is set to 450 seconds. The default timeout interval is 300 seconds and, by default, the timeout feature is disabled. The following example shows how to configure the automatic re-enabling of a disabled port on a switch running</span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>Cisco IOS Software.</span></div>
<div class=paragraph style=" padding:7.44pt 162.72pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myswitch(config)# errdisable recovery cause bpduguard myswitch(config)# errdisable recovery interval 450</span></div>
<div class=paragraph style=" padding:4.56pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can also enable port security or dynamic port security to protect against MAC flooding attacks. For instance, if you have an IP phone attached to a switch port and then a workstation connected directly to the IP phone, it is recommended that you limit the number of learned MAC addresses to two: one for the IP phone and one for the workstation behind the phone. Limit the learned MAC addresses to one in case you have only an IP phone connected to the switch port. This configuration is typically used in lobbies, common areas, and conference rooms. Protecting against MAC flooding attacks is important in publicly accessed areas of your organization such as lobbies because you do</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:66.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 258.72pt; text-align:justify;"><span class=font4>Protecting the IP Telephony Infrastructure <b>269</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:60.00pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">not want outsiders to be able to plug in laptops to an IP phone or disconnect the IP phone and plug in a laptop. Example 9-1 shows how to configure an access port with dynamic port security for a port on which an IP phone resides and a user workstation is plugged into the data port on the phone.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 9-1   </b><span class=font43><i>Dynamic Port-Security</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:93.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">myswitch#configure terminal</span></div>
<div class=paragraph style=" padding:0.00pt 102.96pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">myswitch(config)#interface GigabitEthernet1/12 myswitch(configif)# switchport access vlan 100 myswitch(configif)# switchport mode access myswitch(configif)# switchport voice vlan 10 myswitch(configif)# switchport port-security myswitch(configif)# switchport port-security maximum 3 myswitch(configif)# switchport port-security violation restrict myswitch(configif)# switchport port-security aging time 2 myswitch(configif)# switchport port-security aging type inactivity</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In the previous example, port security is enabled on the interface GigabitEthernet1/12. Notice the way the VLAN assignment is configured. The voice VLAN is VLAN 10, and the data VLAN is VLAN 100. Port security is configured to restrict learning to a maximum of three MAC addresses—one for the phone itself, another for the integrated PC port on the phone, and the third for a PC connected on the phone.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:68.88pt;">
<div class=paragraph style=" padding:0.00pt 39.12pt 0.00pt 36.00pt; text-align:justify;"><span class=font4 style=" line-height:12.00pt;"><b>TIP&nbsp;</b><span class=font44>The <b>switchport port-security violation restrict </b>command enables the switch to learn up</span></span></div>
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">to the maximum number of MAC addresses and then stop learning any new MAC addresses. The default setting is to disable the port. If you keep the default setting and the maximum number of MAC addresses is exceeded, the port becomes disabled, and the phone loses power (in case of inline power). In addition, the recommended port security aging time is 2 minutes.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:116.64pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">It is also recommended that you enable the DHCP snooping feature to prevent rogue DHCP server attacks and DHCP starvation attacks. Attackers can use different tools to create a DHCP starvation attack (the most common is called Gobbler) by making numerous DHCP requests until you run out of IP addresses. Subsequently, legitimate workstations cannot receive an IP address from your DHCP server successfully. You can enable DHCP snooping globally or on a per-interface basis. The following example shows how to configure DHCP snooping globally on a switch running Cisco IOS Software. An IP phone is connected to the switch, and a user workstation is plugged into the data port on the phone.</span></div>
<div class=paragraph style=" padding:6.48pt 192.72pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myswitch(config)#ip dhcp snooping vlan 10, 100 myswitch(config)#ip dhcp snooping</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>270    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:344.40pt;">
<div class=paragraph style=" padding:0.00pt 57.12pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the previous example, DHCP snooping is enabled on VLAN 10 (voice VLAN) and VLAN 100 (data VLAN). The following example shows how DHCP snooping is enabled on a specific port/interface.</span></div>
<div class=paragraph style=" padding:6.24pt 175.44pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myswitch(config)#interface GigabitEthernet 1/48 myswitch(configif)#ip dhcp snooping limit rate 10 myswitch(configif)#ip dhcp snooping trust</span></div>
<div class=paragraph style=" padding:4.56pt 51.12pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">DHCP snooping is a DHCP security feature that provides network security by filtering untrusted DHCP messages and by building and maintaining a DHCP snooping binding database (also referred to as a <i>DHCP snooping binding table).</i></span></div>
<div class=paragraph style=" padding:6.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">DHCP snooping acts like a firewall between untrusted hosts and DHCP servers. You can use DHCP snooping to differentiate between untrusted interfaces connected to the end user and trusted interfaces connected to the DHCP server or another switch. For DHCP snooping to function properly, all DHCP servers must be connected to the switch through trusted interfaces.</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Another feature that you can enable to protect the access layer of your voice-enabled network is the Dynamic Address Resolution Protocol (ARP) Inspection (DAI). DAI is commonly used to prevent gratuitous ARP attacks. Workstations bind a MAC address to an IP address in an ARP cache. When the system sends out an ARP request, the device that owns the IP address in that request replies with its IP and MAC address information to the system that originated the request. On the other hand, gratuitous ARP is an unsolicited ARP reply, in which a system tells the rest of the Layer 2 adjacent systems that it owns a specific IP and MAC address. Networking devices commonly use this technique. For example, when the Cisco PIX or the Cisco Adaptive Security Appliances (ASA) fail over, it sends a gratuitous ARP to other devices on the network to advertise the assumed IP addresses. On the other hand, attackers can use gratuitous ARP to spoof the identity of another system. You can use DAI to inspect all ARP requests and replies (gratuitous and nongratuitous) to avoid these types of exploits on untrusted ports.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.80pt;">
<div class=paragraph style=" padding:0.00pt 213.60pt 0.00pt 35.76pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>You must enable DHCP snooping to use DAI.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:80.40pt;">
<div class=paragraph style=" padding:0.00pt 50.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.24pt;">You can enable DAI globally and then on a per-interface basis. The following example shows how to configure DAI globally on a switch running Cisco IOS Software.</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myswitch#configure terminal</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myswitch(config)#ip arp inspection vlan 10,100</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myswitch(config)#ip dhcp snooping database t<a href="ftp://172.18.108.26/dai/dai_db">ftp://172.18.108.26/dai/dai_db</a></span></div>
<div class=paragraph style=" padding:4.32pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">In the previous example, DAI is enabled on VLANs 10 and 100. The switch is configured to save the DHCP snooping database on a TFTP server (172.18.108.26) under a directory</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:78.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 258.72pt; text-align:justify;"><span class=font4>Protecting the IP Telephony Infrastructure <b>271</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:96.48pt;">
<div class=paragraph style=" padding:0.00pt 62.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">called dai and a file called dai_db. You can also enable DAI on a per-interface basis, as shown in the following example:</span></div>
<div class=paragraph style=" padding:6.48pt 171.36pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myswitch(config)#interface GigabitEthernet 1/12 myswitch(configif)#ip arp inspection limit rate 15</span></div>
<div class=paragraph style=" padding:4.80pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In the previous example, the <b>ip arp inspection </b>command is configured with the <b>limit rate </b>option to specify the maximum number of ARP packets per second allowed on the GigabitEthernet 1/12 interface. The switch disables that port when it detects more than 15 ARP packets per second.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.80pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left; text-indent:-54.24pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>If you do not want to disable the phone when the port receives more then 15 ARP messages in a second, you can set the rate limit to none which allows the phone to stay up.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:332.88pt;">
<div class=paragraph style=" padding:0.00pt 47.04pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Many people are becoming more concerned with unauthorized network access, and potentially, even unauthorized placement of IP phones. More advanced features such as 802.1x and Network Admission Control (NAC) can also be implemented. In 802.1x environments in which user workstations are plugged in to the back of IP phones, the use of automatic port control on Cisco Catalyst switches is recommended. To enable 802.1x automatic port control on switches running Cisco IOS Software, use the <b>dotlx port-control auto </b>command. On switches running CatOS, use the <b>set port dot1x &lt;m/p&gt; port-control auto </b>command. 802.1x and IP telephony are only supported with the use of Cisco IP phones. You must use multi-VLAN access ports (separate VLANs for voice and data) based on the configurations shown in the previous examples in this chapter.</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">When you enable 802.1x on a switch port where a Cisco IP phone resides, authentication is done based only on Cisco Discovery Protocol (CDP). It is important to notice that no voice or data packets are allowed before CDP packets are processed. This varies on a per-platform basis. For instance, on a Catalyst 6500 running CatOS, packets other than Extensible Authentication Protocol over LAN (EAPOL) or CDP are dropped by the software at the in-band driver level. The voice VLAN Spanning Tree state is set to &quot;forwarding,&quot; and the disabling of learning of other MAC addresses is done on the line cards by setting the appropriate bits in port header control registers. On the other hand, Cisco Catalyst 3750 switches put phones addresses in the TCAM after detecting CDP packets to allow voice traffic through. In addition, an ACL to catch all EAPOL packets is used. The hardware drops any other packets sent from unknown source addresses when they hit the catchall entry in the TCAM, triggering an address learning violation in the switch.</span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In short, in 802.1x environments, CDP is absolutely necessary for IP phone operation; without it, an IP phone is unusable. In contrast, when you use the Cisco NAC Framework solution in Layer 2 IP (NAC-L2-IP), EAP over UDP (EoU) is used. EOU provides a different type of architecture and access control environment than 802.1x because EoU acts</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:61.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>272    </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:201.60pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">at Layer 3, and 802.1x is strictly Layer 2. In NAC-L2-IP, the security posture check is triggered after an ARP packet is detected or by the use of DHCP snooping. Cisco switches support EoU in an IP telephony environment. In most cases, it is recommended that you use NAC-L2-IP. Based primarily on CDP, you can exempt Cisco IP phones from any EOU rules. An alternative to this approach includes a configured static exception or use of the Generic Authorization Message Exchange (GAME) protocol with an external audit server.</span></div>
<div class=paragraph style=" padding:6.00pt 41.28pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">It is recommended that you exempt IP phones from the NAC posture entirely. Example 9-2 demonstrates how to configure an exception policy for Cisco IP phones on a switch running Cisco IOS Software.</span></div>
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 9-2 </b><span class=font43><i>Exception Policy for Cisco IP Phones</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">identity profile eapoudp</span></div>
<div class=paragraph style=" padding:0.00pt 133.44pt 0.00pt 97.20pt; text-align:left; text-indent:4.08pt;"><span class=font23 style=" line-height:9.60pt;">device authorize type cisco ip phone policy allow-my-phones identity policy allow-my-phones</span></div>
<div class=paragraph style=" padding:0.00pt 223.44pt 0.00pt 97.20pt; text-align:left; text-indent:4.08pt;"><span class=font23 style=" line-height:9.60pt;">access-group allow-my-phones ip access-list extended allow-my-phones</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.28pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">permit ip any any</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the previous example, an identity profile is configured for EoU, and the <b>device authorize </b>command is used to &quot;authorize&quot; or exempt all Cisco IP phones from NAC posture checks. This is done by using the CDP information from the Cisco IP phone. The identity policy named <b>allow-my-phones </b>is configured with an access list to catch all traffic.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.04pt;">
<div class=paragraph style=" padding:0.00pt 52.56pt 0.00pt 90.00pt; text-align:left; text-indent:-54.24pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>Refer to the Cisco Press book <i>Network Admission Control Volume II </i>for detailed NAC configuration examples and troubleshooting guides.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:117.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can configure Cisco IP phones to allow an administrator to get statistics and device information through a built-in web server that runs on each phone. Administrators can use this feature for debugging and to obtain the remote status of the phone. This built-in web server is also used to receive application information from the Cisco Unified CallManager. You can enable or disable web access globally or on each phone specifically. It is recommended that you control web access to the phones. If you completely disable web access, troubleshooting voice-related issues can be more difficult to solve. Alternatively, you can restrict access by configuring ACLs or VACLs only, allowing an administrative network or subnet in different parts of the network (in most cases, as close as possible to the phone).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:105.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 258.72pt; text-align:justify;"><span class=font4>Protecting the IP Telephony Infrastructure <b>273</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.80pt;">
<div class=paragraph style=" padding:0.00pt 44.64pt 0.00pt 89.76pt; text-align:left; text-indent:-54.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>As previously mentioned in this book, it is extremely important that you have a separate network segment or subnet dedicated to administrative access and applications.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:318.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Distribution Layer</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">At the distribution layer, you can apply enforcement mechanisms (such as ACLs) based on your security policies for the IP telephony-enabled network. For example, you can configure Layer 3 ACLs so that they do not allow traffic from the nonvoice VLANS to access the voice gateway and voice applications in the network. Typically, voice application servers (such as Cisco Unified CallManager and Cisco Unity) are protected by firewalls in the distribution layer of the data center. On the other hand, you can create ACL templates to strategically deploy within your distribution layer to restrict access from nonvoice VLANs. This method simplifies the ACLs at Layer 3 compared to the ACLs at Layer 2 or VLAN ACLs. Figure 9-5 shows the two access switches you saw in the previous examples, in which IP phones in the 192.168.10.0/24 and 192.168.11.0/24 networks reside (voice VLANs 10 and 11). The user workstations are in VLANs 100 (IP range 192.168.100.0/24) and 101 (IP range 192.168.101.0/24).</span></div>
<div class=paragraph style=" padding:6.24pt 39.12pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The goal is to restrict access from nonvoice segments to the voice gateway (10.10.10.100) and to the CallManager cluster (172.18.124.0/24). You can use a simple ACL in your distribution switches, as demonstrated in Example 9-3.</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 9-3 </b><span class=font43><i>ACL in Distribution Switch</i></span></span></div>
<div class=paragraph style=" padding:5.76pt 81.60pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list 100 deny ip 192.168.100.0 0.0.0.255 host 10.10.10.100 access-list 100 deny ip 192.168.101.0 0.0.0.255 host 10.10.10.100 ! the lines above deny all nonvoice devices to send traffic to the voice ! gateway</span></div>
<div class=paragraph style=" padding:0.00pt 90.24pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">access-list 100 deny ip 192.168.100.0 0.0.0.255 172.18.124.0 0.0.0.255 access-list 100 deny ip 192.168.101.0 0.0.0.255 172.18.124.0 0.0.0.255 ! the access list entries above deny all nonvoice devices to send ! traffic to the Cisco Unified CallManager servers access-list 100 permit ip 192.168.100.0 0.0.0.255 any access-list 100 permit ip 192.168.101.0 0.0.0.255 any</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.88pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Depending on your security policy and your environment, you will allow or restrict access to additional services. Of course, in your data center, you will have more granular ACLs allowing or denying traffic based on your security policy.</span></div>
<div class=paragraph style=" padding:6.00pt 41.04pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">High availability is crucial in the distribution layer. Use the Hot Standby Router Protocol (HSRP) at the distribution layer to ensure high availability in the event of a failure.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:109.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:413.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>274   </b>Chapter 9: IP Telephony Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 286.80pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 9-5   </b><span class=font43><i>Distribution Layer Access List</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.48pt;">
<div class=block style=" width:72.48pt; height:135.12pt;">
<div class=paragraph style=" padding:84.00pt 0.00pt 0.00pt 63.60pt; text-align:justify;"><span class=font3>Voice Gateway</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 73.44pt; text-align:center;"><span class=font1>10.10.10.100</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:413.52pt;">
<div class=block style=" width:349.44pt; height:135.12pt; padding:0.00pt 64.08pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-133.jpg" alt="" style=" width:349.44pt; height:135.12pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style="position:relative; z-index:1; width:486.00pt; height:6.72pt;">
<div class=block style="float:right; width:1px; height:6.00pt; clear:right;"><span style="line-height:0pt;"></span></div>
<div class=block style="float:right; width:407.52pt; height:0.72pt; clear:right;"><span style="line-height:0pt;"></span></div>
<div class=paragraph style=" padding:0.00pt 186.48pt 0.00pt 76.32pt; text-align:justify;"><span class=font3>3750-1&nbsp;'&nbsp;&quot;~~  ' 3750-2</span></div>
<div class=block style=" width:219.36pt; height:150.96pt; position:absolute; left:78.48pt; top:6.00pt; z-index:-1;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-134.jpg" alt="" style=" width:219.36pt; height:150.96pt;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:185.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:47.76pt;">
<div class=paragraph style=" padding:0.00pt 42.96pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>The following link contains numerous step-by-step examples of methods for configuring HSRP on Cisco Catalyst switches and Cisco IOS Software routers:</span></span></div>
<div class=paragraph style=" padding:2.88pt 150.96pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a href="http://www.cisco.com/en/US/partner/tech/tk648/tk362/tk321/tsd_technology_support_sub-protocol_home.html">http://www.cisco.com/en/US/partner/tech/tk648/tk362/tk321/ tsd_technology_support_sub-protocol_home.html</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Gateway Load Balancing Protocol (GLBP) is another redundancy mechanism. GLBP is now Stateful Switchover (SSO) aware. GLBP can detect when a router is failing over to the</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:72.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:413.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 267.60pt; text-align:justify;"><span class=font4>Securing the IP Telephony Applications <b>275</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:522.24pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">secondary Route Processor (RP) and continue in its current GLBP group state. Prior to being SSO aware, GLBP was not able to detect that a second RP was installed and configured to take over if the primary RP failed. When the primary failed, the GLBP device would stop participating in the GLBP group and, depending on its role, could trigger another router in the group to take over as the active router. With this enhancement, GLBP detects the failover to the secondary RP, and no change occurs to the GLBP group. If the secondary RP fails and the primary is still not available, the GLBP group detects this and re-elects a new active GLBP router.</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">At the distribution layer, you can also enable NetFlow to gain complete visibility of what is happening in your network. As you learned in previous chapters, NetFlow brings unmatched telemetry features that allow you to maintain visibility of your network traffic.</span></div>
<div class=paragraph style=" padding:24.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><a name="bookmark72"><b>C</b></a><b>ore</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.64pt 0.00pt 89.52pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">A number of books are required to fully cover how to design the core of your network. However, for the purpose of this chapter and this book, the most important thing you need to remember is the need for high availability and the ability to route/switch traffic as fast as possible with little need for traffic filtering in your core. You can use features such as Control Plane Policing (CoPP) to protect the control plane of your core routers. In addition, you should implement the routing protocol security best practices learned in previous chapters and all other Network Foundation Protection (NFP) strategies.</span></div>
<div class=paragraph style=" padding:23.76pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark60"><b>Securing the IP Telephony Applications</b></a></span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>In this section, you learn how to protect IP telephony applications such as:</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Unified CallManager</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Unified Communications Manager Express</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Unity</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Unity Express</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Personal Assistant</span></div>
<div class=paragraph style=" padding:2.40pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Securing these applications starts with the development of a well-defined application security policy that describes all the processes required to ensure server and application security and assumes that you deployed the recommended network infrastructure best practices described earlier in this chapter. This policy not only includes design guidelines, but also operational practices, such as patch management, antivirus protection, and in-depth protection with the Cisco Security Agent (CSA). In the following sections, you learn best practices for increasing the security of the previously mentioned applications.</span></div>
</div>
</td>
]]></content:encoded>
			<wfw:commentRss>http://ciscoasa.org.ua/2010/03/chapter-9-ip-telephony-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter 8: Wireless Security</title>
		<link>http://ciscoasa.org.ua/2010/03/chapter-8-wireless-security/</link>
		<comments>http://ciscoasa.org.ua/2010/03/chapter-8-wireless-security/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 09:48:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[attackers]]></category>
		<category><![CDATA[cellular coverage]]></category>
		<category><![CDATA[coffee shops]]></category>
		<category><![CDATA[deployments]]></category>
		<category><![CDATA[network servers]]></category>
		<category><![CDATA[portability issues]]></category>
		<category><![CDATA[rudimentary level]]></category>
		<category><![CDATA[wireless architecture]]></category>
		<category><![CDATA[wireless lan]]></category>
		<category><![CDATA[wireless networking]]></category>
		<category><![CDATA[wireless networks]]></category>
		<category><![CDATA[wlan solution]]></category>

		<guid isPermaLink="false">http://ciscoasa.org.ua/?p=262</guid>
		<description><![CDATA[

Wireless networks are becoming more and more popular. Not only can you take advantage of wireless networking at the office, home, a hotel, and coffee shops, but also at airports, train stations, and many other places. Wireless networks increase productivity. Your employees can save time by sending and receiving e-mail or accessing information on network [...]]]></description>
			<content:encoded><![CDATA[<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:404.88pt;">
<div class=paragraph style=" padding:0.00pt 37.20pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Wireless networks are becoming more and more popular. Not only can you take advantage of wireless networking at the office, home, a hotel, and coffee shops, but also at airports, train stations, and many other places. Wireless networks increase productivity. Your employees can save time by sending and receiving e-mail or accessing information on network servers from a conference room or any location within your organization that has wireless connectivity. You can also implement a voice over wireless LAN (WLAN) solution. With a WLAN, your employees can reach each other anywhere within your organization without having to rely on cellular coverage that can be spotty or nonexistent.</span></div>
<div class=paragraph style=" padding:6.24pt 40.08pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Now the bad news: wireless networks are a major target for attackers. One of the biggest challenges today is to make sure that the appropriate tools and mechanisms are used to protect data in-transit across wireless networks. In addition, the wireless infrastructure needs to be protected against attacks targeted to the wireless networking devices. Stories abound of attackers gaining access to wireless networks not only to steal information but also to attack other networks.</span></div>
<div class=paragraph style=" padding:6.00pt 36.96pt 0.00pt 90.96pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">After reading this chapter, you will become familiar with some of the technologies, tools, and mechanisms that are typically used to protect your wireless network. You will also learn best practices to use when securing the Cisco Unified Wireless Architecture.</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The 802.11a, 802.11b, and 802.11g are the most widely deployed WLAN technologies today. Historically, 802.11 WLAN security includes the use of open or shared-key authentication and static wired equivalent privacy (WEP) keys. This combination offers a rudimentary level of access control and privacy but each element can be compromised.</span></div>
<div class=paragraph style=" padding:6.24pt 36.96pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The low cost of wireless deployments makes them popular (that is, you do not have to worry about expensive cabling solutions and portability issues). However, inexpensive equipment also makes it easier for attackers to gain unauthorized access. Rogue access points and unauthorized, poorly secured networks compound the odds of a security breach. The best practices you learned in previous chapters play a crucial role when protecting the infrastructure, analyzing risks, and building the most appropriate operational security program for your organization.</span></div>
<div class=paragraph style=" padding:6.00pt 51.36pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In this chapter, you will also learn the different authentication mechanisms in wireless networks. In addition, you will become familiar with advanced topics such as:</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44>•  Wireless intrusion detection and prevention services (IDS/IPS)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:47.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:84.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:311.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>212    </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:519.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><a name="bookmark62">•</a>&nbsp;Precise location tracking</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Network Admission Control (NAC) in wireless networks</span></div>
<div class=paragraph style=" padding:23.76pt 116.88pt 0.00pt 36.24pt; text-align:left;"><span class=font11 style=" line-height:18.00pt;"><a href="#bookmark60"><b>Overview of Cisco Unified Wireless Network </b></a><b>Architecture</b></span></div>
<div class=paragraph style=" padding:3.12pt 37.92pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The Cisco Unified Wireless Architecture is a multiservice solution designed for any type of organization. It can be deployed in your corporate offices, branches, retail stores, hospitals, manufacturing plants, warehouses, educational institutions, financial institutions, government agencies, and any other type of organization that needs wireless connectivity. Industry standards including the IEEE 802.11 and the draft IETF Control and Provisioning of Wireless Access Points (CAPWAP) are supported.</span></div>
<div class=paragraph style=" padding:6.24pt 45.60pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Because the Cisco Unified Wireless Network is a multiservice solution, it supports data, voice, and video applications. Some examples of data applications are as follows:</span></div>
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;E-mail</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Internet access</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Virtual private network (VPN) access</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Inventory management applications</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Asset tracking</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Mobile healthcare applications</span></div>
<div class=paragraph style=" padding:2.40pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can also run Voice over IP (VoIP) over WLAN. The Cisco Unified Wireless Network Architecture also supports video, such as video surveillance applications, video streaming applications for e-learning, and others. The Cisco Unified Wireless solution provides interoperability with the Cisco Wireless IP Phones to provide comprehensive voice communications using Cisco Unified CallManager and Cisco Wi-Fi access points. The Cisco Compatible Extensions program gives third-party manufacturers the ability to design industry-standard and Cisco innovations into a wide variety of devices. Other advanced features such as wireless intrusion detection and prevention, precise location tracking, and Network Admission Control (NAC) are also supported.</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can implement wireless networks in all sizes. For example, you can have merely a couple of wireless access points or wireless routers within your organization, as illustrated in Figure 8-1.</span></div>
<div class=paragraph style=" padding:6.24pt 37.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Figure 8-1, a wireless access point and a wireless router are accepting connections from end-user workstations, laptops, and wireless scanners. This approach is only appropriate for small environments. It is not feasible for medium and large organizations because it does not provide centralized management and ease of deployment. The Cisco Unified Wireless Network solution provides centralized management that allows you to easily deploy WLAN configurations with the same level of security, scalability, and reliability to all</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 197.76pt; text-align:justify;"><span class=font4>Overview of Cisco Unified Wireless Network Architecture <b>213</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph style=" padding:0.00pt 56.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.24pt;">wireless networking devices within your organization. Figure 8-2 illustrates the main components of the Cisco Unified Wireless Network.</span></div>
<div class=paragraph style=" padding:9.84pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 8-1    </b><span class=font43><i>Basic Wireless Network</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:331.20pt; height:425.76pt; padding:0.00pt 77.76pt 0.00pt 77.04pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-84.jpg" alt="" style=" width:331.20pt; height:425.76pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:102.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>214   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 220.56pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-2    </b><span class=font43><i>The Cisco Unified Wireless Network Architecture</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 295.44pt 0.00pt 140.64pt; text-align:justify;"><span class=font3>Mobile Clients</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:352.08pt; height:295.44pt; padding:0.00pt 67.68pt 0.00pt 66.24pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-85.jpg" alt="" style=" width:352.08pt; height:295.44pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 131.52pt 0.00pt 304.56pt; text-align:justify;"><span class=font3>Mobile Clients</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:187.20pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The following are the primary components of the Cisco Unified Wireless Network solution (as illustrated in Figure 8-2):</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;WLAN management: </b>Centralized management enables configuration of the same level of security, scalability, and reliability features throughout your organization. You can use the CiscoWorks Wireless LAN Solution Engine (WLSE) or the CiscoWorks WLSE express.</span></div>
<div class=paragraph style=" padding:3.84pt 39.12pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Wireless LAN controllers: </b>Provision of centralized intelligence for wireless access point management.</span></div>
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Access points: </b>Devices to which mobile devices connect.</span></div>
<div class=paragraph style=" padding:4.80pt 38.40pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Mobile clients: </b>End-user workstations, laptops, personal assistant (PDAs), and other wireless devices that ensure peak performance and interoperability.</span></div>
<div class=paragraph style=" padding:4.32pt 53.28pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Mobility services: </b>Services such as voice over wireless LAN, wireless intrusion detection and prevention, precise location tracking (Cisco WLAN Location Appliance), and others.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 197.76pt; text-align:justify;"><span class=font4>Overview of Cisco Unified Wireless Network Architecture <b>215</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 143.52pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:12.24pt;"><b>NOTE        </b><span class=font44>For general information about the Cisco wireless devices, go to <a href="http://www.cisco.com/go/wireless">http://www.cisco.com/go/wireless.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:89.04pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can deploy wireless access points within your organization in two modes: unified mode (as illustrated in Figure 8-2) and autonomous mode. In autonomous mode, a WLSE network management appliance is deployed with autonomous access points. Some access points act as domain controllers (WDS) for sets of access points communicating over the wired network using the Wireless LAN Context Control Protocol (WLCCP). This is illustrated in Figure 8-3.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 8-3   </b><span class=font43><i>Autonomous Wireless Access Points</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:341.76pt; height:297.84pt; padding:0.00pt 72.48pt 0.00pt 71.76pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-86.jpg" alt="" style=" width:341.76pt; height:297.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The main difference between the unified and autonomous modes is that in unified mode, access points operate with the Lightweight Access Point Protocol (LWAPP) and work in conjunction with Cisco wireless LAN controllers and the Cisco Wireless Control System (WCS). When configured with LWAPP, the access points can automatically detect</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>216    </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:145.20pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">the best-available Cisco wireless LAN controller and download appropriate policies and configuration information with no manual intervention. Autonomous access points are based on Cisco IOS software and may optionally operate with the Cisco WLSE. Autonomous access points, along with the Cisco WLSE, deliver a core set of features and may be field-upgraded to take advantage of the full benefits of the Cisco Unified Wireless Network as requirements evolve.</span></div>
<div class=paragraph style=" padding:6.00pt 41.04pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can individually manage Cisco Aironet autonomous access points via the command-line interface (CLI), a web interface, the CiscoWorks WLSE, or CiscoWorks WLSE Express. On the other hand, Cisco recommends that you upgrade any existing Cisco Aironet access points operating autonomously to run LWAPP and operate them as lightweight access points to receive all the features, benefits, and mobility services of the Cisco Unified Wireless Network.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><a name="bookmark63"><b>N</b></a><b>OTE        </b><span class=font44>Cisco provides free upgrade software for existing customers at</span></span></div>
<div class=paragraph style=" padding:1.92pt 92.16pt 0.00pt 0.00pt; text-align:right;"><span class=font44><a href="http://tools.cisco.com/support/downloads/pub/MDFTree.x?butype=wireless">http://tools.cisco.com/support/downloads/pub/MDFTree.x?butype=wireless.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:293.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font11><a href="#bookmark60"><b>Authentication and Authorization of Wireless Users</b></a></span></div>
<div class=paragraph style=" padding:4.08pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The 802.11 standard supports different types of authentication. The two most generic types are open and shared-key authentication. In most wireless networks, a service set ID (SSID) is specified to identify the wireless network. The basic mechanisms of 802.11 augment the identification by using SSIDs with authentication mechanisms that prevent the client from sending data to and receiving data from the access point unless the client has the correct shared key. One of the most basic wireless authentication protocols is the wired equivalent privacy (WEP) standard. The following section describes WEP in detail.</span></div>
<div class=paragraph style=" padding:24.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font8><b>WEP</b></span></div>
<div class=paragraph style=" padding:3.84pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">WEP, an optional encryption standard in 802.11 that most vendors support, is implemented in the MAC layer. WEP-enabled devices encrypt the payload of each 802.11 frame before transmission by using an RC4 stream cipher. The packets are then decrypted in the wireless access point. WEP encrypts only data between 802.11 stations. After the frame enters the wired side of the network, WEP no longer applies.</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">During the encryption process, WEP arranges a key schedule (otherwise known as a <i>seed) </i>by concatenating the shared secret key supplied by the user of the sending station with a random-generated 24-bit initialization vector (IV). The IV lengthens the life of the secret key because the station can change the IV for each frame transmission. WEP inputs the resulting seed into a pseudorandom number generator that produces a key-stream equal to the length of the frame payload plus a 32-bit integrity check value (ICV), as illustrated in Figure 8-4.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:51.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:158.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:24.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:86.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:106.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:110.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 221.28pt; text-align:justify;"><span class=font4>Authentication and Authorization of Wireless Users <b>217</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 347.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-4    </b><span class=font43><i>WEP Process</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:34.56pt; height:28.80pt; padding:0.00pt 388.56pt 0.00pt 62.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-87.jpg" alt="" style=" width:34.56pt; height:28.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:158.40pt;">
<div class=block style=" width:158.40pt; height:120.48pt;">
<div class=paragraph style=" padding:6.72pt 49.20pt 0.00pt 71.76pt; text-align:justify; text-indent:-2.88pt;"><span class=font3 style=" line-height:9.60pt;">Initialization Vector (IV)</span></div>
<div class=paragraph style=" padding:16.56pt 13.68pt 0.00pt 68.64pt; text-align:justify;"><span class=font3>Shared Key-►</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:24.24pt;">
<div class=block style=" width:24.24pt; height:120.48pt;">
<div class=paragraph style=" padding:37.20pt 10.80pt 0.00pt 0.00pt; text-align:justify;"><span class=font1>Seed</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:86.16pt;">
<div class=block style=" width:84.72pt; height:31.92pt; padding:15.36pt 1.44pt 73.20pt 0.00pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:84.72pt; height:31.92pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:51.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:33.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:51.60pt;">
<div class=block style=" width:51.60pt; height:15.84pt;">
<div class=paragraph style=" padding:7.44pt 0.00pt 0.00pt 17.04pt; text-align:left;"><span class=font3>WEP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.12pt;">
<div class=block style=" width:33.12pt; height:15.84pt;">
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font1>Sequence</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:51.60pt;">
<div class=block style=" width:51.60pt; height:16.08pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 14.88pt; text-align:left;"><span class=font3>PRNG</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.12pt;">
<div class=block style=" width:33.12pt; height:16.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:51.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:33.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:106.32pt;">
<div class=block style=" width:91.20pt; height:160.32pt; padding:0.00pt 15.12pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-88.jpg" alt="" style=" width:91.20pt; height:160.32pt;"></div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:110.88pt;">
<div class=block style=" width:110.88pt; height:160.32pt;">
<div class=paragraph style=" padding:21.84pt 75.84pt 0.00pt 0.00pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">Encrypted Message</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:158.40pt;">
<div class=block style=" width:158.40pt; height:39.84pt;">
<div class=paragraph style=" padding:0.00pt 57.84pt 0.00pt 66.48pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">Plain Text Message</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:110.40pt;">
<div class=block style=" width:110.40pt; height:39.84pt;">
<div class=paragraph style=" padding:22.56pt 46.32pt 0.00pt 0.24pt; text-align:justify;"><span class=font3>Integrity Algorithm</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:175.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following steps are illustrated in Figure 8-4:</span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font4><b>1&nbsp;</b><span class=font44>The ICV is calculated using CRC-32 and concatenated to the plaintext message.</span></span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 99.36pt; text-align:left;"><span class=font4><b>2&nbsp;</b><span class=font44>A random IV and the shared secret key are also concatenated producing the seed.</span></span></div>
<div class=paragraph style=" padding:6.72pt 40.32pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>3&nbsp;</b><span class=font44>This seed is the input to the WEP Pseudorandom Number Generator (PRNG). WEP uses RC4 PRNG of RSA Data Security to produce a pseudorandom sequence.</span></span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 111.60pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>4&nbsp;</b><span class=font44>The message is encrypted by using an XOR operation with the sequence generated in the previous step.</span></span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 99.36pt; text-align:left;"><span class=font4><b>5&nbsp;</b><span class=font44>The encrypted message is sent to the other end.</span></span></div>
<div class=paragraph style=" padding:6.72pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The ICV is a check sum that the receiving station eventually recalculates and compares to the one sent by the sending station to determine whether the transmitted data underwent any form of tampering while in transient. If the receiving station calculates an ICV that does not match the one found in the frame, the receiving station can reject the frame or flag the user.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 178.56pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>WEP shared secrets use 40-bit, 64-bit, or 128-bit keys.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">WEP has some limitations and has undergone extensive examination and criticism over the past years. In short, WEP is vulnerable because of its relatively short IVs and keys that</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:49.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:158.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:24.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:86.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:106.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:110.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>218    </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:188.40pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">remain static. For a large, busy network, this reoccurrence of IVs can happen within an hour or so. Because of this, you will have many frames or packets with similar key-streams. Technically, an attacker can gather frames based on the same IV to determine the shared values among the wireless devices. This information can be key-stream or the shared secret key. The static nature of the shared secret keys emphasizes this problem. In many cases, system administrators and users use the same keys for months or even years. This gives mischievous culprits plenty of time to monitor and attack the WEP-enabled networks. Now some vendors deploy dynamic key distribution solutions based on 802.1X, which definitely improves the security of wireless LANs.</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Many now recommend the use of IP security (IPsec) to ensure data confidentiality, integrity, and authenticity. The only caveat is that when you deploy IPsec in a WLAN environment, you need to install an IPsec software client on every machine that connects to the wireless network.</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44>WEP has several enhancements. The first one is the use of the Temporal Key Integrity</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>Protocol (TKIP) .</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph style=" padding:0.00pt 221.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>TKIP is often referred to as WEP Version 2.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:194.16pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The second enhancement is the use of the Advanced Encryption Standard (AES) encryption protocol instead of RC4, which is used in older WEP implementations.</span></div>
<div class=paragraph style=" padding:6.00pt 54.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Wi-Fi Protected Access (WPA) standard uses TKIP to provide additional security features. WPA is discussed in the next section.</span></div>
<div class=paragraph style=" padding:24.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font8><b>WPA</b></span></div>
<div class=paragraph style=" padding:3.60pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">WPA (using TKIP) includes a per-packet keying (PPK) and message integrity check (MIC) and an extension of the initialization vector from 24 bits to 48 bits. WPA mitigates the WEP threat by implementing different keys on a per-packet basis. It does this by hashing the IV and WEP keys to produce a temporal key. This temporal key is then combined with the IV and fed to an XOR operation with the plaintext message.</span></div>
<div class=paragraph style=" padding:6.00pt 53.52pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Today WPA combines TKIP and user authentication via IEEE 802.1x and the EAP (Extensible Authentication Protocol). This combination mitigates vulnerabilities from several angles and represents a significant security upgrade over WEP.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:119.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:90.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:131.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:131.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 221.28pt; text-align:justify;"><span class=font4>Authentication and Authorization of Wireless Users <b>219</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.00pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The following site includes a whitepaper with detailed information about WEP, WPA, and other authentication mechanisms:</span></span></div>
<div class=paragraph style=" padding:3.12pt 144.72pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;"><a href="http://www.cisco.com/en/US/netsol/ns340/ns394/ns348/ns386/networking_solutions_white_paper09186a00800b469f.shtml">http://www.cisco.com/en/US/netsol/ns340/ns394/ns348/ns386/ networking_solutions_white_paper09186a00800b469f.shtml</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><b>802.1x on Wireless Networks</b></span></div>
<div class=paragraph style=" padding:3.60pt 65.52pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Chapter 1, &quot;Technology Overview,&quot; you learned the basics of the 802.1X. As a refresher, 802.1x is a standard that defines the encapsulation methodologies for the transport of the Extensible Authentication Protocol (EAP) protocol.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 65.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>EAP was originally defined in RFC 2284, which is now obsolete due to RFC 3748.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The 802.1X standard allows you to enforce access control when wired and wireless devices attempt to access the network. Figure 8-5 illustrates the main components of 802.1x.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 294.72pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-5    </b><span class=font43><i>802.1x in Wireless Networks</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="2" valign="top" style=" width:90.00pt;">
<div class=block style="position:relative; z-index:2; width:90.00pt; height:62.88pt;">
<div class=block style="float:right; width:1px; height:13.92pt; clear:right;"><span style="line-height:0pt;"></span></div>
<div class=block style="float:right; width:47.76pt; height:38.16pt; clear:right;"><span style="line-height:0pt;"></span></div>
<div class=paragraph style=" padding:1.92pt 0.24pt 0.00pt 37.20pt; text-align:justify;"><span class=font3 style=" line-height:9.36pt;">Wireless Client with Supplicant</span></div>
</div>
</td>
<td class=cell colspan="2" rowspan="2" valign="top" style=" width:147.60pt;">
<div class=block style="position:relative; z-index:1; width:147.60pt; height:62.88pt;">
<div class=block style="float:left; width:1px; height:23.28pt; clear:left;"><span style="line-height:0pt;"></span></div>
<div class=block style="float:left; width:90.96pt; height:6.24pt; clear:left;"><span style="line-height:0pt;"></span></div>
<div class=block style="float:left; width:137.04pt; height:22.56pt; clear:left;"><span style="line-height:0pt;"></span></div>
<div class=paragraph style=" padding:19.20pt 9.60pt 0.00pt 91.92pt; text-align:justify;"><span class=font3>Authenticator</span></div>
<div class=block style=" width:184.80pt; height:28.80pt; position:absolute; left:-47.76pt; top:23.28pt; z-index:-1;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-89.jpg" alt="" style=" width:184.80pt; height:28.80pt;"></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:117.36pt;">
<div class=block style=" width:117.36pt; height:19.20pt;">
<div class=paragraph style=" padding:12.00pt 14.40pt 0.00pt 28.08pt; text-align:justify;"><span class=font3>Authentication Server</span></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:131.04pt;">
<div class=block style=" width:131.04pt; height:62.88pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 0.00pt; text-align:center;"><span class=font3 style=" line-height:9.36pt;">Identity Store (Microsoft Active Directory, LDAP, ODBC, etc.)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.08pt;">
<div class=block style=" width:28.08pt; height:43.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:58.56pt;">
<div class=block style=" width:24.00pt; height:48.96pt; padding:2.64pt 6.00pt 0.00pt 28.56pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-90.jpg" alt="" style=" width:24.00pt; height:48.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:30.72pt;">
<div class=block style=" width:30.72pt; height:43.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:221.28pt;">
<div class=block style=" width:221.28pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 93.60pt 0.00pt 110.40pt; text-align:justify;"><span class=font1>802.1x</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:44.40pt;">
<div class=block style=" width:44.40pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 6.72pt 0.00pt 16.32pt; text-align:justify;"><span class=font1>RADIUS</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:161.76pt;">
<div class=block style=" width:161.76pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 98.40pt 0.00pt 0.00pt; text-align:justify;"><span class=font1>Identity Store Integration</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:111.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following are the main components of 802.1x illustrated in Figure 8-5:</span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Supplicant: </b>Software running on the client workstation</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Authenticator: </b>The wireless access point</span></div>
<div class=paragraph style=" padding:5.04pt 46.56pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Authentication Server: </b>RADIUS server such as the Cisco Secure Access Control Server (ACS)</span></div>
<div class=paragraph style=" padding:4.08pt 38.88pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;External Database: </b>External database such as the Microsoft Active Directory, Lightweight Directory Access Protocol (LDAP), or any Open Database Connectivity (ODBC) repository.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:90.00pt;">
<div class=block style=" width:90.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 30.00pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE</b></span></div>
</div>
</td>
<td class=cell colspan="6" valign="top" style=" width:396.00pt;">
<div class=block style=" width:396.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 0.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The Cisco comprehensive identity-based solution, which is based on 802.1x, is referred to as Identity Based Networking Services (IBNS).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:61.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:90.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:131.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:131.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:129.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:2.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:92.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:23.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:88.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:112.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>220    </b><span class=font4>Chapter 8: Wireless Security</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 80.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44>The basic 802.1x authentication negotiation scheme is illustrated in Figure 8-6.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 247.20pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-6    </b><span class=font43><i>802.1x Authentication Negotiation Basics</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:132.00pt;">
<div class=block style="position:relative; z-index:2; width:132.00pt; height:25.20pt;">
<div class=block style="float:right; width:1px; height:10.80pt; clear:right;"><span style="line-height:0pt;"></span></div>
<div class=block style="float:right; width:49.92pt; height:14.40pt; clear:right;"><span style="line-height:0pt;"></span></div>
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 77.04pt; text-align:justify; text-indent:2.40pt;"><span class=font3 style=" line-height:9.60pt;">Wirless Client with Supplicant</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:153.60pt;">
<div class=block style="position:relative; z-index:1; width:153.60pt; height:25.20pt;">
<div class=block style="float:left; width:1px; height:20.40pt; clear:left;"><span style="line-height:0pt;"></span></div>
<div class=block style="float:left; width:92.16pt; height:4.32pt; clear:left;"><span style="line-height:0pt;"></span></div>
<div class=block style="float:left; width:138.72pt; height:0.48pt; clear:left;"><span style="line-height:0pt;"></span></div>
<div class=paragraph style=" padding:16.08pt 13.68pt 0.00pt 92.64pt; text-align:justify;"><span class=font3>Authenticator</span></div>
<div class=block style=" width:188.64pt; height:29.28pt; position:absolute; left:-49.92pt; top:20.40pt; z-index:-1;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-91.jpg" alt="" style=" width:188.64pt; height:29.28pt;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:200.40pt;">
<div class=block style=" width:200.40pt; height:25.20pt;">
<div class=paragraph style=" padding:8.16pt 77.28pt 0.00pt 46.56pt; text-align:justify;"><span class=font3>Authentication Server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="3" valign="top" style=" width:129.60pt;">
<div class=block style=" width:129.60pt; height:42.96pt;">
<div class=paragraph style=" padding:0.00pt 33.60pt 0.00pt 92.16pt; text-align:justify;"><span class=font3 style=" line-height:14.16pt;">1 2 3</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:132.72pt;">
<div class=block style=" width:132.72pt; height:20.64pt;">
<div class=paragraph style=" padding:6.24pt 73.20pt 0.00pt 2.40pt; text-align:justify;"><span class=font1>EAP-Identity-Request</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:223.68pt;">
<div class=block style=" width:223.68pt; height:20.64pt;">
<div class=paragraph style=" padding:3.84pt 131.52pt 0.00pt 1.68pt; text-align:justify;"><span class=font3>(EAP Method Dependent)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:95.04pt;">
<div class=block style=" width:95.04pt; height:13.20pt;">
<div class=paragraph style=" padding:0.00pt 33.36pt 0.00pt 0.00pt; text-align:justify;"><span class=font1>EAP-Identity-Response</span></div>
</div>
</td>
<td class=cell colspan="3" rowspan="3" valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:34.32pt;">
<div class=paragraph style=" padding:9.60pt 17.76pt 0.00pt 37.68pt; text-align:justify; text-indent:3.84pt;"><span class=font1 style=" line-height:14.16pt;">Auth Exchange with Auth Server Authentication Successful/Rejected</span></div>
</div>
</td>
<td class=cell rowspan="3" valign="top" style=" width:112.32pt;">
<div class=block style=" width:112.32pt; height:34.32pt;">
<div class=paragraph style=" padding:22.32pt 108.48pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>4</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:95.04pt;">
<div class=block style=" width:95.04pt; height:9.12pt;">
<div class=paragraph style=" padding:0.96pt 37.20pt 0.00pt 3.84pt; text-align:justify;"><span class=font1>EAP-Auth Exchange</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:224.64pt;">
<div class=block style=" width:224.64pt; height:12.00pt;">
<div class=paragraph style=" padding:6.00pt 36.24pt 0.00pt 132.48pt; text-align:justify;"><span class=font1>EAP-Success/Failure</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.52pt;">
<div class=paragraph style=" padding:0.00pt 152.88pt 0.00pt 285.60pt; text-align:justify;"><span class=font1>Policy Instructions</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:2.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.52pt;">
<div class=paragraph style=" padding:0.00pt 390.00pt 0.00pt 92.16pt; text-align:justify;"><span class=font3>5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.52pt;">
<div class=paragraph style=" padding:0.00pt 306.48pt 0.00pt 141.60pt; text-align:justify;"><span class=font1>EAPOL-Logoff</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:25.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:285.60pt;">
<div class=block style=" width:285.60pt; height:4.32pt;">
<div class=paragraph style=" padding:0.00pt 116.40pt 0.00pt 151.68pt; text-align:justify;"><span class=font1>802.1x</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:200.40pt;">
<div class=block style=" width:200.40pt; height:4.32pt;">
<div class=paragraph style=" padding:0.00pt 165.84pt 0.00pt 12.96pt; text-align:justify;"><span class=font1>RADIUS</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:308.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following are the steps illustrated in Figure 8-6:</span></div>
<div class=paragraph style=" padding:6.96pt 38.64pt 0.00pt 111.84pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>1&nbsp;</b><span class=font44>The client attempts to connect to the wireless network, and the wireless access point sends an EAP identity request to the client (supplicant).</span></span></div>
<div class=paragraph style=" padding:3.84pt 38.40pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>2&nbsp;</b><span class=font44>The user enters his credentials, and the client machine sends the EAP identity reply to the wireless access point.</span></span></div>
<div class=paragraph style=" padding:6.24pt 48.24pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>3&nbsp;</b><span class=font44>Depending on the EAP method, the client starts an authentication exchange to the authentication server. An EAP tunnel passes directly to the authentication server.</span></span></div>
<div class=paragraph style=" padding:6.00pt 44.16pt 0.00pt 111.60pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>4&nbsp;</b><span class=font44>The authentication server accepts or rejects the user and sends further information/ instructions based on the authentication and authorization of the user.</span></span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>At the end of the session, the client sends an EAPOL Logout message.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The different types of EAP methods are categorized as follows:</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Challenge/response based</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cryptographic based</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Tunneling methods</span></div>
<div class=paragraph style=" padding:0.00pt 144.24pt 0.00pt 90.00pt; text-align:left; text-indent:7.44pt;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Generic token and one-time-passwords The challenge-response-based EAP methods are the following:</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;EAP with Message Digest 5: Uses MD5 hashing for authentication exchange</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Cisco LEAP: Authentication based on usernames and passwords</span></div>
<div class=paragraph style=" padding:4.56pt 47.28pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;EAP using the Microsoft Challenge Handshake Authentication Protocol Version 2 (MSCHAPv2)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:42.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:129.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:2.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:92.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:23.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:88.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:112.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:129.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:74.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:23.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:88.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:112.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 221.28pt; text-align:justify;"><span class=font4>Authentication and Authorization of Wireless Users <b>221</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:145.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The cryptographic-based EAP method is as follows:</span></div>
<div class=paragraph style=" padding:6.96pt 43.68pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;EAP over Transport Layer Security (EAP-TLS): Uses x.509 digital certificates and TLS for authentication</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The most common EAP tunneling methods are as follows:</span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Protected EAP (PEAP)</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;EAP Tunneling Transport Layer Security (EAP-TTLS)</span></div>
<div class=paragraph style=" padding:4.56pt 48.48pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.24pt;">•&nbsp;EAP Flexible Authentication via Secure Tunneling (EAP-FAST): Designed not to require certificates</span></div>
<div class=paragraph style=" padding:3.60pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The EAP Generic Token Card (EAP-GTC) is an EAP method used for generic token cards and one-time passwords.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 41.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>EAP-GTC is defined in RFC 3748. It does not protect the authentication data in any way.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 192.24pt 0.00pt 90.00pt; text-align:justify;"><span class=font44>The following sections describe each EAP method.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 363.60pt 0.00pt 36.72pt; text-align:justify;"><span class=font8><b>EAP with MD5</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:43.20pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">When you configure EAP-MD5, both the client and the authentication server must have a shared secret established out-of-band. This shared secret is typically a password associated with an identity/username. Figure 8-7 illustrates the primary steps within the EAP-MD5 authentication method.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:204.00pt;">
<div class=block style="position:relative; z-index:1; width:204.00pt; height:42.48pt;">
<div class=block style="float:right; width:1px; height:28.56pt; clear:right;"><span style="line-height:0pt;"></span></div>
<div class=block style="float:right; width:121.92pt; height:13.92pt; clear:right;"><span style="line-height:0pt;"></span></div>
<div class=paragraph style=" padding:0.00pt 76.32pt 0.00pt 36.72pt; text-align:justify;"><span class=font4><b>Figure 8-7 </b><span class=font43><i>EAP-MD5</i></span></span></div>
<div class=paragraph style=" padding:7.20pt 73.44pt 0.00pt 77.04pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">Wireless Client with Supplicant</span></div>
<div class=block style=" width:188.64pt; height:28.80pt; position:absolute; left:82.08pt; top:38.16pt; z-index:-1;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-92.jpg" alt="" style=" width:188.64pt; height:28.80pt;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:81.60pt;">
<div class=block style="position:relative; z-index:1; width:81.60pt; height:42.48pt;">
<div class=block style="float:left; width:1px; height:38.16pt; clear:left;"><span style="line-height:0pt;"></span></div>
<div class=block style="float:left; width:20.16pt; height:4.32pt; clear:left;"><span style="line-height:0pt;"></span></div>
<div class=paragraph style=" padding:33.36pt 13.68pt 0.00pt 20.64pt; text-align:justify;"><span class=font3>Authenticator</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:200.40pt;">
<div class=block style=" width:200.40pt; height:42.48pt;">
<div class=paragraph style=" padding:25.44pt 77.28pt 0.00pt 46.56pt; text-align:justify;"><span class=font3>Authentication Server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:129.60pt;">
<div class=block style=" width:129.60pt; height:19.92pt;">
<div class=paragraph style=" padding:0.00pt 33.60pt 0.00pt 92.16pt; text-align:justify;"><span class=font3 style=" line-height:13.92pt;">1 2</span></div>
</div>
</td>
<td class=cell colspan="5" valign="top" style=" width:356.40pt;">
<div class=block style=" width:356.40pt; height:19.92pt;">
<div class=paragraph style=" padding:6.24pt 296.88pt 0.00pt 2.40pt; text-align:justify;"><span class=font1>EAP-Identity-Request</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.72pt;">
<div class=paragraph style=" padding:0.00pt 294.72pt 0.00pt 129.36pt; text-align:center;"><span class=font1 style=" line-height:7.20pt;">EAP-Identity-Response (HASH)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:204.00pt;">
<div class=block style=" width:204.00pt; height:19.92pt;">
<div class=paragraph style=" padding:13.92pt 15.60pt 0.00pt 132.48pt; text-align:justify;"><span class=font1>EAP-Success/Failure</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:169.68pt;">
<div class=block style=" width:169.68pt; height:19.92pt;">
<div class=paragraph style=" padding:0.00pt 17.76pt 0.00pt 58.32pt; text-align:justify; text-indent:3.84pt;"><span class=font1 style=" line-height:14.16pt;">Auth Exchange with Auth Server Authentication Successful/Rejected</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:112.32pt;">
<div class=block style=" width:112.32pt; height:19.92pt;">
<div class=paragraph style=" padding:7.92pt 108.48pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:204.00pt;">
<div class=block style=" width:204.00pt; height:12.48pt;">
<div class=paragraph style=" padding:0.72pt 7.68pt 0.00pt 192.48pt; text-align:justify;"><span class=font3>4</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.32pt;">
<div class=block style=" width:58.32pt; height:12.48pt;">
<div class=paragraph style=" padding:0.00pt 21.60pt 0.00pt 0.00pt; text-align:justify;"><span class=font1>Allow or Deny</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:223.68pt;">
<div class=block style=" width:223.68pt; height:12.48pt;">
<div class=paragraph style=" padding:6.72pt 152.88pt 0.00pt 23.28pt; text-align:justify;"><span class=font1>Policy Instructions</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:2.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:129.60pt;">
<div class=block style=" width:129.60pt; height:12.00pt;">
<div class=paragraph style=" padding:0.00pt 33.60pt 0.00pt 92.16pt; text-align:justify;"><span class=font3>5</span></div>
</div>
</td>
<td class=cell colspan="5" valign="top" style=" width:356.40pt;">
<div class=block style=" width:356.40pt; height:12.00pt;">
<div class=paragraph style=" padding:5.04pt 295.68pt 0.00pt 0.96pt; text-align:justify;"><span class=font1>Access to the Network</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:89.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:129.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:74.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:23.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:88.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:112.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>222    </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:261.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following are the steps illustrated in Figure 8-7:</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font4><b>Step 1   </b><span class=font44>A random challenge is sent to the supplicant from the wireless access point.</span></span></div>
<div class=paragraph style=" padding:6.96pt 74.16pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 2  </b><span class=font44>The client sends its response containing the hash of the challenge created using the shared secret.</span></span></div>
<div class=paragraph style=" padding:6.00pt 92.16pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 3  </b><span class=font44>The RADIUS authentication server verifies the hash and accepts or rejects the authentication.</span></span></div>
<div class=paragraph style=" padding:6.24pt 98.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 4 </b><span class=font44>The wireless access point allows or disallows access based on the RADIUS authentication server decision.</span></span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 5 </b><span class=font44>If the authentication is successful, the client gains access to the network.</span></span></div>
<div class=paragraph style=" padding:6.72pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Because EAP-MD5 is purely an authentication protocol, it does not provide encryption after the authentication process. Therefore, all the messages are transmitted in cleartext after authentication. In addition, because it is only a client authentication protocol, the server side is not authenticated. Subsequently, you cannot detect rogue wireless access points if you implement EAP-MD5. The use of mutual authentication provides a means of reducing the risk of users installing rogue access points within the infrastructure, because mutual authentication also requires the client to authenticate the server and, most definitely, rogue devices will not do this. Another way you can try to protect against rogue access points is to lock down your switches so that you can use only authorized MAC addresses on your wired network. This is explained later in this chapter.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.36pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 36.00pt; text-align:justify;"><span class=font4 style=" line-height:12.00pt;"><b>TIP&nbsp;</b><span class=font44>EAP-MD5 is vulnerable to dictionary and brute-force attacks when used with Ethernet and</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">wireless.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:172.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Cisco LEAP</b></span></div>
<div class=paragraph style=" padding:3.60pt 37.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Cisco LEAP was initially developed to address the vulnerabilities that WEP showed. At that time, it was an alternative protocol that allowed you to deploy wireless networks without requiring a certificate infrastructure for clients by leveraging authentication mechanisms that were already available within the infrastructure. The following are some of the benefits presented by using Cisco LEAP:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;802.1x EAPOL messages are used within Cisco LEAP.</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Server authentication is achievable.</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;The client username and password are sent over MS-CHAP.</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;RADIUS is used as the authentication server.</span></div>
<div class=paragraph style=" padding:0.00pt 66.00pt 0.00pt 89.76pt; text-align:left; text-indent:7.68pt;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;LEAP provides mechanisms for deriving and distributing encryption keys. Many people are now migrating from Cisco LEAP to full 802.1x implementations.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 221.28pt; text-align:justify;"><span class=font4>Authentication and Authorization of Wireless Users <b>223</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:37.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>EAP-TLS</b></span></div>
<div class=paragraph style=" padding:3.36pt 40.08pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">EAP-TLS provides several features. For example, it supports mutual authentication providing an encrypted transport layer and the capability to change the keys dynamically. EAP-TLS requires the use of digital certificates. You need to keep this in mind when thinking about deploying EAP-TLS within your network.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph style=" padding:0.00pt 259.20pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>EAP-TLS is defined in RFC 2246.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:372.00pt;">
<div class=paragraph style=" padding:0.00pt 41.52pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">During the TLS handshake phase, the client and wireless device establish a session exchanging symmetric session keys used to encrypt the transport during the data transfer phase. TLS has two layers:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Record layer: </b>Includes information about fragmentation, MAC, and encryption</span></div>
<div class=paragraph style=" padding:0.24pt 144.72pt 0.00pt 90.00pt; text-align:left; text-indent:7.44pt;"><span class=font44 style=" line-height:15.84pt;"><b>•&nbsp;Message layer: </b>Includes four different types of messages The following are the four message types:</span></div>
<div class=paragraph style=" padding:4.32pt 41.04pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Change cipher spec: </b>This defines a change in the session context to be used by the record layer.</span></div>
<div class=paragraph style=" padding:4.32pt 39.36pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Alert message: </b>There are approximately 26 different alert message subtypes. (They include access denied, close notify, decryption failed, and certificate revoked.)</span></div>
<div class=paragraph style=" padding:3.36pt 38.88pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Handshake protocol: </b>During the handshake protocol, the client and the server exchange different hello messages; server authentication and key exchange messages; client authentication and key exchange messages; and the finalization message to close the session.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Application data: </b>This is the actual data that is transmitted over the TLS tunnel.</span></div>
<div class=paragraph style=" padding:4.80pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">EAP-TLS does not use all parts of the TLS record protocol; however, it uses the TLS handshake for mutual authentication, for cipher suite negotiation, and for derivation of the session keys. EAP-TLS was initially designed for PPP connections; however, in wireless implementations, EAP-TLS is used as a strong and secure mechanism for mutual authentication and key establishment; then the native WEP mechanisms of the wireless device are used to encrypt the data.</span></div>
<div class=paragraph style=" padding:24.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>PEAP</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Many people refer to PEAP as the true EAP-TLS in wireless implementations. PEAP uses EAP-TLS functionality by securing the open exchanges, but it keeps things simple. For instance, PEAP requires only server-side certificates; however, it can still perform mutual authentication between the client and the server. It also uses TLS for the secure tunnel and</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:68.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>224   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:208.08pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">lengthens the EAP-TLS exchange beyond the finished message to add client authentication and key exchange. One of the disadvantages of PEAP is that it is considered to be a chatty protocol. The PEAP protocol has two phases:</span></div>
<div class=paragraph style=" padding:6.00pt 77.28pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Phase 1: </b>Used to establish a secure tunnel using the EAP-TLS with server authentication</span></div>
<div class=paragraph style=" padding:4.32pt 38.64pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Phase 2: </b>Authenticates the client based on EAP methods, exchange of arbitrary information, and other PEAP-specific means using the information established during Phase 1</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44>Many people use PEAP because it is simple to implement within a wireless infrastructure.</span></div>
<div class=paragraph style=" padding:25.20pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>EAP Tunneled TLS Authentication Protocol (EAP-TTLS)</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">EAP-TTLS is basically the same as EAP-TLS; however, it extends the client authentication by the use of a method called <i>tunneled authentication. </i>With EAP-TTLS, the client does not need a digital certificate (only the authentication server requires one), thereby simplifying the client identity management.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>EAP-TTLS enables you to also use legacy authentication methods such as password-based methodologies.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:185.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>EAP-FAST</b></span></div>
<div class=paragraph style=" padding:2.88pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">EAP-FAST was initially known as the Tunneled EAP (TEAP) and as LEAP Version 2. EAP-FAST is classified by many as the most comprehensive and secure EAP type suitable for wireless implementations. It addresses the risks of man-in-the-middle and dictionary attacks. In addition, EAP-FAST reduces the hardware requirements, making it a flexible deployment model and more attractive to many people.</span></div>
<div class=paragraph style=" padding:6.24pt 42.24pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">EAP-FAST authentication does not require the use of a specific encryption type. Instead, the WLAN encryption type to be used is determined by the client wireless network interface card capabilities.</span></div>
<div class=paragraph style=" padding:6.24pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">If the client devices do not support WPA2 or WPA, you can deploy 802.1X authentication with dynamic WEP keys, but, because of the well-known exploits against WEP keys, this WLAN encryption mechanism is not recommended. If you must support WEP-only clients, it is recommended that you employ a session-timeout interval which requires that the clients derive a new WEP key on a frequent interval.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:100.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 221.28pt; text-align:justify;"><span class=font4>Authentication and Authorization of Wireless Users <b>225</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.80pt;">
<div class=paragraph style=" padding:0.00pt 86.40pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>TIP&nbsp;</b><span class=font44>30 minutes is the recommended session interval for typical WLAN data rates.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 70.32pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Cisco has a comprehensive list of frequently asked questions about EAP-FAST at</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a href="http://www.cisco.com/en/US/products/hw/wireless/ps4555/products_qanda_item09186a00802030dc.shtml">http://www.cisco.com/en/US/products/hw/wireless/ps4555/</a></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a href="http://www.cisco.com/en/US/products/hw/wireless/ps4555/products_qanda_item09186a00802030dc.shtml">products_qanda_item09186a00802030dc.shtml.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.36pt;">
<div class=paragraph style=" padding:0.00pt 392.16pt 0.00pt 36.72pt; text-align:justify;"><span class=font8><b>EAP-GTC</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.20pt;">
<div class=paragraph style=" padding:0.00pt 37.68pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">EAP-GTC enables you to use hardware token cards as one-time-passwords. An example of a hardware token card is the RSA SecurID solution.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 142.56pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>For more information about RSA SecurID, go to <a href="http://rsa.com">http://rsa.com.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:183.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can use EAP-GTC inside the TLS tunnel created by PEAP. You can use this EAP method to implement a two-factor authentication solution to avoid common password compromises and combine it with your remote access VPN solution. For instance, a user can use the token card for both wireless and remote access VPN authentication. If you are just starting to deploy a WLAN, you must decide whether token deployment is cost effective. Many people justify the cost of token deployment by using this authentication mechanism with other network infrastructure authentication, such as remote access VPN.</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In summary, the two EAP methods that most people implement today are EAP-FAST and PEAP. EAP-FAST provides more flexibility when deployed with 802.1x or NAC. EAP-FAST is easy to implement, and it is not Cisco proprietary. It supports Windows single-sign-on and provides support for login script operation with any user database such as Microsoft Active Directory, Lightweight Directory Access Protocol (LDAP), and one-time password (OTP). In addition, because EAP-FAST does not require certificates, you can configure it easily and distribute it for Cisco Aironet client devices with the Cisco Aironet Configuration Administration tool.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt;">
<div class=block style=" width:89.76pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 40.56pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>TIP</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:396.24pt;">
<div class=block style=" width:396.24pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 39.12pt 0.00pt 0.24pt; text-align:justify;"><span class=font44 style=" line-height:12.24pt;">It is recommended that you employ either WPA2 (AES-CCM) or WPA (TKIP) encryption, which are both dependent on the NIC card capabilities in the specific deployment.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:117.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:202.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:4.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:83.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:144.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>226    </b><span class=font4>Chapter 8: Wireless Security</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:77.76pt;">
<div class=paragraph style=" padding:0.00pt 55.68pt 0.00pt 36.24pt; text-align:left;"><span class=font8 style=" line-height:15.12pt;"><b>Configuring 802.1x with EAP-FAST in the Cisco Unified Wireless Solution</b></span></div>
<div class=paragraph style=" padding:2.64pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">This section describes how to configure the wireless LAN context (WLC), the Cisco Secure Services Client (CSSC), and Cisco Secure Access Control Server (ACS) to perform 802.1x authentication using EAP-FAST. Figure 8-8 illustrates the topology used in this configuration example.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 127.20pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-8    </b><span class=font43><i>Configuring 802.1x with EAP-FAST on the Cisco Unified Wireless Solution</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:257.52pt;">
<div class=block style=" width:257.52pt; height:49.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:83.76pt;">
<div class=block style=" width:83.76pt; height:56.40pt;">
<div class=paragraph style=" padding:44.64pt 8.16pt 0.00pt 23.52pt; text-align:justify;"><span class=font3>LWAPP Tunnel</span></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:144.72pt;">
<div class=block style=" width:144.72pt; height:56.40pt;">
<div class=paragraph style=" padding:0.00pt 88.56pt 0.00pt 8.64pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">Wireless LAN</span></div>
<div class=paragraph style=" padding:0.00pt 84.24pt 0.00pt 5.04pt; text-align:left; text-indent:10.80pt;"><span class=font3 style=" line-height:9.60pt;">Controller Management IP</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font1>172.18.85.96</span></div>
<div class=paragraph style=" padding:1.20pt 79.44pt 0.00pt 0.00pt; text-align:center;"><span class=font3>AP Manager</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font1>172.18.85.97</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt; height:7.20pt;">
</td>
<td class=cell colspan="2" rowspan="2" valign="top" style=" width:206.88pt;">
<div class=block style=" width:206.88pt; height:24.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:50.64pt;">
<div class=block style=" width:50.64pt; height:24.96pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 12.96pt; text-align:left;"><span class=font3 style=" letter-spacing:-0.50pt;"><b><i>LWAPPP</i></b></span></div>
<div class=paragraph style=" text-align:left;"><span class=font6>:#:&lt;xxxxx&gt;</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 9.60pt; text-align:left;"><span class=font4 style=" letter-spacing:-1.00pt;">OOOOOO</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt; height:7.20pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:228.48pt;">
<div class=block style=" width:228.48pt; height:17.76pt;">
<div class=paragraph style=" padding:0.00pt 152.64pt 0.00pt 24.72pt; text-align:justify;"><span class=font1 style=" line-height:7.20pt;">Controll Messages Data Encapsulation</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:202.32pt;">
<div class=block style=" width:202.32pt; height:17.04pt;">
<div class=paragraph style=" padding:0.00pt 83.04pt 0.00pt 78.00pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">Workstation with CSSC</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:283.68pt;">
<div class=block style=" width:283.68pt; height:17.04pt;">
<div class=paragraph style=" padding:0.48pt 204.96pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>Wireless Access Point</span></div>
<div class=paragraph style=" padding:0.96pt 204.48pt 0.00pt 0.00pt; text-align:center;"><span class=font1>172.18.85.123</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:82.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.64pt;">
<div class=paragraph style=" padding:0.00pt 79.20pt 0.00pt 341.04pt; text-align:center;"><span class=font3 style=" line-height:7.20pt;">Cisco Secure ACS <span class=font1>172.18.85.181</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Figure 8-8 shows a workstation with the CSSC connecting to a Cisco wireless access point (with IP address 172.18.85.123) in a lightweight configuration controlled by a WLC. The management IP address of the WLC is 172.18.85.96, and the AP manager IP address is 172.18.85.97. The WLC forwards all authentication requests to a Cisco Secure ACS.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:92.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Configuring the WLC</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Complete the following steps to configure the WLC to use the Cisco Secure ACS server for authentication. Cisco Secure ACS validates the user credentials using the Windows database. (The Cisco Secure ACS server configuration is covered in the next section.)</span></div>
<div class=paragraph style=" padding:5.76pt 74.64pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 1 </b><span class=font44>Log in to the WLC as an administrator and click the <b>Security </b>tab; then click <b>New </b>to add a new RADIUS server, as illustrated in Figure 8-9. You will then see the screen shown in Figure 8-10.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:92.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:202.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:4.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:50.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:83.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:144.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 221.28pt; text-align:justify;"><span class=font4>Authentication and Authorization of Wireless Users <b>227</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 261.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-9   </b><span class=font43><i>Adding a RADIUS Server to the WLC</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:332.16pt; height:240.96pt; padding:0.00pt 77.04pt 0.00pt 76.80pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-93.jpg" alt="" style=" width:332.16pt; height:240.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 241.44pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-10 </b><span class=font43><i>RADIUS Server Configuration on the WLC</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:334.08pt; height:241.92pt; padding:0.00pt 76.08pt 0.00pt 75.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-94.jpg" alt="" style=" width:334.08pt; height:241.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4>228    Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:191.28pt;">
<div class=paragraph style=" padding:0.00pt 74.16pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 2  </b><span class=font44>In the screen shown in Figure 8-10, enter the RADIUS server information. In this case, the Cisco Secure ACS IP address is <b>172.18.85.181</b>. Enter a shared key to mutually authenticate the WLC and the RADIUS server. In this example, the default RADIUS port UDP/ <b>1812 </b>is used. Ports UDP/1645 (legacy) and UDP/1812 are supported by Cisco Secure ACS for RADIUS authentication. Leave all other options with the default values and click <b>Apply.</b></span></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>Step 3  </b><span class=font44>By default, the WLC uses 802.1x for the security policies in WLANs.</span></span></div>
<div class=paragraph style=" padding:0.00pt 75.12pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can also combine 802.1x with static WEP, WPA, and others. In this example, 802.1x is used without WEP/WPA. To enable this configuration, navigate to the <b>WLANs </b>tab and edit the configured WLAN. (In this example, the WLAN SSID is named <b>ciscotest.) </b>Under <b>Security Policies </b>and <b>Layer 2 Security, </b>select <b>802.1x </b>from the drop­down menu, as shown in Figure 8-11.</span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 8-11  </b><span class=font43><i>WLAN Layer 2 Security Policy</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.72pt; height:244.80pt; padding:0.00pt 74.88pt 0.00pt 74.40pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:336.72pt; height:244.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:57.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:78.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:80.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:13.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:116.40pt;">
<div class=block style=" width:116.40pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.96pt; text-align:left;"><span class=font6><i>ft </i><span class=font0><b>Cisco - Windows Internet Explorer</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:8.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:8.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:8.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:8.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:6.96pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font0><b>^jiwf </b>т https:,il72,13</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:6.96pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font0>35 Screens/frameset html</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:6.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:6.96pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 13.92pt; text-align:left;"><span class=font0>Certificate Error</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:6.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:6.96pt;">
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font38><i>U -</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:14.64pt;">
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font0>4   <span class=font40><i>&amp; </i></span>Cisco</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:14.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:14.64pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font20>n</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:14.64pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 28.08pt; text-align:left;"><span class=font24 style=" letter-spacing:-0.50pt;">:<span style=" letter-spacing:-1.00pt;"> </span>a<span style=" letter-spacing:-1.00pt;"> </span><span class=font44 style=" letter-spacing:0.00pt;"><b>• a  # • </b></span><span class=font20 style=" letter-spacing:0.00pt;">й</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:14.64pt;">
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font0>^age - Tools</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:14.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:18.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:136.80pt;">
<div class=block style=" width:136.80pt; height:18.00pt;">
<div class=paragraph style=" padding:11.76pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font0>MONITOR    WLANs    CONTROLLER    WIRELESS SECURITY</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:18.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 3.60pt; text-align:left;"><span class=font0 style=" line-height:9.36pt;">Save <span class=font38><i>Z</i></span>:    j.. &quot;a; MANAGEMENT    COMMANDS <b>HELP</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:18.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:18.00pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font0>out Refresh</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:10.80pt;">
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font0><b>WLANs</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:10.80pt;">
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 4.56pt; text-align:left;"><span class=font0><b>WLANS &gt; Edit</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:10.80pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:10.80pt;">
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 78.00pt; text-align:left;"><span class=font30>&lt;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:10.80pt;">
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 0.96pt; text-align:left;"><span class=font0>Back</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:10.80pt;">
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 0.72pt; text-align:left;"><span class=font0><b>Apply</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:10.80pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:12.48pt;">
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font0><b>WLANs</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:12.48pt;">
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font0><b>WLAN ID</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:12.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:12.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:12.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:12.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:12.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font0>WLANs</span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 8.40pt; text-align:left;"><span class=font0>AP Groups VLAN</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:7.68pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font0><b>Profile Name</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:7.68pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font0>ciscotest</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:7.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:7.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:7.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:7.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:7.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:7.44pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font0><b>WLAN SSID</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:7.44pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font0>ciscotest</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:7.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:7.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:7.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:7.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:13.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:13.44pt;">
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font0><b>General Policies</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:13.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:13.44pt;">
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 31.92pt; text-align:left;"><span class=font0><b>Security Policies</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:13.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:13.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:13.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:8.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:8.88pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font0>Radio Policy</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:8.88pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font0>All <b>v</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:8.88pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 37.20pt; text-align:left;"><span class=font0>IPv6 Enable</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:8.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.96pt; text-align:left;"><span class=font5>□</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:8.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:8.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:6.24pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 9.84pt; text-align:left;"><span class=font0>Admin Status</span></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:11.04pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font20>3 <span class=font0>Enabled</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:11.04pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 8.88pt; text-align:left;"><span class=font1>=</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:4.80pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:4.80pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 37.20pt; text-align:left;"><span class=font0>Layer 2 Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:4.80pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font0>802. IX</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:4.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 11.52pt; text-align:left;"><span class=font44><b>■</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:13.92pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:13.92pt;">
<div class=paragraph style=" padding:0.00pt 2.16pt 0.00pt 10.32pt; text-align:left;"><span class=font0 style=" line-height:8.16pt;">Session Timeout (sees) Quality of Service (QoS)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:13.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font0>1SQ0</span></div>
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font0>Silver [best effort) <b>v</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:13.92pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 0.96pt; text-align:left;"><span class=font0>None</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.96pt; text-align:left;"><span class=font0>WPA1+WPA2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:13.92pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:13.92pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:22.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:22.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 9.84pt; text-align:left;"><span class=font0 style=" line-height:8.16pt;">WMM Policy</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font0 style=" line-height:8.16pt;">7320 Phone Support</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font0 style=" line-height:8.16pt;">Broadcast SSID</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:22.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font0 style=" line-height:7.92pt;">Disabled <b>v</b></span></div>
<div class=paragraph style=" padding:0.00pt 4.56pt 0.00pt 3.36pt; text-align:left;"><span class=font0 style=" line-height:7.92pt;">□ Client CAC Limit   □ АР CAC Limit <span class=font20>3 </span>Enabled</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:22.08pt;">
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 37.20pt; text-align:left;"><span class=font0>Layer 3 Security</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:47.28pt;">
<div class=block style=" width:47.28pt; height:22.08pt;">
<div class=paragraph style=" padding:0.72pt 26.64pt 0.00pt 0.96pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">Static WEP Cyrils</span></div>
<div class=paragraph style=" padding:4.08pt 7.68pt 0.00pt 0.96pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">Static-ЛЕР + S02.1X <span class=font38><i>CT-</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:22.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:9.60pt;">
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 9.84pt; text-align:left;"><span class=font0>Aironet IE</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:9.60pt;">
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font20>3 <span class=font0>Enabled</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:12.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:57.84pt;">
<div class=block style=" width:57.84pt; height:71.04pt;">
<div class=paragraph style=" padding:0.96pt 11.28pt 0.00pt 9.84pt; text-align:left;"><span class=font0 style=" line-height:8.40pt;">Allow AAA Override Client Exclusion</span></div>
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font0 style=" line-height:8.16pt;">DHCP Server</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font0 style=" line-height:8.16pt;">DHCP Addr. Assignment</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font0 style=" line-height:8.16pt;">Interface Name</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font0 style=" line-height:8.16pt;">MFP Version Required</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font0>MFP Signature</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font0>Generation</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font0>H-REAP Local Switching</span></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:78.96pt;">
<div class=block style=" width:78.96pt; height:71.04pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font0>□&nbsp;Enabled</span></div>
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font20 style=" line-height:5.76pt;">3 <span class=font0>Enabled ** |б0</span></span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 34.56pt; text-align:left;"><span class=font0 style=" line-height:5.76pt;">Timeout Value (sees)</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font0 style=" line-height:5.76pt;">□&nbsp;Override</span></div>
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font0>□&nbsp;Required</span></div>
<div class=paragraph style=" padding:3.60pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font0>| management <b>v</b></span></div>
<div class=paragraph style=" padding:12.00pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font0>z</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:12.96pt;">
<div class=paragraph style=" padding:1.20pt 0.72pt 0.00pt 37.20pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">* Web Policy cannot be IPsec.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.48pt;">
<div class=block style=" width:30.48pt; height:12.96pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font0>used in cc-mbin</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:12.96pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font0>tion will</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.20pt;">
<div class=block style=" width:13.20pt; height:12.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt;">
<div class=block style=" width:58.56pt; height:58.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:111.36pt;">
<div class=block style=" width:111.36pt; height:58.08pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 37.20pt; text-align:left;"><span class=font0 style=" line-height:4.08pt;">** When client exclusion is enabled<sub>r</sub> a t</span></div>
<div class=paragraph style=" padding:0.00pt 0.24pt 0.00pt 37.20pt; text-align:left;"><span class=font0 style=" line-height:4.08pt;">value of zero means infinity [will require administrative override to reset enclud *&quot; CKIP is not supported by lOrat APs</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:30.00pt;">
<div class=block style=" width:30.00pt; height:58.08pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font0>rneout</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font0>d clients)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:336.72pt;">
<div class=block style=" width:336.72pt; height:8.16pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:57.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:78.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:80.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:13.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 74.64pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 4 </b><span class=font44>Scroll down on the same screen and choose the configured Cisco Secure ACS server on the drop-down menu under the <b>RADIUS Servers </b>section, as shown in Figure 8-12. Click <b>Apply.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:82.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 221.28pt; text-align:justify;"><span class=font4>Authentication and Authorization of Wireless Users <b>229</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 247.92pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-12 </b><span class=font43><i>Selecting the Configured RADIUS Server</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-95.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 96.72pt 0.00pt 90.00pt; text-align:justify;"><span class=font44>The next section shows you how to configure the Cisco Secure ACS server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:176.88pt;">
<div class=paragraph style=" padding:0.00pt 35.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font8><b>Configuring the Cisco Secure ACS Server for 802.1x and EAP-FAST</b></span></div>
<div class=paragraph style=" padding:3.36pt 39.36pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Complete the following steps to configure the Cisco Secure ACS server for 802.1x authentication using the EAP-FAST method. You first add the WLC as AAA client on the Cisco Secure ACS server.</span></div>
<div class=paragraph style=" padding:6.24pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">To add the WLC as a AAA client on Cisco Secure ACS, click the <b>Network Configuration </b>radio button. You can create a network device group to maintain a collection of AAA clients and AAA servers, or you can use the default <b>Not Assigned </b>network device group. In this example, the WLC is added to the <b>Not Assigned </b>default group. Click the <b>Not Assigned </b>group.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 1   </b><span class=font44>Click <b>Add Entry. </b>The screen shown in Figure 8-13 is displayed.</span></span></div>
<div class=paragraph style=" padding:6.96pt 74.88pt 0.00pt 126.24pt; text-align:justify; text-indent:-36.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 2 </b><span class=font44>Complete the form by entering the hostname and IP address of the <b>WLC. (WLC </b>is the hostname, and <b>172.18.85.96 </b>is the management IP address of the WLC in this example.)</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:88.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:360.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.56pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>230   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 233.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-13 </b><span class=font43><i>Adding an AAA Client into Cisco Secure ACS</i></span></span></div>
<div class=paragraph style=" padding:16.08pt 0.00pt 0.00pt 74.40pt; text-align:left;"><span class=font1 style=" letter-spacing:-0.50pt;"><i>\<u>^^</u>^Tj&lt; </i><span class=font3 style=" letter-spacing:0.00pt;">-   <u>|B </u></span><span class=font0 style=" letter-spacing:0.00pt;"><u>ht</u>tp;/J172.18.S5.1Sl;£283/index£.htm</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-96.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="2" valign="top" style=" width:125.76pt;">
<div class=block style=" width:125.76pt; height:86.88pt;">
<div class=paragraph style=" padding:0.00pt 9.36pt 0.00pt 90.24pt; text-align:justify;"><span class=font4><b>Step 3</b></span></div>
<div class=paragraph style=" padding:20.88pt 9.12pt 0.00pt 90.24pt; text-align:justify;"><span class=font4><b>Step 4</b></span></div>
<div class=paragraph style=" padding:16.08pt 9.60pt 0.00pt 90.24pt; text-align:justify;"><span class=font4 style=" line-height:18.00pt;"><b>Step 5 Step 6</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:360.24pt;">
<div class=block style=" width:360.24pt; height:60.00pt;">
<div class=paragraph style=" padding:0.00pt 74.64pt 0.00pt 0.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Enter the shared secret to be used between the Cisco Secure ACS server and the WLC. (In this example, the key is <b>1qaz@WSX.)</b></span></div>
<div class=paragraph style=" padding:6.00pt 84.24pt 0.00pt 0.24pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Choose <b>RADIUS </b>(Cisco Airspace) under the drop-down menu in the Authenticate Using section.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:360.24pt;">
<div class=block style=" width:360.24pt; height:26.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font44>Click <b>Submit + Apply.</b></span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In this example, the Cisco Secure ACS server queries an external<br /></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:158.88pt;">
<div class=paragraph style=" padding:0.00pt 74.40pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Windows 2003 server for authentication credentials. Navigate through the radio button sequence as follows. Click <b>External User Databases &gt; Database Configuration &gt; Windows Database &gt; Configure.</b></span></div>
<div class=paragraph style=" padding:6.00pt 75.12pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 7  </b><span class=font44>Under the Windows EAP Settings, check the <b>Enable password change inside PEAP </b>or <b>EAP-FAST </b>checkbox, as illustrated in Figure 8-14.</span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 8 </b><span class=font44>Click <b>Submit.</b></span></span></div>
<div class=paragraph style=" padding:6.96pt 83.76pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 9   </b><span class=font44>Navigate to <b>External User Databases &gt; Unknown User Policy </b>and click the <b>Check the following external user databases </b>radio button.</span></span></div>
<div class=paragraph style=" padding:6.00pt 85.20pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 10 </b><span class=font44>Click the <b>Windows Database </b>from <b>External Databases </b>to <b>Selected Databases, </b>as shown in Figure 8-15.</span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 11 </b><span class=font44>Click <b>Submit.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:49.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:125.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:360.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 221.28pt; text-align:justify;"><span class=font4>Authentication and Authorization of Wireless Users <b>231</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 314.64pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-14 </b><span class=font43><i>Windows EAP Settings</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.08pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-97.jpg" alt="" style=" width:336.96pt; height:244.08pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 173.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-15 </b><span class=font43><i>Selecting the Windows Database on the Unknown User Policy</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.08pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-98.jpg" alt="" style=" width:336.96pt; height:244.08pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>232   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:65.28pt;">
<div class=paragraph style=" padding:0.00pt 77.76pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 12 </b><span class=font44>Next, you have to enable EAP-FAST support on the Cisco Secure ACS Server. To do this, navigate via the radio buttons to <b>System Configuration &gt; Global Authentication Setup &gt; EAP-FAST Configuration. </b>The screen in Figure 8-16 is displayed.</span></span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 8-16 </b><span class=font43><i>Enabling EAP-FAST on Cisco Secure ACS</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-99.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:201.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 13 </b><span class=font44>Check <b>Allow EAP-FAST.</b></span></span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 14 </b><span class=font44>In this example, the recommended (default) values for <b>Active master</b></span></span></div>
<div class=paragraph style=" padding:0.72pt 75.12pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;"><b>key TTL </b>(1 month), <b>Retired master key TTL </b>(3 months), and <b>Tunnel PAC TTL </b>(1 week) are selected.</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>Step 15 </b><span class=font44>The <b>Authority ID Info </b>text is shown on some EAP-FAST client</span></span></div>
<div class=paragraph style=" padding:0.24pt 74.64pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">software; in this case, <b>cisco </b>is the text configured and displayed. This can be anything you want. On the other hand, the CSSC (used in this scenario) does not display this descriptive text for the PAC authority. However, the word <b>cisco </b>will be displayed if any other client (802.1x supplicant) is used.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 16 </b><span class=font44>Check the <b>Allow anonymous in-band PAC provisioning </b>checkbox.</span></span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44>This enables Automatic PAC Provisioning for EAP-FAST-enabled clients.</span></div>
<div class=paragraph style=" padding:6.72pt 74.16pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 17 </b><span class=font44>The CSSC supports EAP-FAST Version 1a, which uses MS-CHAPv2 for authentication. Scroll down and check <b>EAP-MSCHAPv2 </b>under the <b>Allowed inner methods </b>section, as shown in Figure 8-17.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 221.28pt; text-align:justify;"><span class=font4>Authentication and Authorization of Wireless Users <b>233</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 170.16pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-17 </b><span class=font43><i>EAP-MSCHAPv2 and EAP-FAST Master Server Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-100.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:86.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>Step 18 </b><span class=font44>Check the <b>EAP-FAST master server </b>check box to configure this</span></span></div>
<div class=paragraph style=" padding:0.00pt 75.84pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Cisco Secure ACS server as the master. The Actual EAP-FAST Master server status line will say <b>Master. </b>Any other Cisco Secure ACS servers (if present in your organization) will use this server as the master PAC authority to avoid the need to provision unique keys for each Cisco Secure ACS in a network.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 19 </b><span class=font44>Click <b>Submit + Restart.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:86.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Configuring the CSSC</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.64pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">This section shows how to configure the CSSC to authenticate to the wireless network using EAP-FAST. Complete the following steps to configure the CSSC.</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 1   </b><span class=font44>Launch the CSSC and click <b>Create Network.</b></span></span></div>
<div class=paragraph style=" padding:7.20pt 74.64pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 2  </b><span class=font44>The Network Profile screen shown in Figure 8-18 is displayed. Under <b>Network Configuration Summary </b>and <b>Authentication, </b>click <b>Modify.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:97.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>234   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.16pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-18 </b><span class=font43><i>CSSC Network Profile Screen</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:193.92pt; height:247.20pt; padding:0.00pt 146.16pt 0.00pt 145.92pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-101.jpg" alt="" style=" width:193.92pt; height:247.20pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:213.12pt;">
<div class=paragraph style=" padding:0.00pt 74.88pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 3  </b><span class=font44>The Network Authentication screen shown in Figure 8-19 is displayed. Turn on authentication by clicking the radio button labeled <b>Turn On </b>under the <b>Authentication Methods </b>section, as illustrated in Figure 8-19. In this example, the <b>Use Username as Identity </b>button is selected, because the user credentials are being used for authentication.</span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 4  </b><span class=font44>Under the <b>Protocol </b>list, check <b>FAST </b>and click the <b>Configure </b>button.</span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>Step 5  </b><span class=font44>The Configure EAP Method screen shown in Figure 8-20 is displayed.</span></span></div>
<div class=paragraph style=" padding:0.00pt 74.40pt 0.00pt 125.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Under the <b>Tunneled Method, </b>you can choose <b>Any Method </b>to allow the CSSC to use any EAP method offered by the wireless infrastructure. In this example, the <b>EAP-MSCHAPv2 </b>method is selected, because we are doing external authentication to a Windows Active Directory user database. If, however, you choose the <b>Any Method </b>option, it will work, but in some cases, you may want to be selective to force the use of only one EAP method. (In this case, the method is <b>EAP-MSCHAPv2.)</b></span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 6 </b><span class=font44>Leave all other default values as they are, and click <b>OK.</b></span></span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 7  </b><span class=font44>Click <b>OK </b>in the <b>Network Authentication </b>screen.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:172.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:64.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:249.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 221.28pt; text-align:justify;"><span class=font4>Authentication and Authorization of Wireless Users <span class=font44><b>235</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 261.60pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 8-19 </b><span class=font43><i>CSSC Network Authentication Screen</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:235.68pt; height:204.00pt; padding:0.00pt 125.04pt 0.00pt 125.28pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-102.jpg" alt="" style=" width:235.68pt; height:204.00pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 262.80pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 8-20 </b><span class=font43><i>CSSC Configure EAP Method Screen</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:172.08pt;">
<div class=block style=" width:172.08pt; height:6.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:64.80pt;">
<div class=block style=" width:64.80pt; height:6.00pt;">
<div class=paragraph style=" text-align:justify;"><span class=font1><b>Configure EAP Method..</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:249.12pt;">
<div class=block style=" width:249.12pt; height:6.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 168.24pt; text-align:left;"><span class=font0>-FAST settings:-</span></div>
<div class=paragraph style=" padding:4.32pt 260.64pt 0.00pt 172.56pt; text-align:justify;"><span class=font39><u>I  I</u> <span class=font0>Use Client Certificate</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.84pt;">
<div class=paragraph style=" padding:0.00pt 202.32pt 0.00pt 172.56pt; text-align:left; text-indent:17.28pt;"><span class=font0 style=" line-height:11.28pt;">Use Smartcard-based Client Certificates Only <u>fyl</u> Validate Server Certificate 0 Allow Fast Session Resumption</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.08pt;">
<div class=paragraph style=" padding:0.00pt 276.96pt 0.00pt 171.84pt; text-align:justify;"><span class=font0>Tunneled Method</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style="position:relative;  width:143.76pt; height:46.08pt; padding:0.00pt 170.16pt 0.00pt 172.08pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:143.76pt; height:46.08pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:87.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:87.36pt;">
<div class=block style=" width:87.36pt; height:8.16pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font0>EAP-MSCHAPv2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:8.16pt;">
<div class=paragraph style=" padding:0.00pt 2.40pt 0.00pt 0.00pt; text-align:right;"><span class=font0>■1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:143.76pt;">
<div class=block style=" width:143.76pt; height:8.64pt;">
<div class=paragraph style=" padding:0.48pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font0>Any Method |</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:143.76pt;">
<div class=block style=" width:143.76pt; height:5.28pt;">
<div class=paragraph style=" padding:0.48pt 2.88pt 0.00pt 0.00pt; text-align:right;"><span class=font0>EAP-MSCHAPv2 ;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:87.36pt;">
<div class=block style=" width:87.36pt; height:7.92pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:7.92pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:87.36pt;">
<div class=block style=" width:87.36pt; height:8.40pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font0>EAP-TLS</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:8.40pt;">
<div class=paragraph style=" padding:0.00pt 2.40pt 0.00pt 0.00pt; text-align:right;"><span class=font8><b>1</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:143.76pt;">
<div class=block style=" width:143.76pt; height:7.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:87.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<div class=block style=" width:1.92pt; height:26.40pt; position:absolute; left:312.00pt; top:12.48pt;">
<div class=paragraph style=" text-align:justify;"><span class=font49 style=" line-height:26.40pt;"><b>I</b></span></div>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.80pt;">
<div class=paragraph style=" padding:0.00pt 295.44pt 0.00pt 181.20pt; text-align:justify;"><span class=font0>Help</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:89.04pt;">
<div class=paragraph style=" padding:0.00pt 73.92pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 8 </b>Only wireless networks that have SSIDs enabled for broadcast are visible within the CSSC. In this example, the WLC is configured not to broadcast the SSID. Consequently, you must manually define the SSID in the CSSC. To define the SSID in CSSC, click the <b>Add </b>button under the <b>Access Devices </b>section of the <b>Network Profile </b>screen. The SSID used previously is <b>ciscotest.</b></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 9   </b>Click <b>Add Access.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:172.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:64.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:249.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>236    </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:207.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><a name="bookmark64"><b>S</b></a><b>tep 10 </b><span class=font44>Click </span><b>OK.</b></span></div>
<div class=paragraph style=" padding:6.96pt 80.16pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 11 </b><span class=font44>The CSSC attempts to connect to your wireless network. If it does not automatically make this attempt, click </span><b>Connect </b><span class=font44>from the CSSC main screen.</span></span></div>
<div class=paragraph style=" padding:6.00pt 109.68pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 12 </b><span class=font44>You are prompted for your user credentials, and if successfully authenticated, you are granted access to the network.</span></span></div>
<div class=paragraph style=" padding:23.52pt 0.00pt 0.00pt 37.20pt; text-align:left;"><span class=font11><a href="#bookmark60"><b>Lightweight Access Point Protocol (LWAPP)</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 36.96pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the Cisco Unified Wireless Architecture, a wireless LAN controller (WLC) is used to manage the wireless access point configuration and firmware creating an LWAPP tunnel. LWAP provides the control messaging protocol and data encapsulation. In other words, the wireless client data packets are encapsulated between the access point and the WLC. Figure 8-21 illustrates how a WLC controls a wireless access point over an LWAPP tunnel.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 8-21 </b><span class=font43><i>LWAPP Tunnel</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:346.56pt; height:205.92pt; padding:0.00pt 70.32pt 0.00pt 69.12pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-103.jpg" alt="" style=" width:346.56pt; height:205.92pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.04pt;">
<div class=paragraph style=" padding:0.00pt 197.28pt 0.00pt 90.00pt; text-align:justify;"><span class=font44>The following steps are illustrated in Figure 8-21:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:66.96pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font4><b>1&nbsp;</b><span class=font44>The wireless client sends a packet to the wireless access point.</span></span></div>
<div class=paragraph style=" padding:4.80pt 48.48pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>2&nbsp;</b><span class=font44>The wireless access point decrypts the packet and encapsulates it with an LWAPP header, forwarding it to the WLC.</span></span></div>
<div class=paragraph style=" padding:6.00pt 43.44pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>3&nbsp;</b><span class=font44>The WLC removes the LWAPP header and forwards the packet to its destination in the corporate wired network.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:64.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 249.36pt; text-align:justify;"><span class=font4>Lightweight Access Point Protocol (LWAPP) <b>237</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.80pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 89.52pt; text-align:left; text-indent:-53.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>When a client on the corporate wired network sends replies to the wireless client, the packet first goes into the WLC where it is encapsulated with an LWAPP header and forwarded to the appropriate wireless access point. Subsequently, the access point removes the LWAPP header and encrypts the packet if necessary.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The LWAPP control messages are encrypted using the AES-CCM encryption method. The shared encryption key is derived and exchanged when the access point joins the WLC.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.80pt;">
<div class=paragraph style=" padding:0.00pt 53.52pt 0.00pt 35.52pt; text-align:center;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The payload of the encapsulated LWAPP data is not encrypted. Therefore, you should follow infrastructure protection best practices to protect the wired network.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:317.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following are the major steps or stages used in the LWAPP:</span></div>
<div class=paragraph style=" padding:6.72pt 73.92pt 0.00pt 125.76pt; text-align:justify; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 1 </b><span class=font44><b>Discovery: </b>The wireless access point looks for a controller. The LWAPP Discovery Response from the controller contains the following important information from the WLC:</span></span></div>
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 133.20pt; text-align:left;"><span class=font44 style=" line-height:17.76pt;">—&nbsp;Controller name (sysName)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 133.20pt; text-align:left;"><span class=font44 style=" line-height:17.76pt;">—&nbsp;Controller type</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 133.20pt; text-align:left;"><span class=font44 style=" line-height:17.76pt;">—&nbsp;Controller capacity</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 133.20pt; text-align:left;"><span class=font44 style=" line-height:17.76pt;">—&nbsp;Current wireless access point load in the WLC</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 133.20pt; text-align:left;"><span class=font44 style=" line-height:17.76pt;">—&nbsp;Master controller status information used for redundancy</span></div>
<div class=paragraph style=" padding:3.12pt 75.36pt 0.00pt 148.08pt; text-align:left; text-indent:-14.88pt;"><span class=font44 style=" line-height:12.00pt;">—&nbsp;Access point manager IP address and the number of access points joined to the manager</span></div>
<div class=paragraph style=" padding:6.00pt 77.76pt 0.00pt 179.52pt; text-align:left; text-indent:-17.28pt;"><span class=font44 style=" line-height:12.00pt;">(a)&nbsp;When the AP is powered on, if a static IP address has not been previously configured, the AP issues a DHCP DISCOVER to get an IP address.</span></div>
<div class=paragraph style=" padding:5.76pt 81.84pt 0.00pt 179.52pt; text-align:left; text-indent:-17.28pt;"><span class=font44 style=" line-height:12.00pt;">(b)&nbsp;If Layer 2 mode is supported, the AP attempts a Layer 2 LWAPP Discovery by sending an Ethernet broadcast message.</span></div>
<div class=paragraph style=" padding:6.24pt 79.92pt 0.00pt 179.52pt; text-align:left; text-indent:-17.28pt;"><span class=font44 style=" line-height:11.76pt;">(c)&nbsp;If Layer 2 mode is not supported or the AP fails to find a WLC, the AP attempts a Layer 3 LWAPP Discovery.</span></div>
<div class=paragraph style=" padding:5.76pt 79.68pt 0.00pt 179.52pt; text-align:left; text-indent:-17.28pt;"><span class=font44 style=" line-height:12.24pt;">(d)&nbsp;If a Layer 3 LWAPP Discovery also fails, the AP reboots and retries the first step.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:65.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>238   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:291.60pt;">
<div class=paragraph style=" padding:0.00pt 110.40pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 2 </b><span class=font44><b>Join: </b>The wireless access point attempts to establish a secured relationship with a controller.</span></span></div>
<div class=paragraph style=" padding:5.76pt 75.36pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 3 </b><span class=font44><b>Image Data: </b>The wireless access point downloads code from the WLC when needed.</span></span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 4  </b><span class=font44><b>Config: </b>The wireless access point receives the configuration from the</span></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 125.76pt; text-align:left;"><span class=font44>WLC.</span></div>
<div class=paragraph style=" padding:7.20pt 74.16pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 5  </b><span class=font44><b>Run: </b>The wireless access point and the WLC are operating normally, and service data is exchanged.</span></span></div>
<div class=paragraph style=" padding:6.00pt 74.40pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 6  </b><span class=font44><b>Reset: </b>The wireless access point clears the current state, and this process starts over again.</span></span></div>
<div class=paragraph style=" padding:6.00pt 52.32pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The WLC provides support for radio resource management (RRM). The following are some of the advantages of RRM:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Continuous analysis of RF environment</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Dynamic channel and power management</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Coverage hole detection and correction</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Coverage resiliency</span></div>
<div class=paragraph style=" padding:1.92pt 39.12pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The WLCs elect a radio frequency (RF) group leader who analyzes RF data and neighbor relationships to make more optimized decisions about the RF environment for wireless infrastructure. Multiple RF domains can coexist within a single RF Group. These RF domains can be intercontroller or intracontroller, as illustrated in Figure 8-22.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 318.00pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-22 </b><span class=font43><i>Multiple RF Domains</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:326.40pt; height:167.76pt; padding:0.00pt 80.40pt 0.00pt 79.20pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-104.jpg" alt="" style=" width:326.40pt; height:167.76pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:92.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 228.96pt; text-align:justify;"><span class=font4>Wireless Intrusion Prevention System Integration <b>239</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:359.04pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a name="bookmark65">W</a>hy is this important to security? A good wireless network design that includes network resiliency is important for the overall security of your wireless network. The WLC has a built-in understanding of the signal strength that exists between lightweight access points within the same network. These controllers can use this information to create a dynamic optimal RF topology for the network. When a Cisco LWAPP-enabled access point boots up, it immediately looks for a wireless LAN controller within the network. After it finds a wireless LAN controller, the LWAPP-enabled access point sends out encrypted &quot;neighbor&quot; messages. These neighbor messages include the MAC address and signal strength of any neighboring access points. In a single wireless LAN controller network, the controller uses this neighbor information to determine the relative spatiality of the access points in the network. The controller then tunes each access point channel and optimal signal strength for optimal coverage and capacity.</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">When wireless LAN controllers are clustered in the network, a default controller is chosen. All the controllers feed the default controller information to their registered access points. The default controller correlates information for all the access points in the network and then pushes out the optimal channel and power for every access point on the network. The algorithms built into the Cisco Unified Wireless Network architecture prevent the interruption of wireless connectivity.</span></div>
<div class=paragraph style=" padding:23.52pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font11><a href="#bookmark60"><b>Wireless Intrusion Prevention System Integration</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can integrate Cisco IPS sensors with the Cisco Unified Wireless Solution. This includes the Cisco IPS sensors, the Cisco Adaptive Security Appliance (ASA), Advanced Inspection and Prevention Security Services Module (AIP-SSM), the Catalyst 6500 Intrusion Detection/Prevention Services Module Version 2 (IDSM-2), and the IPS modules for Cisco IOS routers. When you integrate IPS with the Cisco Unified Wireless Solution, the WLC talks to the Cisco IPS sensor via its management port using the Security Device Event Exchange (SDEE) protocol over TCP port 443. The WLC supports up to five IPS sensors.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph style=" padding:0.00pt 45.12pt 0.00pt 90.00pt; text-align:left; text-indent:-54.24pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The WLC also supports the use of a certain limited number of IPS signatures that you can enable to detect security threats within your wireless network. However, the combination of an external IPS device with the WLC provides more granular inspection and detection.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The WLC Software Release Version 4.x and later supports shunning (blocking) from the IPS sensors. A shun request needs to be sent to the WLC from the Cisco IPS device to trigger the client blacklisting or exclusion behavior available on the controller. The WLC queries the Cisco IPS device at a configured query rate to retrieve all the shun events. This is illustrated in Figure 8-23.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>240    </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 314.64pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-23 </b><span class=font43><i>IPS Sensor Integration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:322.08pt; height:186.24pt; padding:0.00pt 82.32pt 0.00pt 81.60pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-105.jpg" alt="" style=" width:322.08pt; height:186.24pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:2.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 317.04pt 0.00pt 118.56pt; text-align:justify;"><span class=font3>Infected Client</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:116.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following steps are illustrated in Figure 8-23:</span></div>
<div class=paragraph style=" padding:6.96pt 89.52pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 1   </b><span class=font44>An infected client sends malicious traffic over the wireless network (through access point 1 (AP1)).</span></span></div>
<div class=paragraph style=" padding:6.24pt 100.32pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 2  </b><span class=font44>The WLC sends the traffic to be inspected by the IPS device (IPS Sensor1).</span></span></div>
<div class=paragraph style=" padding:6.00pt 75.12pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 3  </b><span class=font44>The IPS device sends a shun request to the WLC to block the offending client.</span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 4  </b><span class=font44>The client is blocked (shunned).</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:80.88pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:justify; text-indent:-53.28pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE </b><span class=font44>The shunned client status is maintained on each controller in the mobility group even if any or all of the controllers are reset. On the controller, clients are disabled based on a MAC address, even though the shun request that the IPS initiates uses the client IP address as its destination. Therefore, although a client remains disabled for the duration of the controller exclusion time and is re-excluded if it reacquires its previous DHCP address, that client is no longer disabled if the IP address of the client that is shunned changes Here is an example. The client connects to the same network, and the DHCP lease timeout has not expired.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:122.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 228.96pt; text-align:justify;"><span class=font4>Wireless Intrusion Prevention System Integration <span class=font44><b>241</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:445.44pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Configuring IDS/IPS Sensors in the WLC</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">You can configure IDS/IPS using the WLC web management console or through the CLI. This section demonstrates how to use the web management console to add IDS/IPS sensors.</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 1   </b>Connect the Cisco IPS device to the same switch where the WLC resides.</span></div>
<div class=paragraph style=" padding:6.96pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:11.76pt;"><b>Step 2  </b>Mirror the WLC ports that carry the wireless client traffic to the Cisco IPS device. You do this because the Cisco IPS device must receive a copy of every packet to be inspected on the wireless network. The Cisco IPS device provides a downloadable signature file that you can customize. When a signature is triggered, the Cisco IPS device generates the alarm with a shunning event action. The WLC polls the Cisco IPS device for alarms. When an alarm is detected with the IP address of a wireless client, which is associated to the WLC, the IPS device puts the client into the exclusion list. The WLC generates a trap and notifies the WCS. The WLC removes the user from the exclusion list after the specified period (60 seconds by default).</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 3 </b>Log in to the WLC as an administrator.</span></div>
<div class=paragraph style=" padding:6.48pt 80.40pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 4 </b>To add the Cisco IPS device to the WLC, navigate to the <b>Security </b>tab. Under <b>CIDS, </b>click <b>Sensors.</b></span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44><b>Step 5 </b>Click <b>New.</b></span></div>
<div class=paragraph style=" padding:6.72pt 74.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font44 style=" line-height:12.00pt;"><b>Step 6  </b>The screen shown in Figure 8-24 is displayed. Enter the sensor IP address. The IP address of the IPS device in this example is <b>172.18.85.149. </b>The WLC uses SDEE, and the default port is <b>443. </b>Enter the username and password of the Cisco IPS device.</span></div>
<div class=paragraph style=" padding:6.24pt 79.20pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In this example, the query interval is configured for 15 seconds. This query interval is safe to use in most environments. Enter the Cisco IPS device SHA1 fingerprint. You can obtain this by invoking the <b>show tls fingerprint </b>command on the Cisco IPS device, as follows:</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 138.48pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">Example <span style=" letter-spacing:4.00pt;">81</span> IPS-sensor# show tls fingerprint</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 138.24pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">MD5: B8:A7:74:B5:62:AB:C8:15:5C:FE:E6:4C:0C:42:39:CE</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 138.00pt; text-align:left;"><span class=font23 style=" line-height:9.36pt;">SHA1: AC:6A:FA:FC:BE:05:D1:09:31:53:21:DC:36:A0:1A:B6:6A:DA:00:AF</span></div>
<div class=paragraph style=" padding:6.24pt 77.28pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The highlighted line shows the fingerprint that is entered into the WLC configuration. You must omit the colons (:) within the hexadecimal fingerprint. The fingerprint must be 40 characters in length.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:131.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 306.96pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>242   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 325.20pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-24 </b><span class=font43><i>Adding IPS Sensors</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-106.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:73.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 1   </b><span class=font44>Click <b>Apply.</b></span></span></div>
<div class=paragraph style=" padding:6.96pt 73.92pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 1   </b><span class=font44>Navigate to <b>WLANs </b>and click <b>Edit </b>on the configured WLANs that you want to monitor. Make sure that <b>Client Exclusion </b>is enabled. The default client exclusion timeout is 60 seconds. On the other hand, the client exclusion persists as long as the IPS shun (block) remains active. The default block time in the Cisco IPS devices is 30 minutes.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:116.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Uploading and Configuring IDS/IPS Signatures</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Several signatures come with the WLC by default. You can view the standard signatures by navigating to <b>Security &gt; Wireless Protection Policies </b>and then clicking <b>Standard Signatures. </b>This is illustrated in Figure 8-25.</span></div>
<div class=paragraph style=" padding:6.24pt 39.12pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can also upload a signature file from the WLC to customize the signatures. To do this, navigate to <b>Commands &gt; Upload File &gt; Signature File. </b>To download the modified signature file, navigate to <b>Commands &gt; Download File &gt; Signature File. </b>After you download (or push) the edited signature file to the WLC, all registered wireless access points are refreshed in real time with the new signature configuration.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 272.40pt; text-align:justify;"><span class=font4>Management Frame Protection (MFP) <b>243</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 302.64pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><a name="bookmark66"><b>F</b></a><b>igure 8-25 </b><span class=font43><i>WLC Standard Signatures</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-107.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:40.32pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44>When customizing signatures, you must use the following format:</span></div>
<div class=paragraph style=" padding:7.20pt 55.44pt 0.00pt 97.68pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">Name = &lt;str&gt;, Ver = &lt;int&gt;, Preced = &lt;int&gt;, FrmType = &lt;frmType-type&gt;, Pattern = &lt;pattern-format&gt;,</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.92pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">Freq = &lt;int&gt;, Interval = &lt;int&gt;, Quiet = &lt;int&gt;, Action = &lt;action-val&gt;, Desc = &lt;str&gt;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>The maximum length of each line is 1000 characters. The WLC will not correctly parse any lines longer than 1000 characters.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:139.68pt;">
<div class=paragraph style=" padding:0.00pt 54.48pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can view the custom signatures by navigating to <b>Security &gt; Wireless Protection Policies </b>and then clicking <b>Custom Signatures.</b></span></div>
<div class=paragraph style=" padding:17.52pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark60"><b>Management Frame Protection (MFP)</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 36.48pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Management Frame Protection (MFP) enables authentication of all 802.11 management frames between the WLC and wireless access points. MFP protects against direct and man-in-the-middle attacks. It also detects and reports potential phishing attacks. MFP has three main functions:</span></div>
<div class=paragraph style=" padding:5.76pt 38.64pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.24pt;"><b>•  Frame protection: </b>This enables the wireless access point to protect the management frames by adding a message integrity check information element (MIC-IE) to each frame.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 306.96pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>244   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:155.04pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><a name="bookmark67"><b>•</b></a><b>&nbsp;Frame validation: </b>The wireless access point validates every management frame that it receives from other access points in the network.</span></div>
<div class=paragraph style=" padding:4.32pt 53.76pt 0.00pt 111.36pt; text-align:justify; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Event reporting: </b>The wireless access point notifies the WLC when it detects an anomaly. The WLC can also report these events via SNMP traps to management servers.</span></div>
<div class=paragraph style=" padding:3.84pt 54.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can enable MFP globally. However, you can disable it on individual WLANs and access points. In other words, you can selectively enable or disable MFP on specific wireless access points or WLANs.</span></div>
<div class=paragraph style=" padding:5.76pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">To enable MFP globally, navigate to <b>Security &gt; Wireless Protection Policies. </b>Then click <b>AP Authentication/MFP </b>and choose <b>Management Frame Protection </b>from the <b>Protection Type </b>pull-down menu. You can view the MFP statistics under <b>Security &gt; Wireless Protection Policies &gt; Management Frame Protection.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:165.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 37.20pt; text-align:left;"><span class=font11><a href="#bookmark60"><b>Precise Location Tracking</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Cisco Wireless Location Appliance uses RF fingerprinting technology to track mobile devices to within a few meters. This allows you to gain visibility into the location of people and assets. In addition, RF fingerprinting technology enables you to respond to security issues and thereby gain insight into the location and movement of people and assets, as well as locating rogue wireless access points.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The Cisco Wireless Location Appliance supports two location tracking options:</span></div>
<div class=paragraph style=" padding:6.48pt 61.92pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;On-demand location tracking: </b>The user queries the location of the person or wireless device.</span></div>
<div class=paragraph style=" padding:3.60pt 58.56pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Simultaneous location tracking: </b>This automatically tracks up to thousands of 802.11 wireless devices by adding a Cisco Wireless Location Appliance in conjunction with a Cisco WCS.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>TIP&nbsp;</b><span class=font44>It is recommended that you become familiar with the different methodologies used for</span></span></div>
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">location tracking and that you deploy these solutions within your network. Conventionally, many have used three different methods for locating wireless users or devices: closest access point, triangulation, and RF fingerprinting. As previously mentioned, the Cisco Wireless Location Appliance uses RF fingerprinting. A whitepaper explaining each methodology is located at <a href="http://www.cisco.com/en/US/products/ps6386/products_white_paper0900aecd80477957.shtml">http://www.cisco.com/en/US/products/ps6386/ products_white_paper0900aecd80477957.shtml.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:108.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.32pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 200.88pt; text-align:justify;"><span class=font4>Network Admission Control (NAC) in Wireless Networks <b>245</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:295.92pt;">
<div class=paragraph style=" padding:0.00pt 104.40pt 0.00pt 35.76pt; text-align:left;"><span class=font11 style=" line-height:17.76pt;"><a href="#bookmark60"><a name="bookmark68"><b>N</b></a><b>etwork Admission Control (NAC) in Wireless </b></a><b>Networks</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Network Admission Control (NAC) was initially designed as two separate solutions: the NAC Framework and NAC Appliance (formerly known as Cisco Clean Access). The most commonly deployed NAC solution for wireless networks is the NAC Appliance. This section covers how to integrate the Cisco NAC Appliance into the Cisco Unified Wireless solution.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>As mentioned in previous chapters, the NAC Appliance has three major components:</span></div>
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Clean Access Server (CAS)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Clean Access Manager (CAM)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Clean Access Agent</span></div>
<div class=paragraph style=" padding:1.92pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In the example illustrated in Figure 8-26, the CAS is configured inline and managed by the CAM (172.18.85.181). All wireless traffic will pass through the server before it can reach the corporate network or the Internet. The goal in this example is to separate guest users from employees. The guest users will have only limited access to the Internet via HTTP and HTTPs. The employees will have access to the corporate resources.</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>Two SSIDs are configured in the Figure 8-26 example:</span></div>
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;<b>GUESTNET: </b>Used by guests</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;<b>CORPACCESS: </b>Used by employees</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">The WLC is configured to broadcast the GUESTNET SSID, but not the CORPACCESS.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 36.00pt; text-align:justify;"><span class=font4 style=" line-height:11.76pt;"><b>TIP&nbsp;</b><span class=font44>As a best practice, it is recommended that you use different SSIDs for your employees and</span></span></div>
<div class=paragraph style=" padding:0.00pt 66.72pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">guest wireless users. For your employees (internal users), you can also use 802.1X authentication and strong encryption (WPA with TKIP/MIC or WPA2 with AES).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 59.76pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The following sections provide the step-by-step procedures for configuring the NAC Appliance (CAM and CAS), the WLC, and the NAC Agent configuration.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:162.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font44><b>246    </b><span class=font4>Chapter 8: Wireless Security</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:413.28pt; height:363.84pt; padding:0.00pt 36.72pt 0.00pt 36.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-108.jpg" alt="" style=" width:413.28pt; height:363.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:37.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:116.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>NAC Appliance Configuration</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">It is recommended that you configure the CAS in the Real-IP gateway mode for wireless network deployments. When the CAS is configured in the Real-IP gateway mode, it handles all routing between the unprotected and protected networks. In this example, the untrusted (unprotected) interface resides in the 10.10.10.0/24 subnet, and the trusted (protected) interface resides in the 192.168.40.0/24 subnet.</span></div>
<div class=paragraph style=" padding:6.00pt 39.36pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Complete the following steps to configure the NAC Appliance solution to protect the corporate resources by performing security posture checks for wireless users. In addition, enforce policy for guest users so that they are only able to access the Internet while</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:58.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 201.60pt; text-align:justify;"><span class=font4>Network Admission Control (NAC) in Wireless Networks <b>247</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:145.20pt;">
<div class=paragraph style=" padding:0.00pt 41.04pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">employees can access corporate resources. Noncompliant clients will be quarantined and remediated.</span></div>
<div class=paragraph style=" padding:6.24pt 74.64pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 1   </b><span class=font44>The CAS is always configured via the CAM. Log in to the CAM with an administrator account.</span></span></div>
<div class=paragraph style=" padding:6.00pt 74.16pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 2  </b><span class=font44>After you are logged in to the CAM, navigate to the <b>Device Management </b>section in the menu on the left, and click <b>CCA Servers.</b></span></span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>Step 3  </b><span class=font44>To add a new CAS, click the <b>New Server </b>tab and enter the CAS</span></span></div>
<div class=paragraph style=" padding:0.00pt 74.64pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">information, as illustrated in Figure 8-27. In this example, the CAM will access the CAS via the trusted interface (IP address <b>192.168.40.2).</b></span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 8-27 </b><span class=font43><i>Adding a New CAS in the CAM</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:243.84pt;">
<div class=paragraph style=" padding:35.28pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:243.84pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-109.jpg" alt="" style=" width:336.96pt; height:243.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:113.28pt;">
<div class=paragraph style=" padding:0.00pt 76.80pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 4 </b><span class=font44>Enter a server location description. The description can be any word or phrase that describes the location of the CAS. In this example, the location description is <b>Wireless Network.</b></span></span></div>
<div class=paragraph style=" padding:6.24pt 86.64pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 5  </b><span class=font44>The goal in this example is to configure the CAS in Real-IP gateway mode. Choose <b>Real-IP Gateway </b>from the drop-down menu.</span></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 6   </b><span class=font44>Click <b>Add Clean Access Server.</b></span></span></div>
<div class=paragraph style=" padding:6.48pt 75.12pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 7  </b><span class=font44>To access the CAS, click the <b>Manage </b>icon under <b>Device Management &gt; CCA Servers, </b>as illustrated in Figure 8-28.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:54.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>248   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 280.80pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-28 </b><span class=font43><i>Accessing the CAS via the CAM</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:244.32pt;">
<div class=paragraph style=" padding:35.76pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-110.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:257.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 8 </b><span class=font44>Verify the IP addressing information, and verify that the CAS is</span></span></div>
<div class=paragraph style=" padding:0.72pt 77.52pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">configured with the <b>Real-IP Gateway </b>option by clicking the <b>Network </b>tab, as shown in Figure 8-29.</span></div>
<div class=paragraph style=" padding:6.24pt 74.64pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 9 </b><span class=font44>In this example, the trusted interface IP address is <b>192.168.40.2, </b>and the default gateway is the Cisco ASA <b>(192.168.40.1). </b>Enter this information under the Trusted Interface section, as illustrated in Figure 8-29.</span></span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>Step 10 </b><span class=font44>Enter the IP address information for the untrusted interface. In this</span></span></div>
<div class=paragraph style=" padding:0.00pt 74.40pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">example, the untrusted interface IP address is <b>10.10.10.2, </b>and the default gateway is <b>10.10.10.1. </b>Both the trusted and untrusted interfaces are configured with a 24-bit subnet mask <b>(255.255.255.0).</b></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>Step 11 </b><span class=font44>Enter your DNS information under the <b>DNS </b>section, as illustrated in</span></span></div>
<div class=paragraph style=" padding:0.24pt 74.88pt 0.00pt 125.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Figure 8-30. In this example, the CAS name is <b>cas1, </b>the domain name is <a href="http://cisco.com"><b>cisco.com</b></a><b>, </b>and the IP address of the DNS server is <b>172.18.108.40.</b></span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 12 </b><span class=font44>In this example, you will create two users: guest and employee1. To</span></span></div>
<div class=paragraph style=" padding:0.48pt 74.64pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">create the local database, navigate to <b>User Management &gt; Local Users </b>and enter the user information, as illustrated in Figure 8-31.</span></div>
<div class=paragraph style=" padding:6.00pt 78.96pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 13 </b><span class=font44>The next step is to create the user roles. To enter a new user role, go to <b>User Management &gt; User Roles &gt; New Role </b>and enter the user role information, as illustrated in Figure 8-32.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 201.60pt; text-align:justify;"><span class=font4>Network Admission Control (NAC) in Wireless Networks <b>249</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 281.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-29 </b><span class=font43><i>Real-IP Gateway Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:244.08pt;">
<div class=paragraph style=" padding:35.76pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:244.08pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-111.jpg" alt="" style=" width:336.96pt; height:244.08pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:259.68pt;">
<div class=paragraph style=" padding:51.36pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:259.68pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-112.jpg" alt="" style=" width:374.88pt; height:259.68pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>250   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 324.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-31 </b><span class=font43><i>Adding Local Users</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:244.32pt;">
<div class=paragraph style=" padding:35.76pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-113.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 356.88pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-32 </b><span class=font43><i>User Roles</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:244.80pt;">
<div class=paragraph style=" padding:35.76pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:244.80pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-114.jpg" alt="" style=" width:336.96pt; height:244.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:40.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.68pt 0.00pt 201.60pt; text-align:justify;"><span class=font4>Network Admission Control (NAC) in Wireless Networks <b>251</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:111.12pt;">
<div class=paragraph style=" padding:0.00pt 79.68pt 0.00pt 125.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">In Figure 8-32, the guest user role is configured. The user role name is <b>Guest Role, </b>and the role description is <b>Wireless Guest Role. </b>For guest users, at the <b>After Successful Login Redirect to </b>field, click to choose this URL, and enter the URL to which you want the guest user redirected. In this case, guest users will be redirected to a site called <a href="http://guestaccess.cisco.com"><i>guestaccess.cisco.com</i></a><i> </i>with further instructions and disclaimers. All other options are left with default values.</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 14 </b><span class=font44>You can configure traffic policies to be applied to each user role by</span></span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44>clicking the <b>Policies </b>icon by the specific role, as illustrated in Figure 8-33.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 329.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-33 </b><span class=font43><i>User Role Policies</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:244.08pt;">
<div class=paragraph style=" padding:35.28pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:244.08pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-115.jpg" alt="" style=" width:336.96pt; height:244.08pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:116.88pt;">
<div class=paragraph style=" padding:0.00pt 89.76pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 15 </b><span class=font44>By default, all traffic is denied. To enter a new policy, click the <b>Add Policy </b>link, as illustrated in Figure 8-34.</span></span></div>
<div class=paragraph style=" padding:7.20pt 74.40pt 0.00pt 90.24pt; text-align:justify;"><span class=font4><b>Step 16 </b><span class=font44>Enter the policy information. In this example, all guest users are allowed</span></span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 126.00pt; text-align:left;"><span class=font44>to access the Internet via HTTP (TCP port 80) and HTTPs (TCP port</span></div>
<div class=paragraph style=" padding:0.72pt 79.20pt 0.00pt 125.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">443). DNS traffic (UDP port 53) also needs to be allowed. Figure 8-35 shows how to configure a new policy to allow HTTP traffic.</span></div>
<div class=paragraph style=" padding:6.00pt 75.60pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 17 </b><span class=font44>All internal traffic is denied. In this case, all internal networks can be summarized into two major subnets: 192.168.0.0/16 and 172.18.0.0/16. Figure 8-36 shows how all the guest user policies are configured.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:61.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>252   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 321.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-34 </b><span class=font43><i>Adding a New Policy</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:244.80pt;">
<div class=paragraph style=" padding:35.76pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:244.80pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-116.jpg" alt="" style=" width:336.96pt; height:244.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 280.56pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-35 </b><span class=font43><i>Allowing HTTP for Guest Users</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:244.32pt;">
<div class=paragraph style=" padding:35.52pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-117.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:40.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 201.60pt; text-align:justify;"><span class=font4>Network Admission Control (NAC) in Wireless Networks <b>253</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:260.16pt;">
<div class=paragraph style=" padding:51.36pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:260.16pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-118.jpg" alt="" style=" width:374.88pt; height:260.16pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:237.12pt;">
<div class=paragraph style=" padding:0.00pt 72.72pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Notice how traffic to HTTP and HTTPS to all destinations is allowed by the first few policy entries. This is done because you cannot map the whole Internet for guest users. However, specific deny statements for all UDP and TCP traffic to internal networks are denied. In addition, a catch-all deny statement is included at the end.</span></div>
<div class=paragraph style=" padding:6.00pt 74.88pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">You can assign users to different roles by editing the previously created users.</span></div>
<div class=paragraph style=" padding:6.24pt 74.64pt 0.00pt 125.76pt; text-align:justify; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 18 </b><span class=font44>Configure a host-based policy for access to remediation sites when users are quarantined. Navigate to <b>User Management &gt; User Roles &gt; Traffic Control &gt; Host </b>and choose <b>Agent Quarantine Role </b>in the drop-down menu, as illustrated in Figure 8-37. Then select the sites you want your quarantined clients to be able to access for remediation.</span></span></div>
<div class=paragraph style=" padding:6.00pt 74.16pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">In Figure 8-37, access is allowed to <i>update.microsoft.com </i>(the Microsoft update site) and to an internal remediation server.</span></div>
<div class=paragraph style=" padding:6.00pt 74.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 19 </b><span class=font44>You can create or customize a login page for the wireless users by going to <b>Administration &gt; User Pages </b>and choosing <b>Add </b>at the <b>Login Page </b>tab. You can edit the web login portal page content by going to <b>Administration &gt; User Pages &gt; Login Page &gt; Edit &gt; Content.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:63.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>254   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:260.16pt;">
<div class=paragraph style=" padding:51.36pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:260.16pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-119.jpg" alt="" style=" width:374.88pt; height:260.16pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:216.96pt;">
<div class=paragraph style=" padding:0.00pt 89.52pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 20 </b><span class=font44>To enable basic network scanning for guest user workstations, go to <b>Network Scanner &gt; Scan Setup </b>to determine which user role and operating system to use. This is illustrated in Figure 8-38.</span></span></div>
<div class=paragraph style=" padding:5.76pt 85.92pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 21 </b><span class=font44>Select the operating system options under the <b>Plugins, Options, </b>and <b>Vulnerability </b>tabs.</span></span></div>
<div class=paragraph style=" padding:6.24pt 85.68pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 22 </b><span class=font44>You can also configure a user agreement page for web login users by navigating to the <b>User Agreement </b>tab.</span></span></div>
<div class=paragraph style=" padding:6.00pt 74.88pt 0.00pt 125.76pt; text-align:justify; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 23 </b><span class=font44>To establish employee roles for posture assessment, you must create a requirement rules mapping by going to <b>Device Management &gt; Clean Access &gt; Clean Access Agent &gt; Requirements &gt; Requirement-Rules.</b></span></span></div>
<div class=paragraph style=" padding:0.24pt 74.40pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">For instance, a user can choose to perform Windows HotFixes checks for Windows-based systems.</span></div>
<div class=paragraph style=" padding:6.00pt 86.88pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 24 </b><span class=font44>For employees, you should require the use of the NAC Agent (Clean Access Agent) by clicking <b>Require use of Clean Access Agent.</b></span></span></div>
<div class=paragraph style=" padding:5.76pt 54.24pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">After users are successfully logged in, you will see them under <b>Monitoring &gt; Online Users.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 201.60pt; text-align:justify;"><span class=font4>Network Admission Control (NAC) in Wireless Networks <b>255</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 345.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-38 </b><span class=font43><i>Scanner Setup</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt;">
<div class=block style=" width:114.24pt; height:244.56pt;">
<div class=paragraph style=" padding:35.76pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font45>73</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:371.76pt;">
<div class=block style=" width:297.12pt; height:244.56pt; padding:0.00pt 74.64pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-120.jpg" alt="" style=" width:336.96pt; height:244.56pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:194.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font8><b>WLC Configuration</b></span></div>
<div class=paragraph style=" padding:3.12pt 48.96pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">This section includes the steps necessary to configure the WLC for the NAC Appliance solution to work. Complete the following steps to configure the WLC.</span></div>
<div class=paragraph style=" padding:6.00pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 1   </b><span class=font44>As a best practice, it is recommended that you configure separate VLANs for guest and internal users. To do this, you need to configure two new pseudointerfaces. Log in to the WLC, navigate to <b>Controller &gt; Interfaces, </b>and click <b>New </b>to add a new interface. Enter the name for the new interface and the VLAN you want to assign. This is illustrated in Figure 8-39. In this example, the interface for guest users is called <b>guest </b>and assigned to VLAN Id <b>123.</b></span></span></div>
<div class=paragraph style=" padding:5.76pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 2  </b><span class=font44>The next screen (shown in Figure 8-40) allows you to enter the interface configuration parameters, such as IP address, subnet mask, default gateway, DHCP server information, and others. In this case, the guest interface is configured with the IP address <b>10.20.1.2 </b>with a 24-bit subnet mask. The default gateway and DHCP server is <b>10.20.1.1.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:91.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:114.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:371.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>256   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 209.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-39 </b><span class=font43><i>Adding a New Dynamic Guest Interface in the WLC</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.56pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-121.jpg" alt="" style=" width:336.96pt; height:244.56pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 267.60pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-40 </b><span class=font43><i>WLC Guest Interface Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.72pt; height:244.08pt; padding:0.00pt 74.88pt 0.00pt 74.40pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:336.72pt; height:244.08pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:33.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:65.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:167.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:44.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:125.04pt;">
<div class=block style=" width:125.04pt; height:7.92pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font0><b>Cisco - Windows Internet Explorer</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:7.92pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 21.60pt; text-align:left;"><span class=font24 style=" letter-spacing:-0.50pt;">BHD</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="3" valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:12.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:2.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:2.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:2.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:2.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:98.40pt;">
<div class=block style=" width:98.40pt; height:6.48pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font0>https: <span style=" letter-spacing:1.00pt;"><i>lj </i></span>172.1S. 85.9 <span style=" letter-spacing:1.00pt;"><i>Ц </i></span>screens/frameset .html</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:6.48pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 72.00pt; text-align:left;"><span class=font0><b>v </b><span style=" letter-spacing:1.00pt;"><i>\Щ </i></span>Certificate <b>Error </b><span class=font38><b>||+*||x| </b></span>| Google</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:6.48pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 30.72pt; text-align:left;"><span class=font2>l-°H</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:3.12pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:3.12pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:3.12pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:3.12pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="2" valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font24 style=" letter-spacing:-0.50pt;">u<span style=" letter-spacing:-1.00pt;"> </span>*<span style=" letter-spacing:-1.00pt;"> </span><span class=font43 style=" letter-spacing:0.00pt;"><i>\t</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:3.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:3.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 59.04pt; text-align:left;"><span class=font38>I</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:3.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38>J <span class=font0><b>la* - </b></span><span class=font24 style=" letter-spacing:-0.50pt;">e-</span><span class=font24 style=" letter-spacing:-1.00pt;"> </span><span class=font24 style=" letter-spacing:-0.50pt;">a</span><span class=font24 style=" letter-spacing:-1.00pt;"> </span><span class=font24 style=" letter-spacing:-0.50pt;">»</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:6.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:6.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:6.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:17.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font18 style=" line-height:18.96pt; font-variant: small-caps;"><b>и</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:17.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:232.56pt;">
<div class=block style=" width:232.56pt; height:17.28pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 184.08pt; text-align:left;"><span class=font0>Save Configuration <b>Pin</b></span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font0><b>MONITOR     WLANs     CONTROLLER     WIRELESS     SECURITY     MANAGEMENT     COMMANDS HELP</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:17.28pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font0>g     <b>Logout Refresh</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:5.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:5.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:5.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:5.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:5.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:60.00pt;">
<div class=block style=" width:60.00pt; height:5.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font0><b>Controller</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:5.52pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font0><b>Interfaces &gt; </b><span class=font38><b>Edit</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:5.52pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 147.84pt; text-align:left;"><span class=font0><b>&lt; Back</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:5.52pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 14.88pt; text-align:left;"><span class=font0><b>Apply</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:18.48pt;">
<div class=paragraph style=" padding:3.84pt 0.96pt 0.00pt 4.80pt; text-align:left;"><span class=font0 style=" line-height:7.92pt;"><b>General Inventory</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:18.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:18.48pt;">
<div class=paragraph style=" padding:11.52pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font0><b>General Information</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:18.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:18.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:8.64pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font0><b>Interfaces</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:8.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:8.64pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 5.52pt; text-align:left;"><span class=font0><b>Interface Name </b>gu</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:8.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:8.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:60.00pt;">
<div class=block style=" width:60.00pt; height:7.68pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font0><b>Network Routes</b></span></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:13.20pt;">
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font0><b>Interface Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:7.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:7.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:60.00pt;">
<div class=block style=" width:60.00pt; height:5.52pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font0><b>Internal DHCP Server</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:5.52pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:5.52pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:60.00pt;">
<div class=block style=" width:60.00pt; height:18.72pt;">
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font0 style=" line-height:4.80pt;"><b>Mobility Management</b></span></div>
<div class=paragraph style=" padding:0.00pt 19.44pt 0.00pt 8.64pt; text-align:left;"><span class=font0 style=" line-height:4.80pt;">Mobil<b>ity </b>Groups Mobility Statistics.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:18.72pt;">
<div class=paragraph style=" padding:1.20pt 28.32pt 0.00pt 8.64pt; text-align:left;"><span class=font0 style=" line-height:8.16pt;">VLAN Identifier IP Address</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:18.72pt;">
<div class=paragraph style=" padding:11.28pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font0>10.20.1.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:18.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:60.00pt;">
<div class=block style=" width:60.00pt; height:8.16pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font0><b>Spanning Tree</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:8.16pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 8.88pt; text-align:left;"><span class=font0>Netmask</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:8.16pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font0>255.255.255.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:8.16pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:7.44pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font0><b>Ports</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:7.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:7.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:7.44pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font0>10.20.1.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:7.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:60.00pt;">
<div class=block style=" width:60.00pt; height:12.24pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font0><b>Master Controller Mode</b></span></div>
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font0><b>Mef</b><span class=font38><b>-turirL </b></span><b>Time Pmtnrnl</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:12.24pt;">
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font0><b>Physical Information</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:47.04pt;">
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font0><b>QoS Profi</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:47.04pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:47.04pt;">
<div class=paragraph style=" padding:2.16pt 20.40pt 0.00pt 8.88pt; text-align:left;"><span class=font0 style=" line-height:6.72pt;"><sup>3</sup>ort Number Заскир Port ictivs -o 1 Enable Dynamic AF Management</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font0><b>Configuration</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:47.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.56pt; text-align:left;"><span class=font24 style=" letter-spacing:-0.50pt;">О</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font38><b>■</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:47.04pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:11.52pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:11.52pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:11.52pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:11.52pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font43><b>□</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:11.52pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:11.52pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:11.52pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:11.52pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font0><b>DHCP Information</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:11.52pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:11.52pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:8.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:8.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:8.64pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 9.12pt; text-align:left;"><span class=font0><b>Primary </b>DHCP Server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:8.64pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font0>10.20.1.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:8.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:11.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:11.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:11.76pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 8.88pt; text-align:left;"><span class=font0>Secondary DHCP Server</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:11.76pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 41.04pt; text-align:left;"><span class=font3>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:11.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:8.40pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:8.40pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:65.04pt;">
<div class=block style=" width:65.04pt; height:8.40pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:167.52pt;">
<div class=block style=" width:167.52pt; height:8.40pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 129.84pt; text-align:left;"><span class=font0>$ Internet</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:44.16pt;">
<div class=block style=" width:44.16pt; height:8.40pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font0>+„100% '</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:33.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:65.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:167.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:44.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 201.60pt; text-align:justify;"><span class=font4>Network Admission Control (NAC) in Wireless Networks <b>257</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 149.04pt 0.00pt 90.24pt; text-align:justify;"><span class=font4><b>Step 3  </b><span class=font44>Add another interface for employees (internal users).</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.52pt;">
<div class=paragraph style=" padding:0.00pt 73.20pt 0.00pt 126.48pt; text-align:left; text-indent:-36.24pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 4  </b><span class=font44>Under <b>Controller &gt; General, </b>make sure that <b>Layer 3 </b>is selected in the LWAPP Transport Mode drop-down menu, as illustrated in Figure 8-41.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 347.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-41 </b><span class=font43><i>LWAP Setting</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:243.84pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-122.jpg" alt="" style=" width:336.96pt; height:243.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:206.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 5  </b><span class=font44>In the Default Mobility Domain Name field, enter <b>RFGroup1.</b></span></span></div>
<div class=paragraph style=" padding:6.96pt 75.12pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 6  </b><span class=font44>Create a guest wireless LAN interface named guest and assign an SSID. (In this example, we also name it <b>guest.)</b></span></span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>Step 7  </b><span class=font44>Configure the WLAN with open authentication and DHCP address</span></span></div>
<div class=paragraph style=" padding:0.00pt 74.40pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">assignment required. Enter <b>guest </b>as the wireless LAN interface <b>SSID </b>under the <b>WLANs &gt; Edit </b>window. Click the check box to require <b>DHCP Addr. Assignment, </b>as illustrated in Figure 8-42.</span></div>
<div class=paragraph style=" padding:7.20pt 75.12pt 0.00pt 90.24pt; text-align:justify;"><span class=font4><b>Step 8  </b><span class=font44>Repeat Steps 6 and 7 to create and configure a WLAN for internal users.</span></span></div>
<div class=paragraph style=" padding:6.72pt 72.96pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 9  </b><span class=font44>To add the RADIUS server information for 802.1X authentication, navigate to <b>Security &gt; AAA&gt; RADIUS Authentication. </b>In this case, you use the same server that you configured previously in this chapter (172.18.85.181).</span></span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>Step 10 </b><span class=font44>The CAS uses RADIUS accounting packets to trigger the security</span></span></div>
<div class=paragraph style=" padding:0.24pt 74.16pt 0.00pt 125.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">posture of wireless users. Configure the CAS as the RADIUS Accounting server by going to <b>Security &gt; AAA&gt; RADIUS Accounting &gt; New. </b>Add the CAS information, as illustrated in Figure 8-43.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 307.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>258   </b>Chapter 8: Wireless Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 297.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-42 </b><span class=font43><i>Guest WLAN Configuration</i></span></span></div>
<div class=paragraph style=" padding:17.28pt 257.04pt 0.00pt 0.00pt; text-align:center;"><span class=font0><b>&quot; [tfl**s</b><span style=" font-variant: small-caps;"><b>:»172.1s.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-123.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 219.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 8-43 </b><span class=font43><i>Adding the CAS as a RADIUS Accounting Server</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-124.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 384.24pt; text-align:justify;"><span class=font4>Summary <b>259</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:215.04pt;">
<div class=paragraph style=" padding:0.00pt 48.00pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">After you complete these steps, you will be able to authenticate using a wireless client. Guest users will be redirected to a web-based login, and regular employees will use the Cisco Clean Access Agent to connect to the network.</span></div>
<div class=paragraph style=" padding:23.52pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark60"><a name="bookmark69"><b>S</b></a><b>ummary</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Wireless access is a core part of the infrastructure in most organizations. When developing a wireless implementation, take into consideration the unique security challenges that wireless connectivity brings. Implementing best practice wireless security techniques is a must for any organization. This chapter included best practices when deploying wireless networks. It also covered different types of authentication mechanisms, including 802.1x. In addition, it included an overview of LWAP, location services, MFP, and other wireless features that need to be taken into consideration when designing security within your wireless infrastructure.</span></div>
<div class=paragraph style=" padding:6.24pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This chapter also covered step-by-step configuration examples of the integration of IPS on Cisco wireless networks. In addition, it provided guidance on how to integrate the Cisco NAC Appliance and the Cisco Unified Wireless Network solution.</span></div>
</div>
</td>
]]></content:encoded>
			<wfw:commentRss>http://ciscoasa.org.ua/2010/03/chapter-8-wireless-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter 7: Proactive Security Framework</title>
		<link>http://ciscoasa.org.ua/2010/02/chapter-7-proactive-security-framework/</link>
		<comments>http://ciscoasa.org.ua/2010/02/chapter-7-proactive-security-framework/#comments</comments>
		<pubDate>Sun, 28 Feb 2010 22:50:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[capability gaps]]></category>
		<category><![CDATA[copm]]></category>
		<category><![CDATA[correlation]]></category>
		<category><![CDATA[financial reward]]></category>
		<category><![CDATA[instrumentation]]></category>
		<category><![CDATA[internet service provider]]></category>
		<category><![CDATA[maintaining control]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[next generation network]]></category>
		<category><![CDATA[pillars]]></category>
		<category><![CDATA[provider isp]]></category>
		<category><![CDATA[security frameworks]]></category>
		<category><![CDATA[security landscape]]></category>
		<category><![CDATA[security strategy]]></category>

		<guid isPermaLink="false">http://ciscoasa.org.ua/?p=258</guid>
		<description><![CDATA[
Many network security frameworks are in the marketplace and most of them have the common goal of providing a methodical and efficient approach to network security. No framework is perfect, you should choose an approach that can help reduce the time, cost, and resources needed to plan and deploy your security strategy. This chapter highlights [...]]]></description>
			<content:encoded><![CDATA[<div class=block style=" width:486.00pt; height:376.80pt;">
<div class=paragraph style=" padding:0.00pt 36.96pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Many network security frameworks are in the marketplace and most of them have the common goal of providing a methodical and efficient approach to network security. No framework is perfect, you should choose an approach that can help reduce the time, cost, and resources needed to plan and deploy your security strategy. This chapter highlights best practices and benefits of different security frameworks.</span></div>
<div class=paragraph style=" padding:5.76pt 53.04pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">A framework can help you establish a view of your entire security landscape, identify potential capability gaps, and prioritize initiatives for improvement.</span></div>
<div class=paragraph style=" padding:6.00pt 36.72pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Security Assessment, Validation, and Execution (SAVE) framework, formerly known as the Cisco Operational Process Model (COPM), is a security framework that enables visibility and control for end-to-end security. Cisco initially designed SAVE for the Internet service provider (ISP) part of the Next-Generation Network (NGN) initiative. However, you can also apply its practices to enterprises.</span></div>
<div class=paragraph style=" padding:6.24pt 37.20pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Today, malicious traffic within ISPs is spreading faster than before because attack tools are becoming more sophisticated and easier to find. ISPs have witnessed a transformation in the community that engages in cybercrime activities for financial reward, otherwise known as the <i>miscreant economy. </i>The principles introduced by SAVE allow ISPs and other organizations to defend against these threats while maintaining control and visibility of their networks.</span></div>
<div class=paragraph style=" padding:6.24pt 42.48pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">SAVE defines network security in six major categories or &quot;pillars.&quot; Figure 7-1 illustrates the different categories within the SAVE framework.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 91.20pt; text-align:left;"><span class=font44>The&nbsp;six pillars in SAVE are as follows:</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Identity and trust</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Visibility</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Correlation</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Instrumentation and management</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Isolation and virtualization</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Policy enforcement</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:75.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:84.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:311.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:40.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:24.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:6.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:27.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:47.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:23.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:3.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:38.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>178    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 294.96pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 7-1    </b><span class=font43><i>SAVE Categories Illustrated</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:26.40pt;">
<div class=paragraph style=" padding:0.00pt 37.20pt 0.00pt 58.32pt; text-align:left; text-indent:-2.88pt;"><span class=font3 style=" line-height:9.36pt;">Identity and Trust</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:71.28pt;">
<div class=block style=" width:71.28pt; height:26.40pt;">
<div class=paragraph style=" padding:8.64pt 36.96pt 0.00pt 6.48pt; text-align:justify;"><span class=font3>Visibility</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:62.88pt;">
<div class=block style=" width:62.88pt; height:26.40pt;">
<div class=paragraph style=" padding:7.92pt 25.20pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>Correlation</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:73.68pt;">
<div class=block style=" width:73.68pt; height:26.40pt;">
<div class=paragraph style=" padding:0.00pt 20.88pt 0.00pt 0.00pt; text-align:justify;"><span class=font3 style=" line-height:9.36pt;">Instrumentation</span></div>
<div class=paragraph style=" padding:0.00pt 24.48pt 0.00pt 3.36pt; text-align:left; text-indent:16.80pt;"><span class=font3 style=" line-height:9.36pt;">and Management</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:70.56pt;">
<div class=block style=" width:70.56pt; height:26.40pt;">
<div class=paragraph style=" padding:0.00pt 25.92pt 0.00pt 0.48pt; text-align:center;"><span class=font3 style=" line-height:9.36pt;">Isolation and Virtualization</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:90.48pt;">
<div class=block style=" width:90.48pt; height:26.40pt;">
<div class=paragraph style=" padding:3.12pt 46.08pt 0.00pt 0.00pt; text-align:left; text-indent:12.48pt;"><span class=font3 style=" line-height:9.36pt;">Policy Enforcement</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" rowspan="3" valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:24.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell rowspan="7" valign="top" style=" width:40.80pt;">
<div class=block style=" width:40.80pt; height:72.48pt;">
<div class=paragraph style=" padding:0.00pt 1.20pt 0.00pt 7.20pt; text-align:justify; text-indent:-6.24pt;"><span class=font3 style=" line-height:9.36pt;">Observe IP Packets</span></div>
<div class=paragraph style=" padding:4.80pt 6.72pt 0.00pt 7.92pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">Layer 2 through Layer 7</span></div>
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 4.80pt; text-align:justify; text-indent:-4.80pt;"><span class=font3 style=" line-height:9.60pt;">Stateful and Stateless</span></div>
</div>
</td>
<td class=cell colspan="12" valign="top" style=" width:328.08pt;">
<div class=block style=" width:328.08pt; height:12.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" rowspan="5" valign="top" style=" width:30.72pt;">
<div class=block style=" width:30.72pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell rowspan="5" valign="top" style=" width:37.92pt;">
<div class=block style=" width:37.92pt; height:46.56pt;">
<div class=paragraph style=" text-align:center;"><span class=font3 style=" line-height:9.36pt;">Relational Analysis of System-Wide</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font3 style=" line-height:9.36pt;">Events</span></div>
</div>
</td>
<td class=cell colspan="2" rowspan="5" valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell rowspan="5" valign="top" style=" width:39.84pt;">
<div class=block style=" width:39.84pt; height:46.56pt;">
<div class=paragraph style=" padding:0.00pt 2.16pt 0.00pt 1.92pt; text-align:left; text-indent:6.24pt;"><span class=font3 style=" line-height:9.36pt;">Device Hardening</span></div>
<div class=paragraph style=" text-align:left; text-indent:13.92pt;"><span class=font3 style=" line-height:9.36pt;">and Operational</span></div>
<div class=paragraph style=" text-align:center;"><span class=font3 style=" line-height:9.36pt;">Views</span></div>
</div>
</td>
<td class=cell colspan="6" valign="top" style=" width:188.64pt;">
<div class=block style=" width:188.64pt; height:9.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:101.28pt;">
<div class=block style=" width:101.28pt; height:1.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell rowspan="3" valign="top" style=" width:38.16pt;">
<div class=block style=" width:38.16pt; height:27.84pt;">
<div class=paragraph style=" text-align:center;"><span class=font3 style=" line-height:9.36pt;">Enforce Subscribed Behavior</span></div>
</div>
</td>
<td class=cell rowspan="3" valign="top" style=" width:49.20pt;">
<div class=block style=" width:49.20pt; height:27.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.24pt;">
<div class=block style=" width:54.24pt; height:24.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:26.64pt;">
<div class=block style=" width:26.64pt; height:24.48pt;">
<div class=paragraph style=" text-align:center;"><span class=font3 style=" line-height:9.36pt;"><a name="bookmark49">I</a>dentity State of Trust</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.24pt;">
<div class=block style=" width:36.24pt; height:24.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:24.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:47.52pt;">
<div class=block style=" width:47.52pt; height:24.48pt;">
<div class=paragraph style=" text-align:center;"><span class=font3 style=" line-height:9.36pt;">Segmentation and Partition</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:24.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" rowspan="3" valign="top" style=" width:117.12pt;">
<div class=block style=" width:117.12pt; height:24.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:101.28pt;">
<div class=block style=" width:101.28pt; height:1.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:188.64pt;">
<div class=block style=" width:188.64pt; height:9.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="12" valign="top" style=" width:328.08pt;">
<div class=block style=" width:328.08pt; height:12.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:412.80pt; height:82.32pt; padding:0.00pt 36.96pt 0.00pt 36.24pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:412.80pt; height:82.32pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:206.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:206.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:206.16pt;">
<div class=block style=" width:206.16pt; height:10.32pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:206.64pt;">
<div class=block style=" width:206.64pt; height:10.32pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:412.80pt;">
<div class=block style=" width:412.80pt; height:21.84pt;">
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 185.04pt; text-align:left;"><span class=font4>Resiliency</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:412.80pt;">
<div class=block style=" width:412.80pt; height:6.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:206.16pt;">
<div class=block style=" width:206.16pt; height:43.44pt;">
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 72.00pt; text-align:left;"><span class=font4 style=" line-height:9.36pt;">Total Visibility</span></div>
<div class=paragraph style=" padding:0.00pt 44.40pt 0.00pt 43.68pt; text-align:left; text-indent:-2.16pt;"><span class=font3 style=" line-height:9.36pt;">Classify, Categorize and Associate Events to a Given Control Policy</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:206.64pt;">
<div class=block style=" width:206.64pt; height:43.44pt;">
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 66.96pt; text-align:left;"><span class=font4 style=" line-height:9.36pt;">Complete Control</span></div>
<div class=paragraph style=" padding:0.00pt 21.36pt 0.00pt 23.76pt; text-align:left;"><span class=font3 style=" line-height:9.36pt;">Service Policies that allow for Containment, Mitigation and Service Constraint Enforcement</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:206.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:206.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:47.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:202.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>SAVE Versus ITU-T X.805</b></a></span></div>
<div class=paragraph style=" padding:3.84pt 45.60pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">There is a security methodology created by the Lucent consulting practice called ITU-T X.805, &quot;Security Architecture for Systems Providing End-to-End Communications.&quot; ITU-T X.805 defines a threat model that includes five categories:</span></div>
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Destruction</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Corruption</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Removal</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Disclosure</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Interruption</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">ITU-T X.805 defines three security layers:</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Infrastructure layer</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Services layer</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Applications layer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="16" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:59.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:54.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:40.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:24.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:6.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:27.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:47.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:23.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:3.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:38.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:216.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:52.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:216.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 318.72pt; text-align:justify;"><span class=font4>SAVE Versus ITU-T X.805 <b>179</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 292.08pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 7-2   </b><span class=font43><i>ITU-T X.805 Security Layers</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:216.24pt;">
<div class=block style=" width:216.24pt; height:70.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:52.80pt;">
<div class=block style=" width:52.80pt; height:70.80pt;">
<div class=paragraph style=" text-align:justify;"><span class=font4>ITU-T X.805</span></div>
<div class=paragraph style=" padding:3.60pt 6.72pt 0.00pt 6.24pt; text-align:left;"><span class=font3 style=" line-height:11.76pt;">Destruction Corruption Removal Disclosure Interruption</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:216.96pt;">
<div class=block style=" width:216.96pt; height:70.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:316.32pt; height:69.84pt; padding:0.00pt 85.20pt 0.00pt 84.48pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:316.32pt; height:69.84pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:104.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:106.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:105.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:104.88pt;">
<div class=block style=" width:104.88pt; height:23.04pt;">
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font4>Infrastructure Layer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:106.32pt;">
<div class=block style=" width:106.32pt; height:23.04pt;">
<div class=paragraph style=" padding:11.76pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font4>Services Layer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:105.12pt;">
<div class=block style=" width:105.12pt; height:23.04pt;">
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font4>Applications Layer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:104.88pt;">
<div class=block style=" width:104.88pt; height:10.56pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font3>• Routers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:106.32pt;">
<div class=block style=" width:106.32pt; height:10.56pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font3>• Voice over IP (VoIP)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:105.12pt;">
<div class=block style=" width:105.12pt; height:10.56pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3>• Web Browsing</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:104.88pt;">
<div class=block style=" width:104.88pt; height:9.60pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font3>• Switches</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:106.32pt;">
<div class=block style=" width:106.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font3>• Quality of Service (QoS)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:105.12pt;">
<div class=block style=" width:105.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3>• E-mail</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:104.88pt;">
<div class=block style=" width:104.88pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font3>• Firewalls</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:106.32pt;">
<div class=block style=" width:106.32pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font3>• Location Services</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:105.12pt;">
<div class=block style=" width:105.12pt; height:9.36pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3>• E-Commerce</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:104.88pt;">
<div class=block style=" width:104.88pt; height:17.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font3>• Servers and Workstations</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:106.32pt;">
<div class=block style=" width:106.32pt; height:17.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font3>• Other IP Services</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:105.12pt;">
<div class=block style=" width:105.12pt; height:17.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3>• Mobile Web</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:104.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:106.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:105.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:279.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The ITU-T X.805 infrastructure layer includes all infrastructure devices, including:</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Routers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Switches</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Firewalls</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Servers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;End-user workstations</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">The services layer includes services such as the following:</span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Voice over IP (VoIP)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Quality of service (QoS)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Location services</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Other IP services</span></div>
<div class=paragraph style=" padding:1.68pt 45.84pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The applications layer includes all Layer 7 applications that run on the network infrastructure. Each layer has unique threats, vulnerabilities, and ways to mitigate them. X.805 also has three security planes:</span></div>
<div class=paragraph style=" padding:3.60pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;End-user plane</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Control/Signaling plane</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Management plane</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">These security planes are illustrated in Figure 7-3.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:71.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:216.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:52.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:216.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:201.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:20.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:20.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:17.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:169.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>180    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 323.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 7-3   </b><span class=font43><i>ITU-T X.805 Planes</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:238.80pt;">
<div class=block style=" width:238.80pt; height:56.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:39.84pt;">
<div class=block style=" width:39.84pt; height:56.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.72pt; text-align:left; text-indent:-0.72pt;"><span class=font3 style=" line-height:11.76pt;">Destruction Corruption Removal Disclosure Interruption</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:207.36pt;">
<div class=block style=" width:207.36pt; height:56.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:316.32pt; height:69.84pt; padding:0.00pt 68.88pt 0.00pt 100.80pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:316.32pt; height:69.84pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:105.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:106.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:77.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:105.12pt;">
<div class=block style=" width:105.12pt; height:69.84pt;">
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 5.76pt; text-align:left;"><span class=font4>Infrastructure Layer</span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Routers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Switches</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Firewalls</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Servers and Workstations</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:106.08pt;">
<div class=block style=" width:106.08pt; height:69.84pt;">
<div class=paragraph style=" padding:12.00pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font4>Services Layer</span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Voice over IP (VoIP)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Quality of Service (QoS)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Location Services</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Other IP Services</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:77.76pt;">
<div class=block style=" width:77.76pt; height:69.84pt;">
<div class=paragraph style=" padding:12.00pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font4>Applications Lay</span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Web Browsing</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;E-mail</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;E-Commerce</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Mobile Web</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:16.56pt;">
<div class=block style=" width:16.56pt; height:69.84pt;">
<div class=paragraph style=" padding:12.24pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font4>er</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:10.80pt;">
<div class=block style=" width:10.80pt; height:69.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:105.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:106.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:77.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:2.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:218.40pt;">
<div class=block style=" width:218.40pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:11.52pt;">
<div class=paragraph style=" text-align:justify;"><span class=font4>End-User Security</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:186.72pt;">
<div class=block style=" width:186.72pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:201.60pt;">
<div class=block style=" width:201.60pt; height:27.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell colspan="5" valign="top" style=" width:114.72pt;">
<div class=block style=" width:114.72pt; height:27.36pt;">
<div class=paragraph style=" text-align:center;"><span class=font4 style=" line-height:15.84pt;">Control/Signaling Security Management Security</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:169.68pt;">
<div class=block style=" width:169.68pt; height:27.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:269.04pt;">
<div class=paragraph style=" padding:0.00pt 39.60pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">X.805 also includes eight security dimensions that apply to each security layer and plane. The following are these dimensions:</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Access control: </b>Firewall policies and access control lists (ACL).</span></div>
<div class=paragraph style=" padding:4.80pt 60.48pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Authentication: </b>Public key infrastructure (PKI), shared secrets, and one-time-passwords.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Nonrepudiation: </b>Syslogs and digital signatures.</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Data confidentiality: </b>This confidentiality occurs through the use of encryption.</span></div>
<div class=paragraph style=" padding:4.80pt 46.80pt 0.00pt 111.36pt; text-align:justify; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Communication security: </b>Transport mechanisms such as IP Security (IPsec) and Secure Socket Layer (SSL) virtual private networks (VPN), in addition to Layer 2 Tunneling Protocol (L2TP) tunnels.</span></div>
<div class=paragraph style=" padding:3.84pt 44.16pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Data integrity: </b>Hashing with message digest algorithm 5 (MD5) and Secure Hash Algorithm (SHA).</span></div>
<div class=paragraph style=" padding:4.32pt 60.72pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Availability: </b>Examples include redundancy with Hot Standby Router Protocol (HSRP) or Virtual Router Redundancy Protocol (VRRP).</span></div>
<div class=paragraph style=" padding:1.44pt 125.28pt 0.00pt 90.00pt; text-align:left; text-indent:7.44pt;"><span class=font44 style=" line-height:16.32pt;"><b>•&nbsp;Privacy: </b>Encryption and Network Address Translation (NAT). The eight security dimensions are illustrated in Figure 7-4.</span></div>
<div class=paragraph style=" padding:3.84pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Confused yet? X.805 is an overcomplicated approach. Cisco has tried to evolve it to make it more practical to use; however, X.805 is not a true end-to-end security framework and is even potentially harmful in the market and in standards.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:54.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:201.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:20.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:20.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:17.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:169.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:201.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:1.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:2.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:2.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:1.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:2.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:57.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:109.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 318.72pt; text-align:justify;"><span class=font4>SAVE Versus ITU-T X.805 <b>181</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 274.08pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 7-4   </b><span class=font43><i>ITU-T X.805 Security Dimensions</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:239.52pt;">
<div class=block style=" width:239.52pt; height:6.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell colspan="7" valign="top" style=" width:39.12pt;">
<div class=block style=" width:39.12pt; height:6.00pt;">
<div class=paragraph style=" text-align:justify;"><span class=font3>Destruction</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:207.36pt;">
<div class=block style=" width:207.36pt; height:6.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:240.96pt;">
<div class=block style=" width:240.96pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:36.24pt;">
<div class=block style=" width:36.24pt; height:7.68pt;">
<div class=paragraph style=" text-align:justify;"><span class=font3>Corruption</span></div>
</div>
</td>
<td class=cell colspan="6" valign="top" style=" width:208.80pt;">
<div class=block style=" width:208.80pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:244.08pt;">
<div class=block style=" width:244.08pt; height:6.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:30.24pt;">
<div class=block style=" width:30.24pt; height:6.00pt;">
<div class=paragraph style=" text-align:justify;"><span class=font3>Removal</span></div>
</div>
</td>
<td class=cell colspan="7" valign="top" style=" width:211.68pt;">
<div class=block style=" width:211.68pt; height:6.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:241.20pt;">
<div class=block style=" width:241.20pt; height:6.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:36.24pt;">
<div class=block style=" width:36.24pt; height:6.00pt;">
<div class=paragraph style=" text-align:justify;"><span class=font3>Disclosure</span></div>
</div>
</td>
<td class=cell colspan="5" valign="top" style=" width:208.56pt;">
<div class=block style=" width:208.56pt; height:6.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:239.52pt;">
<div class=block style=" width:239.52pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell colspan="7" valign="top" style=" width:39.12pt;">
<div class=block style=" width:39.12pt; height:7.68pt;">
<div class=paragraph style=" text-align:justify;"><span class=font3>Interruption</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:207.36pt;">
<div class=block style=" width:207.36pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:212.64pt;">
<div class=block style=" width:212.64pt; height:49.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.56pt; text-align:left;"><span class=font4>Infrastructure Layer</span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Routers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Switches</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Firewalls</span></div>
<div class=paragraph style=" padding:0.00pt 10.80pt 0.00pt 105.60pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Servers and Workstations</span></div>
</div>
</td>
<td class=cell colspan="10" valign="top" style=" width:106.08pt;">
<div class=block style=" width:106.08pt; height:49.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font4>Services Layer</span></div>
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Voice over IP (VoIP)</span></div>
<div class=paragraph style=" padding:0.00pt 15.36pt 0.00pt 0.00pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Quality of Service (QoS)</span></div>
<div class=paragraph style=" text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Location Services</span></div>
<div class=paragraph style=" text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Other IP Services</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:57.36pt;">
<div class=block style=" width:57.36pt; height:49.92pt;">
<div class=paragraph style=" padding:0.00pt 3.60pt 0.00pt 0.00pt; text-align:justify;"><span class=font4>Applications</span></div>
<div class=paragraph style=" padding:2.40pt 1.20pt 0.00pt 0.00pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Web Browsing</span></div>
<div class=paragraph style=" text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;E-mail</span></div>
<div class=paragraph style=" padding:0.00pt 5.52pt 0.00pt 0.00pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;E-Commerce</span></div>
<div class=paragraph style=" text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Mobile Web</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:109.92pt;">
<div class=block style=" width:109.92pt; height:49.92pt;">
<div class=paragraph style=" padding:0.00pt 85.44pt 0.00pt 0.00pt; text-align:justify;"><span class=font4>Layer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:201.60pt;">
<div class=block style=" width:201.60pt; height:41.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell colspan="10" valign="top" style=" width:114.72pt;">
<div class=block style=" width:114.72pt; height:41.52pt;">
<div class=paragraph style=" text-align:center;"><span class=font4 style=" line-height:15.84pt;">End-User Security Control/Signaling Security Management Security</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:169.68pt;">
<div class=block style=" width:169.68pt; height:41.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:76.56pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 196.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Access Control</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 196.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Authentication</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 196.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Non-Repudiation</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 196.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Data Confidentiality</span></div>
<div class=paragraph style=" padding:0.00pt 197.76pt 0.00pt 196.80pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Communication Security</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 196.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Data Integrity</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 196.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Availability</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 196.80pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">•&nbsp;Privacy</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:163.20pt;">
<div class=paragraph style=" padding:0.00pt 53.52pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">SAVE introduces a roles-based approach for security assessment in a simple manner. Each device on the network serves a purpose and has a role; subsequently, you should configure each device accordingly. SAVE defines five different planes:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Management plane: </b>Distributed and modular network management environment.</span></div>
<div class=paragraph style=" padding:5.04pt 47.52pt 0.00pt 111.36pt; text-align:justify; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Control plane: </b>Includes routing control. This is often a target because the control plane depends on direct CPU cycles.</span></div>
<div class=paragraph style=" padding:4.32pt 38.16pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;User/Data plane: </b>Receives, processes, and transmits network data among all network elements.</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Services plane: </b>Layer 7 application flow built on the foundation of the other layers.</span></div>
<div class=paragraph style=" padding:5.04pt 49.20pt 0.00pt 111.36pt; text-align:justify; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Policies: </b>The business requirements. Cisco calls policies the business glue for the network. Policies and procedures are part of this section, and they apply to all the planes in this list.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="14" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:40.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:201.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:11.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:1.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:2.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:2.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:1.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:37.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:2.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:57.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:109.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:352.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:133.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>182    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.28pt;">
<div class=paragraph style=" padding:0.00pt 230.64pt 0.00pt 36.48pt; text-align:left; text-indent:53.52pt;"><span class=font44 style=" line-height:20.16pt;">These planes are illustrated in Figure 7-5. <span class=font4><b>Figure 7-5   </b></span><span class=font43><i>Planes in SAVE</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:352.32pt;">
<div class=block style=" width:352.32pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 44.88pt 0.00pt 260.88pt; text-align:justify;"><span class=font3>Management</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:133.68pt;">
<div class=block style=" width:133.68pt; height:9.12pt;">
<div class=paragraph style=" padding:0.96pt 103.68pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>Services</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.60pt;">
<div class=paragraph style=" padding:0.00pt 107.76pt 0.00pt 107.52pt; text-align:justify;"><span class=font28 style=" line-height:31.68pt;">t     t     t t</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:109.68pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44>SAVE also presents security in two different perspectives:</span></div>
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Operational (reactive) security</span></div>
<div class=paragraph style=" padding:0.00pt 270.24pt 0.00pt 90.00pt; text-align:left; text-indent:7.44pt;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Proactive security This is illustrated in Figure 7-6.</span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 7-6    </b><span class=font43><i>Operational and Proactive Security</i></span></span></div>
<div class=paragraph style=" padding:6.96pt 146.16pt 0.00pt 222.00pt; text-align:left; text-indent:-76.08pt;"><span class=font4 style=" line-height:12.00pt;">Improve your capabilities to react to security incidents.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style="position:relative;  width:261.12pt; height:196.32pt; padding:0.00pt 113.04pt 0.00pt 111.84pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-63.jpg" alt="" style=" width:261.12pt; height:196.32pt;">
<div class=block style=" width:40.80pt; height:18.72pt; position:absolute; left:296.88pt; top:29.28pt;">
<div class=paragraph style=" text-align:center;"><span class=font3 style=" line-height:9.60pt;">Operational Security</span></div>
</div>
<div class=block style=" width:32.16pt; height:17.28pt; position:absolute; left:151.44pt; top:150.96pt;">
<div class=paragraph style=" text-align:justify;"><span class=font3 style=" line-height:9.60pt;">Proactive Security</span></div>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:37.92pt;">
<div class=paragraph style=" padding:0.00pt 157.20pt 0.00pt 156.48pt; text-align:center;"><span class=font3 style=" line-height:9.60pt;">Proactively prepare your infrastructure, staff, and organization as a whole. Learn about new attack vectors and mitigate them with the appropriate hardware, software, and architecture solutions.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:352.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:133.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 355.20pt; text-align:justify;"><span class=font4>Identity and Trust <b>183</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:522.00pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a name="bookmark50">Y</a>ou should have a balance between proactive and reactive security approaches. Prepare your network, staff, and organization as a whole to better identify, classify, trace back, and react to security incidents. In addition, proactively protect your organization while learning about new attack vectors, and mitigate those vectors with the appropriate hardware, software, and architecture solutions. You can achieve this balance using what you learned in Chapter 2, &quot;Preparation Phase.&quot; The best practices described there help you to proactively prepare and protect your network and organization as a whole.</span></div>
<div class=paragraph style=" padding:23.28pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark51"><b>Identity and Trust</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 37.92pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Identity and trust is one of the SAVE pillars. You should consider deploying a complete trust and identity management solution for secure network access and admission at every point in the network. The following are the most common technologies that are part of the identity and trust pillar:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Authentication, authorization, and accounting (AAA)</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Guard active verification</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;DHCP snooping</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Digital certificates and PKI</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Internet Key Exchange (IKE) protocol</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;IP Source Guard</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Network Admission Control and 802.1x</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Routing protocol authentication</span></div>
<div class=paragraph style=" padding:0.48pt 160.80pt 0.00pt 90.00pt; text-align:left; text-indent:7.44pt;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Strict Unicast Reverse Path Fowarding (Unicast RPF) These technologies are illustrated in Figure 7-7.</span></div>
<div class=paragraph style=" padding:22.32pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font8><b>AAA</b></span></div>
<div class=paragraph style=" padding:3.60pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Chapter 1, &quot;Overview of Network Security Technologies,&quot; you learned the basic concepts of AAA. In Chapter 2, &quot;Preparation Phase,&quot; you learned best practices for enabling authentication on networking devices for infrastructure protection. In this chapter, AAA concepts are aligned to the identity and trust pillar. A lack of appropriate user management techniques creates numerous direct business risks, including lower productivity, duplicate and conflicting user information, lack of information security, and difficulty in evaluating regulatory compliance. AAA goes beyond the normal authentication and authorization when accessing network devices for management purposes. You should implement a combination of authentication, access control, and user policies to secure network connectivity and resources to which only specific users should be provided access. This access includes the authentication of databases, web servers, e-mail, and other applications, in addition to authentication of users when they attempt to access network segments and their resources.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:248.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:27.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:40.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:169.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>184   </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 332.40pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 7-7   </b><span class=font43><i>Identity and Trust</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 213.12pt 0.00pt 248.88pt; text-align:justify;"><span class=font3>Radius</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:2.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 174.00pt 0.00pt 276.00pt; text-align:justify;"><span class=font3>TACACS+</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:248.88pt;">
<div class=block style=" width:248.88pt; height:23.76pt;">
<div class=paragraph style=" padding:14.64pt 78.48pt 0.00pt 109.44pt; text-align:justify;"><span class=font3>Identity and Trust</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:237.12pt;">
<div class=block style=" width:237.12pt; height:23.76pt;">
<div class=paragraph style=" padding:0.00pt 220.56pt 0.00pt 0.24pt; text-align:justify;"><span class=font16 style=" line-height:21.12pt;"><b>Э</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:316.80pt;">
<div class=block style=" width:316.80pt; height:26.40pt;">
<div class=paragraph style=" padding:19.68pt 99.60pt 0.00pt 201.36pt; text-align:justify;"><span class=font3>AAA</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:169.20pt;">
<div class=block style=" width:169.20pt; height:26.40pt;">
<div class=paragraph style=" padding:0.00pt 108.24pt 0.00pt 25.20pt; text-align:left; text-indent:5.76pt;"><span class=font3 style=" line-height:9.60pt;">Active Directory, LDAP, etc.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 222.72pt 0.00pt 154.56pt; text-align:justify;"><span class=font3>Cisco Guard Active Verification</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 247.92pt 0.00pt 180.48pt; text-align:justify;"><span class=font3>DHCP Snooping</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:276.00pt;">
<div class=block style=" width:276.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 19.92pt 0.00pt 162.24pt; text-align:justify;"><span class=font3>Digital Certificates and PKI</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:210.00pt;">
<div class=block style=" width:210.00pt; height:9.12pt;">
<div class=paragraph style=" padding:1.44pt 180.72pt 0.00pt 10.80pt; text-align:justify;"><span class=font3>Certs</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 270.96pt 0.00pt 203.52pt; text-align:justify;"><span class=font3>IKE</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:248.88pt;">
<div class=block style=" width:248.88pt; height:29.28pt;">
<div class=paragraph style=" padding:10.32pt 10.32pt 0.00pt 180.24pt; text-align:justify;"><span class=font3>IP Source Guard</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:237.12pt;">
<div class=block style=" width:98.40pt; height:29.28pt; padding:0.00pt 115.44pt 0.00pt 23.28pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-64.jpg" alt="" style=" width:98.40pt; height:29.28pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 228.48pt 0.00pt 161.04pt; text-align:justify;"><span class=font3>Network Admission Control</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:276.00pt;">
<div class=block style=" width:276.00pt; height:15.84pt;">
<div class=paragraph style=" padding:0.00pt 11.76pt 0.00pt 153.36pt; text-align:justify;"><span class=font3>Routing Protocol Authentication</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:210.00pt;">
<div class=block style=" width:210.00pt; height:15.84pt;">
<div class=paragraph style=" padding:0.00pt 114.72pt 0.00pt 13.20pt; text-align:justify;"><span class=font16 style=" line-height:15.12pt; letter-spacing:5.50pt;"><b><i>Ъ</i></b><span style=" letter-spacing:0.00pt;"><b><i>      </i></b></span><b><i>Ъ</i></b><span style=" letter-spacing:0.00pt;"><b><i> </i></b></span><b><i>4</i></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:276.00pt;">
<div class=block style=" width:276.00pt; height:32.16pt;">
<div class=paragraph style=" padding:10.80pt 46.32pt 0.00pt 189.12pt; text-align:justify;"><span class=font3>Strict uRPF</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:40.80pt;">
<div class=block style=" width:40.80pt; height:32.16pt;">
<div class=paragraph style=" padding:10.32pt 3.12pt 0.00pt 13.20pt; text-align:justify;"><span class=font16 style=" line-height:15.12pt; letter-spacing:5.50pt;"><b><i>Ъ</i></b><span style=" letter-spacing:0.00pt;"><b><i> </i></b></span><b><i>4</i></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:169.20pt;">
<div class=block style="position:relative;  width:65.28pt; height:32.16pt; padding:0.00pt 103.92pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-65.jpg" alt="" style=" width:65.28pt; height:32.16pt;">
<div class=block style=" width:28.80pt; height:7.68pt; position:absolute; left:27.36pt; top:12.72pt;">
<div class=paragraph style=" text-align:justify;"><span class=font3>Spoofed</span></div>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:135.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Other examples include authentication for remote access VPN and authentication of wireless users. The identity lifecycle consists of account setup, maintenance, and teardown. Account setup includes giving users the appropriate level of access to resources necessary to do their jobs. Account maintenance consists of keeping user identity information up-to-date and appropriately adjusting levels of access to resources needed to conduct business. Account teardown consists of deactivating the user account when the user is no longer affiliated with the company.</span></div>
<div class=paragraph style=" padding:6.00pt 41.28pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Stronger forms of authentication, such as PKI and one-time passwords (OTP), are increasingly used to control user access to corporate resources. Several solutions provide these kinds of services. You should always look for solutions that provide flexible authorization policies that are tied to the user identity, the network access type, and the</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:248.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:27.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:40.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:169.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 355.20pt; text-align:justify;"><span class=font4>Identity and Trust <b>185</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">security of the machine used to access the network. In addition, the ability to centrally track and monitor the connectivity of network users is of primary importance in isolating unwanted and excessive use of valuable network resources.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 49.44pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:12.24pt;"><b>NOTE        </b><span class=font44>Management, monitoring (correlation), and isolation are discussed later in this chapter, because they are separate SAVE categories or pillars.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:98.64pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">As you learned in Chapter 1, TACACS+ and RADIUS are the most commonly used AAA protocols. Cisco Secure ACS supports both of these protocols and provides support for advanced authentication mechanisms, including the interoperability to external directory services, OTP servers, PKI, and other authentication solutions.</span></div>
<div class=paragraph style=" padding:6.24pt 48.24pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Cisco Secure ACS is an important component of the Cisco Identity-Based Networking Services (IBNS) architecture based on port-security standards such as 802.1x (an IEEE standard for port-based network access control). It is also the &quot;brains&quot; behind the Cisco Network Admission Control (NAC) Framework solution.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.24pt;">
<div class=paragraph style=" padding:0.00pt 51.12pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>Examples of the use of Cisco Secure ACS are discussed in the case studies included in Chapter 12, &quot;Case Studies.&quot; The Cisco Secure ACS documentation is located at <a href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/tsd_products_support_maintain_and_operate.html">http://www.cisco.com/en/US/products/sw/secursw/ps2086/ tsd_products_support_maintain_and_operate.html.</a></span></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">A good white paper on how to place the Cisco ACS servers within your network is located at <a href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a0080092567.shtml">http://www.cisco.com/en/US/products/sw/secursw/ps2086/ products_white_paper09186a0080092567.shtml.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:86.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Cisco Guard Active Verification</b></span></div>
<div class=paragraph style=" padding:3.60pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco Guard provides multiple layers of defense to identify and block all types of attacks with extreme accuracy. It has integrated dynamic filtering capabilities and active verification technologies. These capabilities and technologies are implemented through the use of a patented Multiverification Process (MVP) architecture, which can process suspicious flows by applying numerous levels of analysis. The MVP enables malicious packets to be identified and removed, while allowing legitimate packets to flow freely.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt;">
<div class=block style=" width:89.76pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 29.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:396.24pt;">
<div class=block style=" width:396.24pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 43.44pt 0.00pt 0.24pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Chapter 3, &quot;Identifying and Classifying Security Threats,&quot; you learned how to use the Cisco Guard in conjunction with the Cisco Detector and other third-party solutions to identify and classify attacks.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:60.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>186    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:158.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>DHCP Snooping</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">DHCP snooping is another technology or feature that can be considered part of identity and trust. It is a DHCP security feature that filters DHCP messages by building and maintaining a binding table. This table contains information that corresponds to the local untrusted interfaces of a switch, such as:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;MAC address of the device connected to the switch</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;IP address of the device connected to the switch</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;DHCP lease time</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;DHCP binding type</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;VLAN number</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Interface information</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 39.36pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The DHCP snooping table does not contain information regarding hosts interconnected with a trusted interface. An untrusted interface is an interface that is configured to receive packets from an untrusted network or device. A trusted interface is an interface that is configured to receive only messages from within the trusted network or device.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:221.52pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">You can configure DHCP snooping for a single VLAN or a range of VLANs. The following example shows how to enable DHCP snooping on VLANs 10 through 50:</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 7-1   </b><span class=font43><i>IP DHCP Snooping</i></span></span></div>
<div class=paragraph style=" padding:6.72pt 261.36pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">'enable DHCP snooping globally !</span></div>
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23>ip dhcp snooping vlan 10 50</span></div>
<div class=paragraph style=" padding:1.20pt 227.52pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:8.40pt;">!apply DHCP snooping on VLANs 10 to 50 <sub>!</sub></span></div>
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23>ip dhcp snooping information option</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:1.92pt 257.52pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.84pt;">interface GigabitEthernet1/1 ip dhcp snooping limit rate 100</span></div>
<div class=paragraph style=" padding:0.48pt 55.92pt 0.00pt 105.36pt; text-align:left; text-indent:-7.20pt;"><span class=font23 style=" line-height:8.16pt;">!this interface is classified as an untrusted interface, and the rate limit is configured.</span></div>
<div class=paragraph style=" padding:10.32pt 65.76pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:9.84pt;">!You may not want to configure untrusted rate limiting to more than 100 pps. !Normally, the rate limit applies to untrusted interfaces.</span></div>
<div class=paragraph style=" padding:0.48pt 55.92pt 0.00pt 105.36pt; text-align:left; text-indent:-7.20pt;"><span class=font23 style=" line-height:8.16pt;">!If you want to set up rate limiting for trusted interfaces, keep in mind that trusted</span></div>
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23>!interfaces aggregate all DHCP traffic in the switch, and you will need to adjust</span></div>
<div class=paragraph style=" padding:0.00pt 284.40pt 0.00pt 98.16pt; text-align:left; text-indent:7.20pt;"><span class=font23 style=" line-height:9.84pt;">the rate !limit to a higher value.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:85.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 355.20pt; text-align:justify;"><span class=font4>Identity and Trust <b>187</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:138.24pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">You can use the <b>show ip dhcp snooping </b>command to verify your configuration, as shown in the following example:</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 7-2  </b><span class=font43><i>Ouput of the </i><b>show ip dhcp snooping </b><i>command</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">myswitch#show ip dhcp snooping</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.48pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Switch DHCP snooping is enabled</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">DHCP snooping is configured on following VLANs:</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">10,20,30,40,50</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Insertion of option 82 is enabled</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.48pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Option 82 on untrusted port is not allowed</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">Verification of hwaddr field is enabled</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:19.44pt;">Interface&nbsp;Trusted        Rate limit (pps)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.72pt; text-align:left;"><span class=font23 style=" line-height:19.44pt;">GigabitEthernet1/1&nbsp;no 100</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:369.60pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the previous example, you can see that DHCP snooping is enabled on VLANs 10, 20, 30, 40, and 50 (which are VLANs enabled on this switch). The interface GigabitEthernet1/1 is an untrusted interface, and rate limit is applied to 100 packets per second (pps). To configure an interface as a trusted interface, you must use the <b>ip dhcp snooping trust </b>interface subcommand.</span></div>
<div class=paragraph style=" padding:22.56pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font8><b>IP Source Guard</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">IP Source Guard is a Layer 2 feature that works in conjunction with DHCP snooping. When IP Source Guard is enabled, all IP traffic on the port is initially blocked, with the exception of DHCP packets that are processed by the DHCP snooping feature (if enabled). After the end host receives a valid IP address from the DHCP server, or when a user configures a static IP source binding, a Port Access Control List (PACL) is applied on the port to restrict the client IP traffic to specific source IP addresses that are configured in the binding configuration. The switch drops all IP traffic with a source IP address other than that in the IP source binding.</span></div>
<div class=paragraph style=" padding:6.24pt 43.20pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">An important note to remember is that if you configure IP Source Guard on a trunk port with a large number of VLANs that have DHCP snooping enabled, you might run out of ACL hardware resources, and depending on your platform, some packets might be switched in software. You can configure two levels of IP traffic filtering with IP Source Guard:</span></div>
<div class=paragraph style=" padding:6.00pt 38.88pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Filtering source IP addresses: </b>Only IP traffic with a source IP address that matches the IP source binding entry is permitted.</span></div>
<div class=paragraph style=" padding:3.84pt 40.80pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Filtering on Source IP and MAC address: </b>This is based on source IP address and its associated MAC address.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>To enable IP Source Guard, use the <b>ip verify source vlan dhcp-snooping interface</b></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44>subcommand, as shown in the following example:</span></div>
<div class=paragraph style=" padding:7.20pt 235.68pt 0.00pt 102.24pt; text-align:left; text-indent:-4.56pt;"><span class=font23 style=" line-height:8.16pt;">interface GigabitEthernet1/1 ip verify source vlan dhcp-snooping</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:55.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:55.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:55.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:154.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:75.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>188    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph style=" padding:0.00pt 90.24pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">To verify the configuration, you can use the <b>show ip verify source interface gigabitEthernet 1/1 </b>command, as shown in the following example:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="5" valign="top" style=" width:410.16pt;">
<div class=block style=" width:410.16pt; height:14.88pt;">
<div class=paragraph style=" padding:0.00pt 35.04pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myswitch#show ip verify source interface gigabitEthernet 1/1 Interface   Filter-type   Filter-mode   IP-address Mac-address</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:75.84pt;">
<div class=block style=" width:75.84pt; height:14.88pt;">
<div class=paragraph style=" padding:6.72pt 59.76pt 0.00pt 0.00pt; text-align:justify;"><span class=font23>Vlan</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:144.96pt;">
<div class=block style=" width:144.96pt; height:16.56pt;">
<div class=paragraph style=" padding:0.24pt 28.08pt 0.00pt 97.20pt; text-align:justify;"><span class=font23 style=" line-height:7.92pt;">Gi1/1 Gi1/1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:55.44pt;">
<div class=block style=" width:55.44pt; height:16.56pt;">
<div class=paragraph style=" padding:0.00pt 30.96pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:7.92pt;">ip-mac ip-mac</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:55.68pt;">
<div class=block style=" width:55.68pt; height:16.56pt;">
<div class=paragraph style=" padding:0.24pt 30.96pt 0.00pt 0.00pt; text-align:justify;"><span class=font23 style=" line-height:7.92pt;">active active</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:154.08pt;">
<div class=block style=" width:154.08pt; height:16.56pt;">
<div class=paragraph style=" padding:0.48pt 117.60pt 0.00pt 0.24pt; text-align:justify;"><span class=font23>10.10.1.1</span></div>
<div class=paragraph style=" padding:0.00pt 120.72pt 0.00pt 0.00pt; text-align:justify;"><span class=font23>deny-all</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:75.84pt;">
<div class=block style=" width:75.84pt; height:16.56pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font23>10</span></div>
<div class=paragraph style=" padding:0.00pt 55.20pt 0.00pt 0.48pt; text-align:justify;"><span class=font23>11-20</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.48pt;">
<div class=paragraph style=" padding:0.00pt 284.64pt 0.00pt 36.72pt; text-align:justify;"><span class=font8><b>Digital Certificates and PKI</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.52pt;">
<div class=block style=" width:89.52pt; height:241.92pt;">
<div class=paragraph style=" padding:201.60pt 33.12pt 0.00pt 36.72pt; text-align:justify;"><span class=font8><b>IKE</b></span></div>
</div>
</td>
<td class=cell colspan="5" valign="top" style=" width:396.48pt;">
<div class=block style=" width:396.48pt; height:241.92pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 0.24pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Digital certificates and PKI are also technologies that are used for trust and identity. Digital certificates bind an identity to a pair of electronic keys that can be used to encrypt and sign digital information. A digital certificate makes it possible to verify a claim that someone has the right to use a given key. This verification helps to prevent people from using phony keys to impersonate other users. Used in conjunction with encryption, digital certificates provide a more complete security solution than traditional username and password schemes. Digital certificates ensure the identity of all parties involved in a transaction.</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font44>The following are some of the most common uses of digital certificates:</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;IPsec VPN tunnel authentication</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;SSL transactions</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Code signing</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Application authentication (that is, e-mail, e-commerce, and so on)</span></div>
<div class=paragraph style=" padding:39.12pt 42.00pt 0.00pt 0.48pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">IKE provides authentication mechanisms for IPsec VPN tunnels. This protocol is also an example of identity and trust technologies.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.52pt;">
<div class=block style=" width:89.52pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 29.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE</b></span></div>
</div>
</td>
<td class=cell colspan="5" valign="top" style=" width:396.48pt;">
<div class=block style=" width:396.48pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 73.20pt 0.00pt 0.00pt; text-align:justify;"><span class=font44>Detailed information on IKE authentication mechanisms is covered in Chapter 1.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.24pt;">
<div class=paragraph style=" padding:0.00pt 240.24pt 0.00pt 36.72pt; text-align:justify;"><span class=font8><b>Network Admission Control (NAC)</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:69.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">NAC is also an example of a trust and identity technology. As you learned in Chapters 1 and 2, NAC appliance and framework provide a solution to evaluate whether end-host workstations are compliant with security policies before they enter the network. These policies can include antivirus, antispyware software, operating system updates, security patches, and other preconfigured options. In addition, the role-based authentication features provide more granular access to end hosts and users.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:63.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:55.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:55.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:55.68pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:154.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:75.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 390.24pt; text-align:justify;"><span class=font4>Visibility <b>189</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:75.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font8><b>Routing Protocol Authentication</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Another example of a trust and identity technique is the implementation of routing protocol authentication. Border Gateway Protocol (BGP), Enhanced Interior Gateway Routing Protocol (EIGRP), Open Shortest Path First (OSPF), Routing Information Protocol (RIP) and Intermediate System-to-Intermediate System Protocol (IS-IS) all support various forms of authentication mechanisms.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 117.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><a name="bookmark52"><b>N</b></a><b>OTE        </b><span class=font44>These authentication mechanisms are discussed in Chapter 2 in detail.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:74.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><b>Strict Unicast RPF</b></span></div>
<div class=paragraph style=" padding:3.60pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Strict Unicast RPF is an antispoofing mechanism that verifies the source address of a packet received on a router interface by verifying the forwarding table of the router. If the source address is reachable through the same interface on which the packet was received, the router processes the packet; if not, the packet is dropped. You can also categorize Unicast RPF as a trust and identity mechanism.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 241.68pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>Unicast RPF is discussed in Chapter 2.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:183.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font11><a href="#bookmark51"><b>Visibility</b></a></span></div>
<div class=paragraph style=" padding:3.84pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Network visibility is one of the most important pillars within the SAVE framework. In fact, two of the most important components of SAVE are visibility and control. The following are the most common technologies that can be used to obtain and maintain complete network visibility:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Anomaly detection</span></div>
<div class=paragraph style=" padding:4.56pt 82.80pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Intrusion detection system/intrusion prevention system (IDS/IPS) [IOS, Cisco Security Agent (CSA), network-based intrusion detection system/network-based intrusion prevention system (NIDS/NIPS)]</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Cisco Network Analysis Module (NAM)</span></div>
<div class=paragraph style=" padding:4.80pt 45.12pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Layer 2 and Layer 3 information [Cisco Discovery Protocol (CDP), routing tables, Cisco Express Forwarding (CEF) tables]</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>These are illustrated in Figure 7-8.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:97.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:77.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:98.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:45.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:24.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:94.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>190    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 117.36pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 7-8    </b><span class=font43><i>Technologies That Help to Achieve and Maintain Complete Network Visibility</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="6" valign="top" style=" width:77.04pt;">
<div class=block style=" width:77.04pt; height:152.88pt;layout-flow:vertical-ideographic;">
</div>
</td>
<td class=cell rowspan="6" valign="top" style=" width:72.72pt;">
<div class=block style=" width:72.72pt; height:152.88pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:72.72pt; height:152.88pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:72.72pt;">
<div class=block style=" width:72.72pt; height:20.16pt;">
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 22.08pt; text-align:left;"><span class=font3>Visibility</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:13.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:13.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:12.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:12.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:11.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:11.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:13.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:13.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:9.12pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:9.12pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:15.12pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:15.12pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:13.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:13.68pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:14.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:14.88pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt;">
<div class=block style=" width:36.00pt; height:16.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:16.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell colspan="6" valign="top" style=" width:336.24pt;">
<div class=block style=" width:336.24pt; height:0.48pt;layout-flow:vertical-ideographic;">
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:143.76pt;">
<div class=block style=" width:143.76pt; height:6.00pt;layout-flow:vertical-ideographic;">
</div>
</td>
<td class=cell valign="top" style=" width:43.44pt;">
<div class=block style=" width:43.44pt; height:6.00pt;">
<div class=paragraph style=" text-align:justify;"><span class=font3>Cisco Guard</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:149.04pt;">
<div class=block style=" width:149.04pt; height:6.00pt;layout-flow:vertical-ideographic;">
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="6" valign="top" style=" width:336.24pt;">
<div class=block style=" width:336.24pt; height:28.80pt;layout-flow:vertical-ideographic;">
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:143.76pt;">
<div class=block style=" width:143.76pt; height:26.40pt;">
<div class=paragraph style=" padding:0.00pt 77.52pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>Anomaly Detection</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:68.40pt;">
<div class=block style=" width:68.40pt; height:26.40pt;">
<div class=paragraph style=" padding:0.00pt 39.60pt 0.00pt 0.24pt; text-align:justify;"><span class=font3>NetFlow</span></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:29.28pt;">
<div class=block style=" width:25.92pt; height:28.80pt; padding:26.40pt 3.36pt 8.64pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-66.jpg" alt="" style=" width:25.92pt; height:28.80pt;"></div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:94.80pt;">
<div class=block style=" width:94.80pt; height:63.84pt;">
<div class=paragraph style=" padding:37.92pt 78.96pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>CSA</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:98.40pt;">
<div class=block style=" width:98.40pt; height:37.44pt;">
<div class=paragraph style=" padding:11.04pt 51.12pt 0.00pt 19.68pt; text-align:justify;"><span class=font3>IDS/IPS</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:113.76pt;">
<div class=block style=" width:113.76pt; height:37.44pt;">
<div class=paragraph style=" padding:5.76pt 12.24pt 0.00pt 44.88pt; text-align:left; text-indent:6.00pt;"><span class=font3 style=" line-height:9.60pt;">IPS Sensors, AIP-SSM, IDSM</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:98.40pt;">
<div class=block style=" width:98.40pt; height:53.76pt;">
<div class=paragraph style=" padding:11.52pt 56.88pt 0.00pt 24.96pt; text-align:justify;"><span class=font3>NAM</span></div>
</div>
</td>
<td class=cell colspan="5" valign="top" style=" width:237.84pt;">
<div class=block style="position:relative;  width:32.64pt; height:32.16pt; padding:0.00pt 195.12pt 21.60pt 10.08pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-67.jpg" alt="" style=" width:32.64pt; height:32.16pt;">
<div class=block style=" width:21.60pt; height:20.16pt; position:absolute; left:17.76pt; top:2.88pt;">
<div class=paragraph style=" text-align:justify;"><span class=font51 style=" line-height:20.16pt;">■</span></div>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 128.88pt 0.00pt 248.16pt; text-align:justify;"><span class=font3>CDP, Routing Tables, CEF, etc.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:100.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 39.60pt; text-align:left;"><span class=font8><b>Anomaly Detection</b></span></div>
<div class=paragraph style=" padding:3.60pt 84.72pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Anomaly detection can be performed by various tools that provide insightful information on exactly what is happening within your network. These tools or technologies include the following:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;NetFlow</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Arbor Peakflow SP and Peakflow X</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Anomaly Detector XT</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 73.68pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>Anomaly detection technologies and solutions are discussed in Chapters 1 and 2.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:74.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>IDS/IPS</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">IDSs and IPSs also provide visibility into what is happening on the network. Most of the network IDS and IPS systems rely on signatures for detection and protection. For this reason, it is extremely important to keep signatures up-to-date and to tune the IDS/IPS devices accordingly. Cisco IPS 6.0 now supports anomaly detection capabilities that allow you to detect day-zero vulnerabilities more easily.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="8" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:95.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:77.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:98.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:45.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:24.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:94.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 390.24pt; text-align:justify;"><span class=font4>Visibility <b>191</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:justify; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE </b><span class=font44>An introduction to network IDS and IPS systems is covered in Chapter 1. Chapter 3 teaches you how to use network IDS and IPS systems to successfully identify and classify security threats. The configuration of IPS systems is covered within the case studies included in</span></span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>Chapter 12.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Host-based intrusion prevention systems, such as the Cisco Security agent, also provide information about the behavior of end-host systems by extending the visibility to each end point (host or servers).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:108.96pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Cisco Network Analysis Module (NAM)</b></span></div>
<div class=paragraph style=" padding:3.60pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Cisco NAM is an integrated network monitoring solution for the Cisco Catalyst 6500 series switches. Ciso NAM is designed to give you visibility into the network by showing you information about applications running on your network and the performance of these applications. The Cisco NAM solution includes a web-based traffic analyzer GUI that presents statistical information to the administrator. The Cisco NAM uses Management Information Bases (MIB) for Remote Monitoring II (RMON II), Differentiated Services Monitoring (DSMON), Switch Monitoring (SMON), and other mechanisms to analyze and store the collected data.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.16pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>NOTE        </b><span class=font44>The following link provides detailed information about NAM:</span></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44><a href="http://www.cisco.com/en/US/products/hw/modules/ps2706/ps5025/index.html">http://www.cisco.com/en/US/products/hw/modules/ps2706/ps5025/index.html.</a></span></div>
<div class=paragraph style=" padding:4.08pt 39.84pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The configuration guide is located at <a href="http://www.cisco.com/en/US/products/hw/switches/ps708/products_configuration_guide_book09186a00805e081e.html">http://www.cisco.com/en/US/products/hw/switches/ ps708/products_configuration_guide_book09186a00805e081e.html.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:72.96pt;">
<div class=paragraph style=" padding:0.00pt 44.16pt 0.00pt 36.72pt; text-align:justify;"><span class=font8><b>Layer 2 and Layer 3 Information (CDP, Routing Tables, CEF Tables)</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Layer 2 and Layer 3 routing features can provide insightful information and increase visibility. Features such as CDP, <span style=" letter-spacing:-1.00pt;">CEF,</span> and IP routing tables can give you topological information about the network. It is important to notice that in the hands of the enemy, tools like CDP can be destructive. Therefore, it is recommended that you enable CDP only on trusted interfaces.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt;">
<div class=block style=" width:89.76pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 29.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:396.24pt;">
<div class=block style=" width:396.24pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 36.96pt 0.00pt 0.00pt; text-align:justify;"><span class=font44>For more information on best practices to use when implementing CDP, refer to Chapter 2.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:91.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>192    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:223.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark51"><a name="bookmark53"><b>C</b></a><b>orrelation</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In previous chapters, you learned the different aspects of event correlation. For example, you learned that the more complex the network and devices deployed, the more event messages, alarms, and alerts these devices will generate. In the end, far more data is generated than anyone can easily scan, and it is located in numerous places. In this chapter, you learn the importance of event correlation for maintaining good visibility of what is happening in the network. This chapter also describes tools and technologies you can deploy to successfully correlate events, while maintaining visibility and control of the network. Event correlation tools enable you to efficiently use your staff time and skills, and they prevent revenue loss resulting from downtime. The following are examples of correlation tools:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Security Monitoring, Analysis, and Response System (CS-MARS)</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Arbor Peakflow SP and Peakflow X</span></div>
<div class=paragraph style=" padding:0.00pt 65.76pt 0.00pt 90.00pt; text-align:left; text-indent:7.44pt;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Security Agent Management Center (CSA-MC) basic event correlation These tools are illustrated in Figure 7-9.</span></div>
<div class=paragraph style=" padding:8.40pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 7-9   </b><span class=font43><i>Example of Tools That Help You Maintain Network Visibility</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:288.72pt; height:254.64pt; padding:0.00pt 99.12pt 0.00pt 98.16pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-68.jpg" alt="" style=" width:288.72pt; height:254.64pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:90.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 288.96pt; text-align:justify;"><span class=font4>Instrumentation and Management <b>193</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.96pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>CS-MARS</b></span></div>
<div class=paragraph style=" padding:3.60pt 40.32pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">CS-MARS supports events from routers, switches, firewalls, VPN devices, IPS/IDS solutions, operating system logs, application logs, and many other items. It supports both Cisco and non-Cisco devices.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:11.76pt;"><a name="bookmark54"><b>N</b></a><b>OTE        </b><span class=font44>Chapter 3 teaches how you can use CS-MARS to successfully identify and classify security threats. The configuration of CS-MARS is covered within the case studies included in Chapter 12.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font8><b>Arbor Peakflow SP and Peakflow X</b></span></div>
<div class=paragraph style=" padding:3.60pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Arbor Peakflow SP (for service providers) and Peakflow X (for enterprises) are excellent tools that allow you to obtain network visibility. Based on information collected from routers, such as interface statistics and NetFlow, Peakflow SP and Peakflow X can show you details of the traffic traversing throughout your network.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>NOTE        </b><span class=font44>For more information about these tools, go to <a href="http://www.arbor.net">http://www.arbor.net.</a></span></span></div>
<div class=paragraph style=" padding:3.84pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Arbor has excellent white papers about anomaly detection and combating day-zero threats at <a href="http://www.arbor.net/resources_researchers.php">http://www.arbor.net/resources_researchers.php.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:68.16pt;">
<div class=paragraph style=" padding:0.00pt 78.72pt 0.00pt 35.76pt; text-align:left;"><span class=font8 style=" line-height:15.12pt;"><b>Cisco Security Agent Management Console (CSA-MC) Basic Event Correlation</b></span></div>
<div class=paragraph style=" padding:2.40pt 58.32pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">CSA-MC can also provide you with basic host-based event correlation. You can gain visibility of what exactly is happening within each endpoint (user workstations and servers).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:123.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark51"><b>Instrumentation and Management</b></a></span></div>
<div class=paragraph style=" padding:3.12pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Instrumentation and management is also an important category within the SAVE framework. You should always implement protocols and mechanisms that achieve the management of every network device. Having good instrumentation and management mechanisms in place not only allows you to provision configurations to your network devices, but it also helps you to maintain control of your environment. Some examples of management and instrumentation tools are as follows:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Cisco Security Manager (CSM)</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Configuration logger and configuration rollback</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:227.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:71.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:177.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>194   </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:93.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Embedded device managers</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco IOS XR XML interface</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Simple Network Management Protocol (SNMP) and remote monitoring (RMON)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Syslog</span></div>
<div class=paragraph style=" padding:0.00pt 210.00pt 0.00pt 36.48pt; text-align:left; text-indent:53.52pt;"><span class=font44 style=" line-height:19.92pt;">These tools are illustrated in Figure 7-10. <span class=font4><b>Figure 7-10 </b></span><span class=font43><i>Example of Instrumentation and Management Tools</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:227.04pt;">
<div class=block style=" width:227.04pt; height:55.20pt;">
<div class=paragraph style=" padding:0.00pt 96.00pt 0.00pt 69.12pt; text-align:justify; text-indent:4.08pt;"><span class=font3 style=" line-height:9.60pt;">Instrumentation and Management</span></div>
</div>
</td>
<td class=cell colspan="3" rowspan="2" valign="top" style=" width:258.96pt;">
<div class=block style=" width:121.92pt; height:108.48pt; padding:0.00pt 137.04pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-69.jpg" alt="" style=" width:121.92pt; height:108.48pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:227.04pt;">
<div class=block style=" width:227.04pt; height:53.28pt;">
<div class=paragraph style=" padding:0.00pt 14.16pt 0.00pt 128.16pt; text-align:justify;"><span class=font3>Cisco Security Manager</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:227.04pt;">
<div class=block style=" width:227.04pt; height:43.68pt;">
<div class=paragraph style=" padding:12.00pt 19.68pt 0.00pt 132.48pt; text-align:center;"><span class=font3 style=" line-height:9.60pt;">Configuration Logger and Rollback</span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:258.96pt;">
<div class=block style=" width:27.36pt; height:43.68pt; padding:0.00pt 222.00pt 0.00pt 9.60pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-70.jpg" alt="" style=" width:27.36pt; height:43.68pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:236.64pt;">
<div class=block style=" width:236.64pt; height:35.52pt;">
<div class=paragraph style=" padding:12.48pt 15.12pt 0.00pt 118.56pt; text-align:justify;"><span class=font3>Embedded Device Managers</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:249.36pt;">
<div class=block style=" width:25.92pt; height:35.52pt; padding:0.00pt 221.52pt 0.00pt 1.92pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-71.jpg" alt="" style=" width:25.92pt; height:35.52pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:308.40pt;">
<div class=block style=" width:308.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 46.32pt 0.00pt 240.00pt; text-align:justify;"><span class=font3>ASDM</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:177.60pt;">
<div class=block style=" width:177.60pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 73.44pt 0.00pt 87.60pt; text-align:justify;"><span class=font3>SDM</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:236.64pt;">
<div class=block style=" width:236.64pt; height:19.20pt;">
<div class=paragraph style=" padding:0.00pt 33.12pt 0.00pt 136.32pt; text-align:center;"><span class=font3 style=" line-height:9.60pt;">Cisco IOS XR XML Interface</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:19.20pt;">
<div class=paragraph style=" padding:4.32pt 49.44pt 0.00pt 6.24pt; text-align:justify;"><span class=font3>XML</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:177.60pt;">
<div class=block style=" width:177.60pt; height:19.20pt;">
<div class=paragraph style=" padding:1.92pt 138.48pt 0.00pt 0.00pt; text-align:justify;"><span class=font16 style=" line-height:15.84pt; letter-spacing:5.50pt;"><b><i>Ъ4</i></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:236.64pt;">
<div class=block style=" width:236.64pt; height:54.72pt;">
<div class=paragraph style=" padding:22.80pt 35.04pt 0.00pt 137.52pt; text-align:justify;"><span class=font3>SNMP and RMON</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:249.36pt;">
<div class=block style=" width:121.92pt; height:54.72pt; padding:0.00pt 126.48pt 0.00pt 0.96pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-72.jpg" alt="" style=" width:121.92pt; height:54.72pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 304.08pt 0.00pt 158.64pt; text-align:justify;"><span class=font3>Syslog</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:99.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:227.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:71.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:177.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 288.96pt; text-align:justify;"><span class=font4>Instrumentation and Management <b>195</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Cisco Security Manager</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">CSM helps you configure Cisco firewalls, IPS devices, and VPN tunnels easily. It not only saves you time in the provisioning phase, but it can also be used to update enforcement policies in firewalls and routers when needed. CSM achieves scalability through policy-based management techniques that are used to simplify administration.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Configuration Logger and Configuration Rollback</b></span></div>
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Cisco IOS configuration logger logs all changes that are manually entered at</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">the command-line prompt. In addition, it can notify registered clients about any changes</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">to the log.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:54.96pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>The contents of the configuration log are stored in the run-time memory; the contents of the log are not persisted after reboots. The Configuration Logger Persistency feature allows you to keep the configuration commands entered by users after reloads. You can enable the Configuration Logger Persistency feature by using the <b>archive log config persistent save </b>command.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 40.08pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco IOS Software configuration rollback feature allows you to keep a journal file containing a log of the changes and discard them if needed. The purpose of this feature is to revert (or roll back) to a previous configuration. You can use the <b>configure replace </b>command to roll back to a previous configuration state.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 70.08pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>More information about the Cisco IOS configuration rollback feature is located at <a href="http://www.cisco.com/en/US/products/sw/iosswrel/ps5207/products_feature_guide09186a0080356ea5.html%23wp1066264">http://www.cisco.com/en/US/products/sw/iosswrel/ps5207/ products_feature_guide09186a0080356ea5.html#wp1066264.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:139.68pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 39.36pt; text-align:left;"><span class=font8><b>Embedded Device Managers</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In small environments, you can use embedded devices managers to configure and manage network access devices such as routers, switches, firewalls, IPS devices, and others. Numerous Cisco devices come with an embedded device manager. Examples include the following:</span></div>
<div class=paragraph style=" padding:5.76pt 59.28pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.24pt;"><b>•&nbsp;Cisco Adaptive Security Device Manager (ASDM): </b>Manages Cisco PIX and Cisco Adaptive Security Appliance (ASA) security appliances</span></div>
<div class=paragraph style=" padding:3.36pt 44.88pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Cisco IPS Device Manager (IDM): </b>Manages Cisco IPS sensors, in addition to Advanced Inspection and Prevention Security Services Module (AIP-SSM) for the Cisco ASA</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44><b>•&nbsp;Security Device Manager (SDM): </b>Manages Cisco IOS routers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>196    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Cisco IOS XR XML Interface</b></span></div>
<div class=paragraph style=" padding:3.36pt 90.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco IOS XR software supports an extensible markup language (XML) application programming interface (API) that helps you develop external management applications for routers that run Cisco IOS XR software.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>NOTE        </b><span class=font44>The following site has detailed information about the Cisco IOS XR XML interface:</span></span></div>
<div class=paragraph style=" padding:4.56pt 47.28pt 0.00pt 0.00pt; text-align:right;"><span class=font44><a href="http://www.cisco.com/en/US/products/ps5845/tsd_products_support_series_home.html">http://www.cisco.com/en/US/products/ps5845/tsd_products_support_series_home.html</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><a name="bookmark55"><b>S</b></a><b>NMP and RMON</b></span></div>
<div class=paragraph style=" padding:3.60pt 49.20pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">SNMP allows you to exchange management information between network devices and central management servers. SNMP is the most commonly used network device management protocol.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 39.60pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>In Chapter 2, you learn the basics of SNMP and what is most important: how to secure it.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 39.12pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The RMON protocol provides you with freedom when selecting network-monitoring probes and consoles with features that not only provide ease of management, but also can be used for greater visibility and control of the network.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:43.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:185.04pt;">
<div class=paragraph style=" padding:0.00pt 46.08pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Chapters 2 and 3, you learn how syslog can provide you with details on what is happening in network devices, while also allowing you to achieve more control and visibility of the network. Firewalls, routers, switches, and other networking devices can send insightful information to administrators via syslog. The combination of syslog and event correlation systems gives you powerful capabilities.</span></div>
<div class=paragraph style=" padding:23.28pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark51"><b>Isolation and Virtualization</b></a></span></div>
<div class=paragraph style=" padding:3.84pt 52.08pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The fifth pillar in the SAVE framework addresses network isolation and virtualization. Several isolation and virtualization techniques and tools are available, including the following:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco IOS Role-Based CLI Access (CLI Views)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Anomaly detection zones</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Network device virtualization</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:51.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 318.48pt; text-align:justify;"><span class=font4>Isolation and Virtualization <b>197</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:77.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Segmentation with VLANs</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Segmentation with firewalls</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Segmentation with VRF/VRF-Lite</span></div>
<div class=paragraph style=" padding:0.24pt 169.20pt 0.00pt 0.00pt; text-align:right;"><span class=font44 style=" line-height:15.84pt;">These techniques and tools are illustrated in Figure 7-11.</span></div>
<div class=paragraph style=" padding:8.40pt 171.84pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 7-11 </b><span class=font43><i>Examples of Isolation and Virtualization Techniques and Tools</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:211.44pt; height:238.80pt; padding:0.00pt 137.76pt 0.00pt 136.80pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:211.44pt; height:238.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:135.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:76.32pt;">
<div class=block style=" width:76.32pt; height:20.16pt;">
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 22.32pt; text-align:left;"><span class=font3>Isolation</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:135.12pt;">
<div class=block style=" width:135.12pt; height:20.16pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="12" valign="top" style=" width:36.48pt;">
<div class=block style=" width:36.48pt; height:218.64pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:174.96pt;">
<div class=block style=" width:174.96pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt;">
<div class=block style=" width:39.84pt; height:24.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:135.12pt;">
<div class=block style=" width:135.12pt; height:24.00pt;">
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 1.20pt; text-align:center;"><span class=font3>Cisco IOS role-based CLI Access</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:174.96pt;">
<div class=block style=" width:174.96pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt;">
<div class=block style=" width:39.84pt; height:24.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:135.12pt;">
<div class=block style=" width:135.12pt; height:24.24pt;">
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 0.72pt; text-align:center;"><span class=font3>Anomaly Detection Zones</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:174.96pt;">
<div class=block style=" width:174.96pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt;">
<div class=block style=" width:39.84pt; height:24.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:135.12pt;">
<div class=block style=" width:135.12pt; height:24.00pt;">
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 0.72pt; text-align:center;"><span class=font3>Network Device Virtualization</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:174.96pt;">
<div class=block style=" width:174.96pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt;">
<div class=block style=" width:39.84pt; height:24.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:135.12pt;">
<div class=block style=" width:135.12pt; height:24.24pt;">
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 1.20pt; text-align:center;"><span class=font3>Segmentation with VLANs</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:174.96pt;">
<div class=block style=" width:174.96pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt;">
<div class=block style=" width:39.84pt; height:24.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:135.12pt;">
<div class=block style=" width:135.12pt; height:24.00pt;">
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 1.20pt; text-align:center;"><span class=font3>Segmentation with Firewalls</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:174.96pt;">
<div class=block style=" width:174.96pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt;">
<div class=block style=" width:39.84pt; height:24.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:135.12pt;">
<div class=block style=" width:135.12pt; height:24.72pt;">
<div class=paragraph style=" padding:8.16pt 0.00pt 0.00pt 0.72pt; text-align:center;"><span class=font3>Segmentation with VRF/VRF Lite</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:135.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:146.40pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Another isolation technique is maintaining separation between the different network planes. For example, keep the data plane separate from the control and management planes, by also implementing the necessary policies to protect each of them.</span></div>
<div class=paragraph style=" padding:22.56pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Cisco IOS Role-Based CLI Access (CLI Views)</b></span></div>
<div class=paragraph style=" padding:2.88pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can consider the Cisco IOS routers Role-Based CLI Access feature a form of virtualization. This feature, otherwise known as CLI Views, allows you to define a virtual set of operational commands and configuration capabilities that provide selective or partial access to Cisco IOS <b>exec </b>and <b>configuration </b>mode commands. A <i>view </i>is a framework of policies that defines which commands are accepted and which configuration information is visible to the user based on his role.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:87.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>198    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph style=" padding:0.00pt 149.52pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:14.88pt;"><b>NOTE        </b><span class=font44>The following site has detailed information about this feature: <a href="http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a0080455b96.html%23wp1027184">http://www.cisco.com/en/US/products/ps6350/</a></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44><a href="http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a0080455b96.html%23wp1027184">products_configuration_guide_chapter09186a0080455b96.html#wp1027184</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:147.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font8><b>Anomaly Detection Zones</b></span></div>
<div class=paragraph style=" padding:3.12pt 49.44pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Cisco Detector XT and the Cisco Guard XT allow you to configure zones to categorize and define anomaly detection policies for more granularity and customization. The following are examples of zones you can configure within the Cisco traffic anomaly detectors:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Collections of servers or clients</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Collections of routers or other network access devices</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Network links, subnets, or entire networks</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Single users or whole companies</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Internet service providers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.24pt;">
<div class=paragraph style=" padding:0.00pt 56.64pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>The following site provides step-by-step instructions on how to create zones in Cisco Detector and Guard implementations:</span></span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44><a href="http://www.cisco.com/en/US/products/ps5887/products_configuration_guide_chapter09186a00804bee78.html%23wp1043192">http://www.cisco.com/en/US/products/ps5887/</a></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44><a href="http://www.cisco.com/en/US/products/ps5887/products_configuration_guide_chapter09186a00804bee78.html%23wp1043192">products_configuration_guide_chapter09186a00804bee78.html#wp1043192</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:196.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Network Device Virtualization</b></span></div>
<div class=paragraph style=" padding:3.84pt 40.32pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Several networking devices support virtualization. You can take advantage of device virtualization to segment and apply different policies within your infrastructure, while saving money in hardware. For example, you can partition a single hardware device into multiple virtual devices. In most cases, each virtual device acts as an independent device. The following devices support virtualization:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco PIX</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco ASA</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Firewall Services Module (FWSM) for the Catalyst 6500 series switches</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco IPS sensors running version 6.x or later</span></div>
<div class=paragraph style=" padding:2.16pt 51.60pt 0.00pt 111.60pt; text-align:left; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;The Cisco Application Control Engine (ACE) family for the Cisco Catalyst 6500 series switches</span></div>
<div class=paragraph style=" padding:4.08pt 49.44pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Cisco PIX, Cisco ASA, and FWSM can be configured in multiple context mode in which each context has its own security policy, interfaces, and administrators. Having</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:43.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 318.48pt; text-align:justify;"><span class=font4>Isolation and Virtualization <b>199</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 41.76pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">multiple contexts is similar to having multiple standalone devices. Figure 7-12 illustrates how a Cisco FWSM is deployed with three contexts (admin, context-1, and context-2) to segment different servers in a data center).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 296.40pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 7-12 </b><span class=font43><i>Security Contexts in FWSM</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:36.00pt; height:79.44pt; padding:0.00pt 225.36pt 0.00pt 224.64pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-73.jpg" alt="" style=" width:36.00pt; height:79.44pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:360.24pt; height:108.96pt; padding:0.00pt 63.36pt 0.00pt 62.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-74.jpg" alt="" style=" width:360.24pt; height:108.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 52.80pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Many features are supported in Cisco ASA, Cisco PIX, and Cisco FWSM running in multiple-context mode; however, some features are not supported, including VPN and dynamic routing protocols.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 37.20pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>Chapter 10, &quot;Data Center Security,&quot; includes sample configurations of Cisco FWSM virtualization to provide data center security. Chapter 12, &quot;Case Studies,&quot; also has configuration examples of virtualization in Cisco PIX and Cisco ASA security appliances.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><b>Segmentation with VLANs</b></span></div>
<div class=paragraph style=" padding:3.12pt 48.24pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can achieve network segmentation and isolation in many ways. The use of VLANs is one of the most commonly used methods because of its simplicity and ease of deployment. Figure 7-13 illustrates how you can isolate/segment different types of devices just by using VLANs.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>200    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 296.64pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 7-13 </b><span class=font43><i>Segmentation Using VLANs</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:360.00pt; height:158.88pt; padding:0.00pt 63.36pt 0.00pt 62.64pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-75.jpg" alt="" style=" width:360.00pt; height:158.88pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.96pt;">
<div class=paragraph style=" padding:0.00pt 71.52pt 0.00pt 69.84pt; text-align:justify;"><span class=font3>Web Servers&nbsp;Database Servers&nbsp;LDAP Servers Management</span></div>
<div class=paragraph style=" padding:0.24pt 72.24pt 0.00pt 0.00pt; text-align:right;"><span class=font3>Applications</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:239.04pt;">
<div class=paragraph style=" padding:0.00pt 48.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Figure 7-13, a set of web, database, Lightweight Directory Access Protocol (LDAP), and management servers are isolated by simply configuring four separate VLANs (VLANs 10, 20, 30, and 40, respectively).</span></div>
<div class=paragraph style=" padding:22.32pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><b>Segmentation with Firewalls</b></span></div>
<div class=paragraph style=" padding:3.12pt 49.68pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In many situations, you can simply segment or isolate parts of the network, servers, or users by placing firewalls. Firewalls also provide more granular policy enforcement mechanisms. Sometimes you can use firewalls with VLAN segmentation, as illustrated in Figure 7-14.</span></div>
<div class=paragraph style=" padding:6.24pt 39.36pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Figure 7-14, the same servers and the four separate VLANs are configured. In addition, a pair of Cisco ASAs are placed to provide segmentation services while enforcing more granular security policies.</span></div>
<div class=paragraph style=" padding:20.64pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><b>Segmentation with VRF/VRF-Lite</b></span></div>
<div class=paragraph style=" padding:2.88pt 50.88pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">You can also use Multiprotocol Label Switching (MPLS) VPN routing and forwarding (VRF) or the MPLS VRF-Lite feature on Cisco IOS routers for network segmentation purposes. This concept is illustrated in Figure 7-15.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:127.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 318.48pt; text-align:justify;"><span class=font4>Isolation and Virtualization <b>201</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:386.16pt; height:226.56pt; padding:0.00pt 63.36pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-76.jpg" alt="" style=" width:386.16pt; height:226.56pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 7-15 </b><span class=font43><i>Segmentation Using VRF and VRF-Lite</i></span></span></div>
<div class=paragraph style=" padding:8.64pt 217.20pt 0.00pt 0.00pt; text-align:right;"><span class=font4>Cisco ASAs</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:360.00pt; height:140.40pt; padding:0.00pt 63.36pt 0.00pt 62.64pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-77.jpg" alt="" style=" width:360.00pt; height:140.40pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.28pt;">
<div class=paragraph style=" padding:0.00pt 71.52pt 0.00pt 70.08pt; text-align:justify;"><span class=font3>Web Servers&nbsp;Database Servers&nbsp;LDAP Servers Management</span></div>
<div class=paragraph style=" padding:1.44pt 72.24pt 0.00pt 0.00pt; text-align:right;"><span class=font3>Applications</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph style=" padding:0.00pt 42.96pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The main challenge of implementing VRFs and VRF-Lite is that most enterprises do not run MPLS within their corporate network. More importantly, their staffs do not have the skills to implement MPLS because it is a complicated routing technology. This segmentation technique is mainly implemented by service providers.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:48.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>202    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:93.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 41.76pt; text-align:left;"><span class=font11><a href="#bookmark51"><a name="bookmark56"><b>P</b></a><b>olicy Enforcement</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 49.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The last pillar in the SAVE framework defines policy enforcement. You can enforce policy in many ways. Figure 7-16 illustrates some examples of techniques and features that allow you to enforce security policies within your organization:</span></div>
<div class=paragraph style=" padding:8.40pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 7-16 </b><span class=font43><i>Policy Enforcement</i></span></span></div>
<div class=paragraph style=" padding:12.48pt 0.00pt 0.00pt 155.28pt; text-align:left;"><span class=font3>Policy Enforcement</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 177.60pt 0.00pt 232.80pt; text-align:justify;"><span class=font3>Cisco Guard XT MVP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 176.40pt 0.00pt 231.84pt; text-align:justify;"><span class=font3>Control Plane Policing</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 166.32pt 0.00pt 221.52pt; text-align:justify;"><span class=font3>Encryption Policies in IPsec</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 161.28pt 0.00pt 217.20pt; text-align:justify;"><span class=font3>Firewalls, ACLs, Packet Filters</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 171.36pt 0.00pt 226.56pt; text-align:justify;"><span class=font3>NAC Policy Enforcement</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 178.08pt 0.00pt 233.52pt; text-align:justify;"><span class=font3>Policy-based Routing</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 205.44pt 0.00pt 260.40pt; text-align:justify;"><span class=font3>RTBH</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:251.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following examples are illustrated in Figure 7-16.</span></div>
<div class=paragraph style=" padding:6.72pt 38.64pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Cisco Guard XT MVP: </b>With the Cisco Guard XT, you can do per-flow-level attack analysis, identification, and mitigation. This is an example of policy enforcement, because the Cisco Guard XT MVP architecture provides multiple layers of defense that can block attack traffic, while allowing legitimate transactions to pass.</span></div>
<div class=paragraph style=" padding:3.36pt 36.96pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Control Plane Policing: </b>In Chapter 2, you learn best practices when deploying Control Plane Policing (CoPP) in your network. CoPP is also used to enforce predefined policies to protect the control plane of Cisco IOS routers in your network.</span></div>
<div class=paragraph style=" padding:4.08pt 41.52pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Encryption policies: </b>You can enforce security encryption policies that best fit your environment in IPsec site-to-site and remote access VPN tunnels.</span></div>
<div class=paragraph style=" padding:4.08pt 43.44pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Firewalls, packet filters, and ACLs: </b>Firewalls, packet filters, and ACLs (including VLAN ACLs [VACLs] and policy-based ACLs in the Catalyst 6500) are the methods most commonly used to enforce security policies for segmentation and protection of network resources.</span></div>
<div class=paragraph style=" padding:3.84pt 37.92pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;NAC policy enforcement: </b>You can configure NAC Appliance and NAC Framework policies to ensure that only compliant machines can enter the network. Based on your configured policies, you can quarantine and remediate noncompliant machines.</span></div>
<div class=paragraph style=" padding:3.60pt 39.84pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.24pt;"><b>•&nbsp;Policy-based routing (PBR): </b>You can also use PBR on routers and Layer 3 devices to define enforcement policies for traffic within your network.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 324.72pt; text-align:justify;"><span class=font4>Visualization Techniques <b>203</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:197.52pt;">
<div class=paragraph style=" padding:0.00pt 39.36pt 0.00pt 111.60pt; text-align:justify; text-indent:-14.16pt;"><span class=font44 style=" line-height:12.00pt;"><b>• Remotely triggered black holes (RTBH): </b>In previous chapters, you learn how you can block attack traffic or infected hosts using RTBH. RTBH is another example of how you can reactively enforce policies within your network.</span></div>
<div class=paragraph style=" padding:19.44pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font11><a href="#bookmark51"><a name="bookmark57"><b>V</b></a><b>isualization Techniques</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 39.12pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This section includes a few examples of how you can create topology maps and other diagrams to visualize your network resources and apply SAVE. These diagrams give you the basic idea so that you can then customize the diagrams to fit your organizational needs.</span></div>
<div class=paragraph style=" padding:6.00pt 42.24pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can create circular diagrams like the one illustrated in Figure 7-17. Typically, these types of diagrams include resources that surround a critical system or area of the network you want to protect. In Figure 7-17, a cluster of database servers is illustrated in the center of the diagram. Several layers describe the devices in the topology in relation to different sections of the network.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 7-17 </b><span class=font43><i>Topology Map Visualization</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:356.88pt; height:331.68pt; padding:0.00pt 64.56pt 0.00pt 64.56pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-78.jpg" alt="" style=" width:356.88pt; height:331.68pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:42.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>204   </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:177.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The illustration in Figure 7-17 helps you visualize and understand the different layers of protection you can apply within your network to protect the mission-critical systems. The diagram in Figure 7-17 has four major sections that portray the path from and to the protected system and the following sections of the network:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font4><b>1&nbsp;</b><span class=font44>Finance department users</span></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 99.36pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>2&nbsp;</b><span class=font44>Internet</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 99.36pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>3&nbsp;</b><span class=font44>Call Center</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 99.60pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>4&nbsp;</b><span class=font44>Branch Office in Los Angeles, California (LA)</span></span></div>
<div class=paragraph style=" padding:2.88pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can also visualize packet flows and understand how security policies can be applied to each network device to protect critical systems and the infrastructure as a whole. An example is illustrated in Figure 7-18.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 7-18 </b><span class=font43><i>Traffic Flow Visualization</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:356.88pt; height:331.68pt; padding:0.00pt 64.56pt 0.00pt 64.56pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-79.jpg" alt="" style=" width:356.88pt; height:331.68pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:60.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 324.72pt; text-align:justify;"><span class=font4>Visualization Techniques <b>205</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:95.28pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Figure 7-18 illustrates an example of the packet flow when a user from the finance department accesses the Internet. There you can see the devices that these packets touch and the relation to the critical systems.</span></div>
<div class=paragraph style=" padding:6.24pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can identify where you can apply the technologies that belong to each SAVE pillar. For example, Figure 7-19 shows how you can apply technologies that enable you to gain and maintain visibility of what is happening in your network.</span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 7-19 </b><span class=font43><i>Visibility Techniques Applied</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:356.88pt; height:337.20pt; padding:0.00pt 64.56pt 0.00pt 64.56pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-80.jpg" alt="" style=" width:356.88pt; height:337.20pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:51.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Figure 7-19 shows you how you can enable syslog on devices such as the switches, routers, FWSM for the Cisco Catalyst 6500 series switches, and Cisco ASA. It also shows you places where you want to enable NetFlow, IPS services, and other features.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44>Figure 7-20 shows where you can enforce policies to restrict access.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:65.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:64.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:421.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.04pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>206    </b>Chapter 7: Proactive Security Framework</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 277.68pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 7-20 </b><span class=font43><i>Policy Enforcement Visualization</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:356.88pt; height:344.88pt; padding:0.00pt 64.56pt 0.00pt 64.56pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-81.jpg" alt="" style=" width:356.88pt; height:344.88pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:55.20pt;">
<div class=paragraph style=" padding:0.00pt 52.80pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can apply ACLs and IP inspection features on the Cisco ASA and the FWSM. In addition, you can apply VACLs on the access switches and antispoofing and infrastructure ACLs on the Internet router and other routers within the network. You can also enforce strict IPsec policies for the site-to-site connectivity between the main office and the branch office.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:64.56pt;">
<div class=block style=" width:64.56pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 4.80pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:421.44pt;">
<div class=block style=" width:421.44pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 36.96pt 0.00pt 25.44pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Antispoofing and infrastructure ACLs are discussed in Chapter 2, &quot;Preparation Phase.&quot; Chapter 12, &quot;Case Studies,&quot; also provides some examples within the case studies it covers.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:89.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:64.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:421.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 384.24pt; text-align:justify;"><span class=font4>Summary <b>207</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:68.88pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a name="bookmark58">Y</a>ou can also create similar diagrams to visualize where you can apply the technologies and features described on each of the pillars in SAVE. SAVE advocates the understanding of device roles and their appropriate configuration. For example, the Internet edge routers do not have the same role as the other routers within the topology in the previous examples. Despite that, Internet edge routers can be the same model and run the same software versions as other routers, and their configuration should be modeled after their role.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The types of diagrams shown in Figures 7-18, 7-19, and 7-20 are not limited to only these technologies, features, and applications. You can customize them to your specific needs.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:105.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font11><a href="#bookmark51"><b>Summary</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">SAVE is a framework that was initially developed for service providers, but you can apply its practices to any organization. This chapter covers SAVE in detail. Examples of technologies within the six SAVE main categories are discussed. Visibility and control are two of the most important topics and concepts within SAVE. This chapter provides examples of techniques and practices that can allow you to gain and maintain visibility and control over the network during normal operations or during the course of a security incident or an anomaly in the network.</span></div>
</div>
</td>
]]></content:encoded>
			<wfw:commentRss>http://ciscoasa.org.ua/2010/02/chapter-7-proactive-security-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter 6: Postmortem and Improvement</title>
		<link>http://ciscoasa.org.ua/2010/02/chapter-6-postmortem-and-improvement/</link>
		<comments>http://ciscoasa.org.ua/2010/02/chapter-6-postmortem-and-improvement/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 22:41:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[budget]]></category>
		<category><![CDATA[device configuration]]></category>
		<category><![CDATA[gaps]]></category>
		<category><![CDATA[improvements]]></category>
		<category><![CDATA[incident data]]></category>
		<category><![CDATA[incident response team]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[new security]]></category>
		<category><![CDATA[postmortem]]></category>
		<category><![CDATA[security incident]]></category>
		<category><![CDATA[security threats]]></category>
		<category><![CDATA[technology solutions]]></category>

		<guid isPermaLink="false">http://ciscoasa.org.ua/?p=256</guid>
		<description><![CDATA[

After any security incident, you should hold a postmortem. At this postmortem, you should look at the full chronology of events that took place during the incident. This chapter includes common best practices when documenting a security incident postmortem.
The postmortem is one of the most critical steps in incident management. The development of the postmortem [...]]]></description>
			<content:encoded><![CDATA[<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:165.12pt;">
<div class=paragraph style=" padding:0.00pt 36.96pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">After any security incident, you should hold a postmortem. At this postmortem, you should look at the full chronology of events that took place during the incident. This chapter includes common best practices when documenting a security incident postmortem.</span></div>
<div class=paragraph style=" padding:6.00pt 36.72pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The postmortem is one of the most critical steps in incident management. The development of the postmortem should be based on analysis of the gaps that enabled a security incident to occur and resulting recommendations for improvements. These recommendations will impact your policies, processes, standards, and guidelines. They will also indirectly impact people—your staff and other personnel. Based on gap analysis, you should design and implement solutions as necessary.</span></div>
<div class=paragraph style=" padding:6.00pt 36.96pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Postmortems can also help you justify increases to your budget for technology solutions that can help you avoid damage that you experienced during the incident. This is why it is important that you identify all weaknesses and holes in systems, infrastructure defenses, or policies that allowed the incident to take place.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:155.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 37.68pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Collected Incident Data</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 36.96pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The postmortem is one of the most important parts of incident response and is also the part that is most often omitted. As mentioned in the previous chapter, documenting events that occurred during the previous phases (identification, classification, traceback, and reaction) is important to effectively create a good postmortem following a security incident. The collection of this data is important because it can be used for future improvement in the process, policies, and device configuration. This data can also be used to calculate the cost and the total hours of involvement and may help you justify additional funding of the incident response team.</span></div>
<div class=paragraph style=" padding:6.00pt 37.68pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This also can help you to understand changes in new security threats and trends. You can use the data and lessons learned from the postmortem as input to improve security policies, processes, and system configurations. This is illustrated in Figure 6-1.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:105.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:84.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:311.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 256.08pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>168    </b>Chapter 6: Postmortem and Improvement</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 288.00pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 6-1    </b><span class=font43><i>Postmortem Looped Feedback</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:240.96pt; height:212.88pt; padding:0.00pt 122.88pt 0.00pt 122.16pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-61.jpg" alt="" style=" width:240.96pt; height:212.88pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:42.24pt;">
<div class=paragraph style=" padding:0.00pt 39.60pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Try to address the &quot;who, what, how, when, why&quot; questions in your postmortem. Table 6-1 demonstrates this approach.</span></div>
<div class=paragraph style=" padding:11.28pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4><b>Table 6-1      </b><span class=font43><i>Typical Questions Answered in a Postmortem</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:236.88pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:236.88pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:291.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt;">
<div class=block style=" width:70.08pt; height:22.56pt;">
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Type</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:291.12pt;">
<div class=block style=" width:291.12pt; height:22.56pt;">
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Question</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt;">
<div class=block style=" width:70.08pt; height:93.84pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Who</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:291.12pt;">
<div class=block style=" width:291.12pt; height:93.84pt;">
<div class=paragraph style=" padding:1.68pt 159.12pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:14.88pt;">Who was affected by this incident? Who reported the incident? Were the right people engaged? Were customers impacted? Were partners impacted?</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:14.88pt;">Was communication between staff and other teams appropriate?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt;">
<div class=block style=" width:70.08pt; height:120.48pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>What</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:291.12pt;">
<div class=block style=" width:291.12pt; height:120.48pt;">
<div class=paragraph style=" padding:1.44pt 116.88pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:15.12pt;">What systems were affected by this incident? What processes were affected by this incident?</span></div>
<div class=paragraph style=" padding:1.68pt 33.60pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">What tools were used to identify, classify, trace back, and mitigate the incident?</span></div>
<div class=paragraph style=" padding:2.16pt 196.32pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:14.88pt;">What worked well? What did not work well?</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:14.88pt;">What were the key lessons learned from the incident?</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:14.88pt;">What other contingency plans in the organization could be applied?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:291.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:50.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 330.00pt; text-align:justify;"><span class=font4>Collected Incident Data <b>169</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 187.68pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>Table 6-1      </b><span class=font43><i>Typical Questions Answered in a Postmortem (Continued)</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:195.84pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:195.84pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:291.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt;">
<div class=block style=" width:70.08pt; height:22.32pt;">
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Type</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:291.12pt;">
<div class=block style=" width:291.12pt; height:22.32pt;">
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Question</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt;">
<div class=block style=" width:70.08pt; height:75.12pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>How</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:291.12pt;">
<div class=block style=" width:291.12pt; height:75.12pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>How was the incident first identified?</span></div>
<div class=paragraph style=" padding:5.04pt 41.76pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">How could the recovery process have been shortened after a fix was identified?</span></div>
<div class=paragraph style=" padding:1.68pt 85.44pt 0.00pt 6.24pt; text-align:left;"><span class=font43 style=" line-height:15.12pt;">How effective was the incident diagnosis and response? How effective was the communication process?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt;">
<div class=block style=" width:70.08pt; height:48.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>When</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:291.12pt;">
<div class=block style=" width:291.12pt; height:48.96pt;">
<div class=paragraph style=" padding:1.68pt 146.88pt 0.00pt 6.24pt; text-align:left; text-indent:-0.24pt;"><span class=font43 style=" line-height:14.88pt;">When was the incident first identified? When was the incident first reported? When was the incident mitigated?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt;">
<div class=block style=" width:70.08pt; height:49.44pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Why</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:291.12pt;">
<div class=block style=" width:291.12pt; height:49.44pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:14.88pt;">Why did a procedure fail?</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:14.88pt;">Why was a procedure difficult to implement?</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font43 style=" line-height:14.88pt;">Why was your methodology successful?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:70.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:291.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:225.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The answers to questions like those included in Table 6-1 should be collected in a collaborative effort between the team members who help on the identification, classification, traceback, and reaction phases. Keep in mind that if you ask questions that are too broad, you may have different perspectives within your staff. This is not necessarily a problem; however, you want to collect clear and concrete facts. If you ask questions that are too narrow, you may end up limiting the input and information that you can collect and analyze from your team experience during the incident. On the other hand, you should collect data that is clear and concrete, rather than collecting data simply because it is available and may be incorrect.</span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The analysis of the data collected in the postmortem will also help you to measure the success of the incident response team. However, the postmortem process will fail miserably if the problem review board is used as a forum to point fingers at specific staff members or organizational divisions. The most important thing is to understand that the data collected in the initial stage of the postmortem helps you organize a list of lessons learned during the incident.</span></div>
<div class=paragraph style=" padding:6.24pt 43.68pt 0.00pt 89.52pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Figure 6-2 shows the first part of a basic incident response report and postmortem. In this example, Joe Doe from a fictitious company called SecureMe is the author of the report.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:129.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:658.80pt; height:486.00pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt;">
<div class=block style=" width:658.80pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt;">
<div class=block style=" width:487.20pt; height:411.36pt; padding:0.00pt 97.68pt 0.00pt 73.92pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:487.20pt; height:411.36pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:14.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:222.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:6.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:6.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:139.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:17.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:80.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:487.20pt;">
<div class=block style=" width:487.20pt; height:18.00pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 114.48pt; text-align:left;"><span class=font4>SecureMe, Inc. Incident Response Report and Postmortem</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:487.20pt;">
<div class=block style=" width:487.20pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:11.76pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font3>Reported by: Joe Doe</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:11.76pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>Date: 07/05/2009</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:11.04pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font3>Phone: (555) 123-1234</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:11.04pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>Email: <a href="mailto:jdoe@somedomain.com">jdoe@somedomain.com</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:11.04pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font3>Date of Incident: 07/04/2009</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:11.04pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font3>Time of Incident: 9:30 a.m. EST</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:12.24pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font3>Incident ID (if applicable): CSIRT-987654321</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:12.24pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>External Service Request (If applicable): 601234569</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:487.20pt;">
<div class=block style=" width:487.20pt; height:10.32pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:487.20pt;">
<div class=block style=" width:487.20pt; height:37.20pt;">
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font3>Incident Summary:</span></div>
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font3>Numerous ICMP packets were sent by an unauthorized system to a sales e-commerce web-server farm.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:70.56pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font3 style=" line-height:9.36pt;">How was it discovered?</span></div>
<div class=paragraph style=" padding:0.00pt 43.20pt 0.00pt 4.80pt; text-align:left; text-indent:-1.20pt;"><span class=font3 style=" line-height:9.36pt;">Abnormal behavior was noticed from CS-MARS incident using Netflow data. An automatic e-mail notification from the system was received at 9:30 a.m.</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:70.56pt;">
<div class=paragraph style=" padding:2.64pt 71.52pt 0.00pt 3.12pt; text-align:left; text-indent:-0.24pt;"><span class=font3 style=" line-height:9.36pt;">What actions and technical mitigation have been taken?</span></div>
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 3.12pt; text-align:left; text-indent:-0.24pt;"><span class=font3 style=" line-height:9.36pt;">The source of attack was confirmed by using Netflow data and CS-MARS reports. An access control list was deployed at the Internet edge router to mitigate the attack.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:487.20pt;">
<div class=block style=" width:487.20pt; height:12.96pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font3>Select the type of incident:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:12.96pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 5.52pt; text-align:left;"><span class=font3>X</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:222.48pt;">
<div class=block style=" width:222.48pt; height:12.96pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>Denial of Service Attack</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:12.24pt;">
<div class=block style=" width:12.24pt; height:12.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:139.20pt;">
<div class=block style=" width:139.20pt; height:12.96pt;">
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>Unauthorized Application Access</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:17.52pt;">
<div class=block style=" width:17.52pt; height:12.96pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:12.96pt;">
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font3>Other</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:222.48pt;">
<div class=block style=" width:222.48pt; height:12.24pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font3>Worm or Virus</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:12.24pt;">
<div class=block style=" width:12.24pt; height:12.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:139.20pt;">
<div class=block style=" width:139.20pt; height:12.24pt;">
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font3>Website Defacement</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:98.40pt;">
<div class=block style=" width:98.40pt; height:12.24pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 23.04pt; text-align:left;"><span class=font3>(please specify):</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:11.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:222.48pt;">
<div class=block style=" width:222.48pt; height:11.76pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font3>Theft of information data</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:12.24pt;">
<div class=block style=" width:12.24pt; height:11.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:139.20pt;">
<div class=block style=" width:139.20pt; height:11.76pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>Identity Theft</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:98.40pt;">
<div class=block style=" width:98.40pt; height:11.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:12.48pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font3>List all the systems that were affected:</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:12.48pt;">
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>List all departments or business units that were affected:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:34.80pt;">
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font3>Sales e-Commerce web servers</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:34.80pt;">
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font3>Sales Department</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:34.56pt;">
<div class=paragraph style=" padding:1.68pt 57.36pt 0.00pt 7.20pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">Where any of the affected systems mission critical? [X] Yes   [ ] No</span></div>
</div>
</td>
<td class=cell colspan="4" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:34.56pt;">
<div class=paragraph style=" padding:2.88pt 77.04pt 0.00pt 3.12pt; text-align:left; text-indent:-0.24pt;"><span class=font3 style=" line-height:9.36pt;">Was the source of the attack/incident spoofed? [ ] Yes   [x] No</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:487.20pt;">
<div class=block style=" width:487.20pt; height:12.96pt;">
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font3>What was the source?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:12.72pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 5.52pt; text-align:left;"><span class=font3>X</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:222.48pt;">
<div class=block style=" width:222.48pt; height:12.72pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font3>External unauthorized user</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:12.24pt;">
<div class=block style=" width:12.24pt; height:12.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:139.20pt;">
<div class=block style=" width:139.20pt; height:12.72pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>Former employee</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:17.52pt;">
<div class=block style=" width:17.52pt; height:12.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:80.88pt;">
<div class=block style=" width:80.88pt; height:12.72pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.00pt; text-align:left;"><span class=font3>Other</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:12.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:222.48pt;">
<div class=block style=" width:222.48pt; height:12.48pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font3>Internal employee (full time)</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:12.24pt;">
<div class=block style=" width:12.24pt; height:12.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:139.20pt;">
<div class=block style=" width:139.20pt; height:12.48pt;">
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>Internal guest</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:98.40pt;">
<div class=block style=" width:98.40pt; height:12.48pt;">
<div class=paragraph style=" padding:3.60pt 0.00pt 0.00pt 23.04pt; text-align:left;"><span class=font3>(please specify):</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:13.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:222.48pt;">
<div class=block style=" width:222.48pt; height:13.44pt;">
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font3>Contractor</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:12.24pt;">
<div class=block style=" width:12.24pt; height:13.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:139.20pt;">
<div class=block style=" width:139.20pt; height:13.44pt;">
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>Unknown</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:98.40pt;">
<div class=block style=" width:98.40pt; height:13.44pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="7" valign="top" style=" width:487.20pt;">
<div class=block style=" width:487.20pt; height:36.00pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 7.20pt; text-align:left;"><span class=font3>Was law enforcement contacted? [ ] Yes   [x] No</span></div>
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font3>If yes, what department (i.e., local enforcement, FBI, etc):</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:14.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:222.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:6.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:6.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:139.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:17.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:80.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt;">
<div class=block style=" width:658.80pt; height:37.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:658.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 250.32pt; text-align:justify;"><span class=font4>Root-Cause Analysis and Lessons Learned <b>171</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:163.20pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;"><a name="bookmark45">I</a>n Figure 6-2, a member of the SecureMe incident response team reports that numerous ICMP packets were sent to a web server farm that is part of an e-commerce solution that belongs to its sales department. The fields on the form include most of the questions listed in Table 6-1. Figure 6-2 is merely a basic example. You can expand this form by incorporating more detailed information that is appropriate for your environment and organization, such as the following:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Total person-hours spent working on the incident</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Elapsed time from the beginning of the incident to its resolution</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Elapsed time for each stage of the incident handling process</span></div>
<div class=paragraph style=" padding:1.92pt 39.12pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Total hours spent by the incident response team in responding to the initial report of the incident</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Estimated monetary damage from the incident</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:25.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:300.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Root-Cause Analysis and Lessons Learned</b></a></span></div>
<div class=paragraph style=" padding:3.84pt 42.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Always remember that &quot;lessons learned&quot; is knowledge or understanding gained by experience (in this case, by the experience during the security incident). The Lessons Learned section in your postmortem should focus on identifying incremental and innovative improvements that will measurably improve the following areas of the organization:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Processes and policies</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Technology and configurations</span></div>
<div class=paragraph style=" padding:4.56pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The postmortem should include both negative and positive experiences. You should highlight the recurrence of successful outcomes while helping to prevent the recurrence of unsuccessful outcomes.</span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Lessons Learned section in the postmortem will also help you to improve your risk management processes. You can incorporate these lessons learned into several areas of risk management. One of the key inputs to risk identification is historical information. An input to both qualitative and quantitative risk analysis is identified risks, which can be obtained in your postmortem. Each incident response team should evolve to reflect new threats, improved technology, and lessons learned.</span></div>
<div class=paragraph style=" padding:6.00pt 36.72pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">You should establish criteria for a lessons learned process. More importantly, you should turn &quot;lessons learned&quot; into &quot;applied lessons.&quot; The following section gives you tips on how to build an action plan from the lessons learned during each phase of the incident response.</span></div>
<div class=paragraph style=" padding:6.24pt 38.64pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Figure 6-3 shows the Lessons Learned section of the SecureMe Incident Response Report and Postmortem.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:87.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 256.08pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>172    </b>Chapter 6: Postmortem and Improvement</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 270.72pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 6-3   </b><span class=font43><i>Lessons Learned Section of Report</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.44pt;">
<div class=paragraph style=" padding:0.00pt 112.80pt 0.00pt 112.08pt; text-align:center;"><span class=font4 style=" line-height:12.00pt;">SecureMe, Inc. Incident Response Report and Postmortem Lessons Learned</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 102.72pt 0.00pt 76.32pt; text-align:justify;"><span class=font3>Success stories (describe what good, repeatable practices and procedures took place):</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 75.60pt 0.00pt 76.56pt; text-align:justify;"><span class=font3>How well did the incident response staff and management perform in dealing with the incident?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 144.00pt 0.00pt 75.84pt; text-align:justify;"><span class=font3>Were the documented procedures followed? Explain if they were adequate.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 273.84pt 0.00pt 75.84pt; text-align:justify;"><span class=font3>What information was needed sooner?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 141.36pt 0.00pt 75.84pt; text-align:justify;"><span class=font3>What should be done differently the next time a similar incident takes place?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 175.44pt 0.00pt 75.84pt; text-align:justify;"><span class=font3>What corrective actions can prevent similar incidents in the future?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 236.88pt 0.00pt 75.84pt; text-align:justify;"><span class=font3>What additionally tools or resources are needed?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:137.28pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The questions and information in the form outlined in Figure 6-3 are just examples of the items you can incorporate within your Lessons Learned section in your postmortem. In addition, you can build a rating system of different areas within your incident response ecosystem. For instance, you can list several areas under several major sections, such as the following:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Tools and resources</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Incident response policies and processes</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Incident response team</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Timeliness of resolution</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Collaboration with other teams</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:109.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 330.72pt; text-align:justify;"><span class=font4>Building an Action Plan <b>173</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:107.04pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Under each of these categories, you can list more detailed items or subcategories and then rate them. You can use a simple scale from 1 to 5, such as the following:</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 99.84pt; text-align:left;"><span class=font4><b>1&nbsp;</b><span class=font44>Poor</span></span></div>
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 99.36pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>2&nbsp;</b><span class=font44>Needs improvement</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 99.36pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>3&nbsp;</b><span class=font44>Average</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 99.60pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>4&nbsp;</b><span class=font44>Good</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 99.36pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>5&nbsp;</b><span class=font44>Excellent</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:11.76pt;"><a name="bookmark46"><b>N</b></a><b>OTE        </b><span class=font44>The rating system outlined here is just an example. The numbering scheme should be based on the needs of your organization.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:299.28pt;">
<div class=paragraph style=" padding:0.00pt 44.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">At the end of this phase, you can calculate an overall average and use metrics to rate the effectiveness of your incident response process and resources.</span></div>
<div class=paragraph style=" padding:23.52pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Building an Action Plan</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 42.72pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">After you have collected all necessary information and documented the different lessons learned, you should build a comprehensive action plan to address any deficiencies in processes, policies, or technology. Some underlying causes may remain unknown at the time of the initial post-incident meetings; however, you can capture these causes as open action items to be closed when you have completed your final research.</span></div>
<div class=paragraph style=" padding:6.00pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Prioritize the gaps identified to make sure that you address the most critical first. In addition, understand the root cause of gaps and problems identified. One aspect that sometimes gets lost in the incident postmortems is exploring the reasons for the problems identified. If you do not pay attention to underlying causes, you may fix specific problems and improve particular procedures; however, you will likely encounter different consequences of the same fundamental errors that caused those particular problems.</span></div>
<div class=paragraph style=" padding:6.24pt 48.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">When you build an improvement plan based on the information collected in the lessons learned, each action item should have the following (at the very minimum):</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Clear description</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Person assigned</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Due date for follow-up</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Priority</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:82.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:171.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:96.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:86.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:132.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 256.08pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>174   </b>Chapter 6: Postmortem and Improvement</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:75.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.24pt;">This reduces risks that could develop if you fail to follow up on items that can present future threats. This concept is illustrated in Figure 6-4.</span></div>
<div class=paragraph style=" padding:9.12pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><a name="bookmark47"><b>F</b></a><b>igure 6-4   </b><span class=font43><i>Action Items</i></span></span></div>
<div class=paragraph style=" padding:27.60pt 1.68pt 0.00pt 0.00pt; text-align:center;"><span class=font3>Action Item</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:60.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:171.36pt;">
<div class=block style=" width:171.36pt; height:28.32pt;">
<div class=paragraph style=" padding:0.00pt 21.12pt 0.00pt 88.32pt; text-align:center;"><span class=font3 style=" line-height:9.60pt;">Clear, Detailed Description of the Gap Identified</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:96.00pt;">
<div class=block style=" width:96.00pt; height:28.32pt;">
<div class=paragraph style=" padding:9.60pt 36.00pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>Person Assigned</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:86.40pt;">
<div class=block style=" width:86.40pt; height:28.32pt;">
<div class=paragraph style=" padding:10.56pt 53.76pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>Due Date</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:132.24pt;">
<div class=block style=" width:132.24pt; height:28.32pt;">
<div class=paragraph style=" padding:10.56pt 108.24pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>Priority</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:41.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:156.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Summary</b></a></span></div>
<div class=paragraph style=" padding:3.84pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">It is highly recommended that your Computer Security Incident Response Team (CSIRT) perform a postmortem after any security incident. This postmortem should identify the strengths and weaknesses of the incident response effort. With this analysis, you can identify weaknesses in systems, infrastructure defenses, or policies that allowed the incident to take place. In addition, the postmortem can help you identify problems with communication channels, interfaces, and procedures that hampered the efficient resolution of the reported problem.</span></div>
<div class=paragraph style=" padding:6.00pt 44.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This chapter offered you several tips on how to create effective postmortems and how to execute post-incident tasks. It included guidelines for collecting post-incident data, documenting lessons learned during the incident, and building action plans to close any gaps that are identified.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:215.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:171.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:96.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:86.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:132.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.32pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 383.76pt; text-align:justify;"><span class=font4>Summary <b>175</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:116.88pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">It is worth mentioning that many individuals claim to always conduct post-incident analysis; however, they rarely execute and close the gaps identified. Always make sure that you follow up an incident by addressing all the gaps and communicating the lessons learned to other members of the organization. Follow up by educating employees, especially the incident coordinators. Having a group of people who know all the processes and who can guide the various departments of the company to cooperate in response to an issue is important. Work with incident coordinators to fix processes or create new ones. Incident coordinators may also be able to help educate the rest of the company on these processes. You definitely want everyone in the organization to understand at least where to report a suspected problem or concern.</span></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://ciscoasa.org.ua/2010/02/chapter-6-postmortem-and-improvement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter 5: Reacting to Security Incidents</title>
		<link>http://ciscoasa.org.ua/2010/02/chapter-5-reacting-to-security-incidents/</link>
		<comments>http://ciscoasa.org.ua/2010/02/chapter-5-reacting-to-security-incidents/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 22:34:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[appropriate response]]></category>
		<category><![CDATA[critical factors]]></category>
		<category><![CDATA[ddos attack]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[facets]]></category>
		<category><![CDATA[outbreak]]></category>
		<category><![CDATA[policies and procedures]]></category>
		<category><![CDATA[response mechanisms]]></category>
		<category><![CDATA[response procedures]]></category>
		<category><![CDATA[security incidents]]></category>
		<category><![CDATA[security policy]]></category>

		<guid isPermaLink="false">http://ciscoasa.org.ua/?p=254</guid>
		<description><![CDATA[Reacting to security incidents can be an overwhelming and difficult task if you are not prepared. This chapter covers several best practices, techniques, and tips for use when reacting to security incidents. In the previous chapters, you learned how to identify, classify, and trace security incidents. Without successful identification, classification, and traceback, you will never [...]]]></description>
			<content:encoded><![CDATA[<div class=paragraph style=" padding:0.00pt 37.44pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Reacting to security incidents can be an overwhelming and difficult task if you are not prepared. This chapter covers several best practices, techniques, and tips for use when reacting to security incidents. In the previous chapters, you learned how to identify, classify, and trace security incidents. Without successful identification, classification, and traceback, you will never be able to effectively react to any security event. Therefore, it is important that you understand the topics covered in previous chapters before reading this one.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:305.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 37.44pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Adequate Incident-Handling Policies and Procedures</b></a></span></div>
<div class=paragraph style=" padding:3.12pt 37.20pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The steps you take when reacting to security incidents depend on the type of threat you are mitigating. For example, if you are mitigating a distributed denial-of-service (DDoS) attack, you will probably not take the same steps as when reacting to a theft of information where the attacker does not make that much noise on the network. However, when reacting to any security incident, time is one of the most critical factors.</span></div>
<div class=paragraph style=" padding:6.24pt 36.96pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">It is extremely important to have well-defined incident handling policies in place. In Chapter 2, &quot;Preparation Phase,&quot; you learned that without defined policies and procedures for mitigation, you can put yourself in a difficult position when a security outbreak or event occurs. Following these policies or procedures is important.</span></div>
<div class=paragraph style=" padding:6.00pt 37.44pt 0.00pt 90.72pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">These policies may be in the form of standalone documentation, or they may be incorporated into other documentation such as company security policies or disaster recovery plans. You may consider developing different procedures and response mechanisms when responding to a direct DDoS attack versus a worm outbreak, or when information has been stolen. Not all security incidents are the same, and you should make sure that the appropriate response procedures are in place.</span></div>
<div class=paragraph style=" padding:6.00pt 60.00pt 0.00pt 91.20pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You should try to create a security policy and be serious about covering all facets of security. Ideally, you should develop security policies in the preparation phase.</span></div>
<div class=paragraph style=" padding:6.00pt 37.44pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Collaboration between support teams within your organization may be necessary when responding to security incidents. After you have successfully identified a security incident, classified it, and tracked it, you must notify the appropriate personnel. For example, if you are a member of the Information Security (InfoSec) or Security Operations (OpSec) team, you may need to involve administrators from separate parts of your organization. You may</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:51.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:84.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:311.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>154   </b>Chapter 5: Reacting to Security Incidents</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:506.88pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">not have access to the affected device or may not be an expert on a specific application. This is why collaboration is so important.</span></div>
<div class=paragraph style=" padding:6.00pt 39.36pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The reason for setting up collaboration between support teams is to establish lines of communication and ensure that personnel understand the areas of responsibility and capability for each partner. In addition, you should provide a detailed description of the incidents technical aspects to your collaborative teams. This will aid in prompt acknowledgment and understanding of the problem. However, great care should be taken, because you do not want to distribute sensitive information unnecessarily.</span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You should also have adequate emergency procedures in place. In some cases, you may need to discuss issues and tasks within external teams. For example, suppose that you are a member of the OpSec group and you are trying to get information about a specific system that an external team controls. After several attempts, you have received no response. With the correct escalation procedures in place, the task of getting the right people involved becomes easier. Similarly, you should have emergency procedures when other teams try to engage your staff. The main goal of incident response is to restore control of the network and its systems and to limit the impact and damage. Many people say that, in some cases, shutting down affected systems or disconnecting the system from the network may the only practical solution. However, if you have the necessary tools in place, you may be able to quarantine and remediate such systems without unplugging them from the network. For example, you can use routing as a security mechanism and isolate systems within your network. You can use mechanisms such as remotely triggered blackholes (discussed later in this chapter) and in other cases put systems in quarantine segments so that you can patch them accordingly when security outbreaks occur.</span></div>
<div class=paragraph style=" padding:6.24pt 38.16pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Having a systematic approach for patch management is crucial. For instance, if you have a good system in place to provide security operating system and application patches as soon as they become available, your systems are far less likely to fall prey to major attacks. An updated security management system is not a top priority for many companies; however, attackers, worms, and malware do not wait for you to patch every system manually. More importantly, in the case of worm outbreaks, having a distributed patch management system can save you and your staff considerable time thereby saving your organization money.</span></div>
<div class=paragraph style=" padding:6.00pt 38.88pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">It is important to create checklists of procedures to be followed during an incident. Documenting events as they happen is important. On most occasions, you may feel as if you do not have time to completely document events in detail during the incident. However, during the identification, classification, and traceback phases, you should gather as much information about the incident as possible. Attempt to answer the following questions:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;What type of incident are you experiencing?</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;When did the attack occur (date and time)?</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Where did the attack occur?</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;What systems were affected and compromised?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:69.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 311.76pt; text-align:justify;"><span class=font4>Laws and Computer Crimes <b>155</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 51.36pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:11.76pt;"><a name="bookmark39"><b>N</b></a><b>OTE        </b><span class=font44>Chapter 6, &quot;Postmortem and Improvement,&quot; includes examples of these checklists and incident response reports.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:290.88pt;">
<div class=paragraph style=" padding:0.00pt 52.56pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.24pt;">These are some of the most fundamental questions that need to be answered. You may develop more specific questions on a case-by-case basis.</span></div>
<div class=paragraph style=" padding:5.52pt 37.92pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Another procedure that you must document is when to involve law enforcement. Incident response is probably one of the disciplines most affected by legal considerations because many incidents involve some sort of crime. Consequently, your organization might want to prosecute the attacker, and in this case, it must consider the legal implications of the incident. If legal implications are present, you must assist law enforcement in all aspects of their investigation. Different laws and regulations are covered in the next section.</span></div>
<div class=paragraph style=" padding:21.60pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Laws and Computer Crimes</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 40.32pt 0.00pt 89.52pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In most cases, United States and international laws might affect or impact the incident response process. If you want to prosecute an attacker, you might merely have to contact local authorities. In some cases, however, you will need to contact the Federal Bureau of Investigation or equivalent organizations in other countries, especially when dealing with attacks that involve international boundaries. International and inter-jurisdictional cooperation is difficult. What is illegal in one country may not be in another.</span></div>
<div class=paragraph style=" padding:6.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Typically, you have three different options. The first option is to mitigate the problem and move on. The second is to prosecute the attacker in his own country (assuming that the security event you experienced is illegal in that country). The third option is to apply for extradition and prosecute the offender in the country where the incident happened. If you opt for the second or third option, you should seek assistance from your local authorities.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph style=" padding:0.00pt 49.20pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The procedures and circumstances for engaging law enforcement depend on your local laws. International laws may also apply.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The U.S. laws distinguish between crimes <i>against </i>computers and crimes <i>involving </i>computers. For example, a DDoS or a person gaining unauthorized access to a computer or network is classified as a crime &quot;against a computer.&quot; On the other hand, if a person commits an assault against someone else or any other felony in which a computer was only the tool used to commit the crime, this is classified as a crime &quot;involving a computer.&quot;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:75.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>156    </b>Chapter 5: Reacting to Security Incidents</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The &quot;Computer Fraud and Abuse Act&quot; is the standard statute covering computer crimes in the United States. This was initially introduced in 1986 and updated ten years later in 1996. Title 18, Section 1030, covers crimes against computers.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 42.00pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><a name="bookmark40"><b>N</b></a><b>OTE        </b><span class=font44>You can access Title 18, Section 1030 at the Cornell University Law School website at <a href="http://www4.law.cornell.edu/uscode/html/uscode18/usc_sec_18_00001030----000-.html">http://www4.law.cornell.edu/uscode/html/uscode18/usc_sec_18_00001030—000-.html.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:117.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The U.S. Department of Justice has a website where you can obtain specific information on who to contact when reporting a security incident. You can access the website at <a href="http://www.cybercrime.gov/reporting.htm">http://www.cybercrime.gov/reporting.htm.</a></span></div>
<div class=paragraph style=" padding:6.00pt 78.72pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">An excellent document titled &quot;Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations&quot; can be accessed at <a href="http://www.cybercrime.gov/s&#038;smanual2002.htm">http://www.cybercrime.gov/s&amp;smanual2002.htm.</a></span></div>
<div class=paragraph style=" padding:6.24pt 43.44pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Another initiative by the U.S. government is the Internet Crime Complaint Center (IC3). IC3 is a partnership between the Federal Bureau of Investigation (FBI) and the National White Collar Crime Center (NW3C). The website is <a href="http://www.ic3.gov">http://www.ic3.gov.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:69.12pt;">
<div class=paragraph style=" padding:0.00pt 43.20pt 0.00pt 36.00pt; text-align:justify;"><span class=font4 style=" line-height:12.00pt;"><b>TIP&nbsp;</b><span class=font44><i>Infragard </i>is an organization that is the product of a collaborative effort between the FBI,</span></span></div>
<div class=paragraph style=" padding:0.00pt 39.84pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">local enforcement agencies, and private organizations. It has created Special Interest Groups (SIGs), which are resources dedicated to the safeguarding of specific critical infrastructures of both private industry and government through information-sharing networks and a private secure portal of communication. You can obtain more information about Infragard and local chapters at <a href="http://www.infragard.net">http://www.infragard.net</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:136.08pt;">
<div class=paragraph style=" padding:0.00pt 40.08pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">If you work in the health care industry, you should be aware of several new regulations, such as the Health Industry Portability and Accountability Act (HIPAA). The act requires all persons with access to this information to take reasonable care to protect the integrity and confidentiality of patient data. Not only hospitals and health care facilities, but also insurers are now implementing security safeguards and completing risk assessments to ensure the privacy of patients.</span></div>
<div class=paragraph style=" padding:23.28pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Security Incident Mitigation Tools</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 38.16pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">This section includes several tools and techniques that you can use when mitigating security incidents, such as DDoS and worm outbreaks.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:70.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 292.56pt; text-align:justify;"><span class=font4>Security Incident Mitigation Tools <b>157</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>TIP&nbsp;</b><span class=font44>The mitigation technique and enforcement depends on your network architecture and</span></span></div>
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">design. This section covers the most common techniques. As a rule of thumb, you want to base your mitigation operations as close as possible to the source of the attack.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:224.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font8><b>Access Control Lists (ACL)</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">When you react to a DDoS or to a worm outbreak, one of the most important matters is how fast you can quarantine and isolate the problem. <i>Quarantining </i>is the process of identifying all infected machines and blocking them from the network to prevent them from infecting other systems (in case of a worm outbreak). The easiest way to quarantine or block systems is by using router and firewall access control lists (ACL) and VLAN ACLs (or VACL) on Cisco switches. VACLs allow port-level filtering on a VLAN basis. In most cases, VACLs are more feasible when blocking an infected machine. VACLs are applied directly on the switch port, thereby enabling you to do per-host filtering.</span></div>
<div class=paragraph style=" padding:5.76pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">It is extremely important that you be familiar with your network topology and understand how all the VLANs are configured. It is a best practice to document the devices (or at least the device types) that reside within each VLAN. This will be extremely helpful to you when you are in the mitigating phase of your reaction to attacks and worm outbreaks.</span></div>
<div class=paragraph style=" padding:5.76pt 41.52pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.24pt;">Another best practice is to prioritize your network resources and critical systems. During the reaction phase, you should protect the most critical systems first.</span></div>
<div class=paragraph style=" padding:5.52pt 79.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">For more information on tools that can be used for asset management and asset classification, see Chapter 7, &quot;Proactive Security Framework.&quot;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>TIP&nbsp;</b><span class=font44>The Cisco Catalyst 6000 series of switches has a switching engine known as a Policy</span></span></div>
<div class=paragraph style=" padding:0.00pt 50.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Feature Card (PFC) that contains specialized application-specific integrated circuits (ASIC) that enable the blocking of traffic to occur at close to wire speed on the switch.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:111.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">One of the major problems with ACLs and VACLs is that you must apply them throughout the network quickly. You can use tools such as the Cisco Security Manager (CSM) to deploy ACLs quickly in your network. You can also use commercial tools such as OpsWare, and</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font44>SolSoft.</span></div>
<div class=paragraph style=" padding:6.96pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Many security administrators allocate a range of extended ACL numbers that can be dynamically used when mitigating security incidents. For instance, you can assign 190 to 199 for security reaction ACLs, if this range is not in use anywhere else in your network. Some people recommend configuring, on each network, a dummy list device which is well documented with a detailed description so that staff will know that this ACL is reserved</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:66.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>158    </b>Chapter 5: Reacting to Security Incidents</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 50.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">and will know its purpose. If you have NetConfig, you can create templates to ease the deployment.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:98.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Private VLANs</b></span></div>
<div class=paragraph style=" padding:3.60pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Private VLANs can be used to achieve Layer 2 isolation of hosts within a VLAN. Some people use private VLANs in their data center to isolate servers in case they are compromised or infected. However, private VLANs do not provide perfect isolation. For example, you can insert a Layer 3 device to a promiscuous port and hop from one system to another using the destination IP address with the Layer 3 device MAC address. This type of attack and others are explained extensively in the whitepaper at <a href="http://www.cisco.com/en/US/netsol/ns340/ns394/ns171/ns128/networking_solutions_white_paper09186a008014870f.shtml%23wp1002364">http://www.cisco.com/en/US/netsol/ns340/ns394/ ns171/ns128/networking_solutions_white_paper09186a008014870f.shtml#wp1002364.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:86.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Remotely Triggered Black Hole Routing</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Remotely triggered black hole (RTHB) routing is a technique that can be used to drop all attack traffic based on either destination or attack source addresses. Source and destination-based RTBH filter undesirable traffic by forwarding it to the Null0 interface (a pseudointerface that is always up and can never forward or receive traffic). Performance is not a significant challenge with RTBH because it occurs directly in the forwarding path or Cisco Express Forwarding (CEF).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:42.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>This section assumes that you have a basic understanding of Border Gateway Protocol</span></span></div>
<div class=paragraph style=" padding:0.24pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">(BGP). If you need to review BGP, refer to <a href="http://www.cisco.com/en/US/tech/tk365/tk80/tsd_technology_support_sub-protocol_home.html">http://www.cisco.com/en/US/tech/tk365/tk80/ tsd_technology_support_sub-protocol_home.html </a>which includes a comprehensive list of BGP-related FAQs, configuration guidelines, and troubleshooting tips.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:40.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:68.88pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Destination-based RTBH works by filtering traffic destined to the hosts being attacked or by filtering an infected host (in worm outbreaks) at the boundary closest to the source. The trigger is typically a router that sends a routing update (iBGP in most cases) to other edge routers configured for black hole filtering. The trigger sends an update with the next-hop IP address defined in a static route pointing to Null0. This is illustrated in Figure 5-1.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:108.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:344.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:106.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 292.56pt; text-align:justify;"><span class=font4>Security Incident Mitigation Tools <b>159</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 5-1    </b><span class=font43><i>Destination-Based RTBH</i></span></span></div>
<div class=paragraph style=" padding:7.92pt 152.64pt 0.00pt 0.00pt; text-align:right;"><span class=font3>Edge Router 1&nbsp;Edge Router 2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="3" valign="top" style=" width:344.16pt;">
<div class=block style=" width:279.36pt; height:151.44pt; padding:0.00pt 0.24pt 0.00pt 64.56pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-55.jpg" alt="" style=" width:279.36pt; height:151.44pt;"></div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:24.96pt;">
<div class=paragraph style=" padding:2.88pt 0.96pt 0.00pt 0.00pt; text-align:justify;"><span class=font1>Attack Traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:106.32pt;">
<div class=block style=" width:24.72pt; height:20.88pt; padding:4.08pt 81.60pt 0.00pt 0.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-56.jpg" alt="" style=" width:24.72pt; height:20.88pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:141.84pt;">
<div class=block style=" width:35.76pt; height:12.24pt; padding:0.00pt 76.08pt 3.12pt 30.00pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-57.jpg" alt="" style=" width:35.76pt; height:15.36pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:141.84pt;">
<div class=block style=" width:141.84pt; height:111.12pt;">
<div class=paragraph style=" padding:0.00pt 65.28pt 0.00pt 18.96pt; text-align:justify;"><span class=font3>Attacker/Zombie</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.24pt;">
<div class=paragraph style=" padding:0.00pt 373.20pt 0.00pt 88.80pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">Center (NOC)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Figure 5-1, two zombies are attacking a web server (10.10.10.123). The network administrator in the Network Operations Center (NOC) notices the attack and configures a static route on the trigger router with the destination host address (10.10.10.123), pointing it to Null0. This trigger router then sends an iBGP update to the two other routers causing it to drop the attack traffic. Example 5-1 is the trigger router configuration:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 290.40pt 0.00pt 36.24pt; text-align:justify;"><span class=font3><b>Example 5-1   </b><span class=font43><i>Trigger Router Configuration</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:200.64pt;">
<div class=paragraph style=" padding:0.00pt 223.20pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.84pt;">interface loopback0 ip address 10.20.30.18 255.255.255.255</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.40pt; text-align:left;"><span class=font23>!</span></div>
<div class=paragraph style=" padding:2.40pt 308.64pt 0.00pt 101.52pt; text-align:left; text-indent:-4.32pt;"><span class=font23 style=" line-height:9.60pt;">interface Null0 no ip unreachables</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23 style=" line-height:9.84pt;"><sub>!</sub></span></div>
<div class=paragraph style=" padding:0.96pt 205.68pt 0.00pt 101.52pt; text-align:left; text-indent:-4.08pt;"><span class=font23 style=" line-height:9.84pt;">router bgp 64555 no synchronization no bgp client-to-client reflection bgp log-neighbor-changes redistribute static route-map rtbh-trigger</span></div>
<div class=paragraph style=" padding:9.60pt 201.36pt 0.00pt 101.52pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">neighbor rtbh-group peer-group neighbor rtbh-group remote-as 64555 neighbor rtbh-group update-source loopback0 neighbor rtbh-group route-reflector-client neighbor 10.20.30.1 peer-group rtbh-group</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.16pt; text-align:left;"><span class=font23><sub>!</sub></span></div>
<div class=paragraph style=" padding:2.16pt 252.96pt 0.00pt 100.80pt; text-align:left; text-indent:-3.36pt;"><span class=font23 style=" line-height:9.60pt;">route-map rtbh-trigger permit 10 match tag 666</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 101.76pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">set ip next-hop 192.168.20.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 413.04pt; text-align:justify;"><span class=font43><i>continues</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:76.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:344.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:106.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>160    </b>Chapter 5: Reacting to Security Incidents</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:71.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><a name="bookmark41"><b>E</b></a><b>xample 5-1   </b><span class=font43><i>Trigger Router Configuration (Continued)</i></span></span></div>
<div class=paragraph style=" padding:6.00pt 261.36pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">set local-preference 200 set origin igp set community no-export route-map rtbh-trigger deny 20</span></div>
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 97.20pt; text-align:justify;"><span class=font23 style=" line-height:9.60pt;">! The following is the static route that drops the traffic from the infected machine ip route 10.10.10.123 255.255.255.255 Null0 tag 666</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:165.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In the previous configuration example, a static route for the IP address (10.10.10.123) of the victim is configured pointing to Null0 and with a tag of 666. A route map called rtbh-trigger is applied prior to redistributing the static route into BGP. This route map is configured to match on a tag value of 666. It also sets the next-hop to 192.168.20.1 which is an unused address space that you must configure to selectively drop the traffic. The trigger router sets the next-hop route for the destination IP address whose traffic will be dropped. Route updates are used to propagate this route to all iBGP peer routers. These routers then set their next-hop to the destination. You must configure a static route for the next-hop address (in this example, 192.168.20.1) pointing to Null0 in all the routers where you want the traffic to be dropped. This enables the edge routers to set their next-hops accordingly and forward all traffic for the black-holed destination IP address to Null0. In this example, the local preference is set to 200, and the origin is set to the remote Interior Gateway Protocol (IGP) system. The community is set to no-export, so these routes will not be advertised to external BGP (eBGP) peers.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>For RTBH to operate successfully, the trigger router must have an iBGP peering</span></span></div>
<div class=paragraph style=" padding:0.00pt 41.04pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">relationship with the other two routers. If you use BGP route reflectors, the trigger router must have an iBGP relationship with the route reflectors in every cluster.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:180.96pt;">
<div class=paragraph style=" padding:0.00pt 53.52pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">If the attacker uses nonspoofed addresses for the attack, you can also do source-based RTBH just by adding a static route to the source or source network, as shown in the following example.</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23>ip route 192.168.20.2 255.255.255.255 Null0 tag 666</span></div>
<div class=paragraph style=" padding:5.52pt 41.04pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In this example, the attacker is using the IP address 192.168.20.2. However, an attacker could target a legitimate IP address by spoofing it as the source of an attack and counting on you to black-hole the source using sourced-based RTBH filtering. This is why having antispoofing mechanisms in place is crucial for every network in any organization.</span></div>
<div class=paragraph style=" padding:21.84pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Forensics</b></a></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Many people say that computer forensics is similar to a crime scene investigation, in most cases, the security event you are investigating may be an actual crime. You should determine which computer forensic methodology is most appropriate for your organization.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:53.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 384.72pt; text-align:justify;"><span class=font4>Forensics <b>161</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:68.88pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This investigation can be done by you or your own staff, by law enforcement, or by private sector computer forensic specialists. One of the most critical items to remember is the consequences of mishandling evidence. Forensics is a broad topic, and the laws and handling of evidence vary based on your locality. This chapter is intended to give you only some of the common tools and mechanisms that you can use to perform basic forensics after a security event.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.88pt;">
<div class=paragraph style=" padding:0.00pt 75.60pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>References to several whitepapers and tools are listed in the sections that follow.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:149.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Log Files</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">After a security incident, you can use log files to obtain clues on what happened. However, logs are useful only if they are actually read. Even in small networks, logs from servers, networking devices, end-host machines, and other systems can be large, and their analysis may be tedious and time consuming. That is why it is important to use event correlation systems and other tools to better analyze and study log entries. You can use robust systems such as CS-MARS or even simple tools and programs such as Swatch. <i>Swatch </i>stands for Simple Watcher. It is an open source tool written in Perl that is capable of searching a file for a list of strings and then performing specific actions when such a string is found. Swatch was designed to do real-time monitoring of server log files; however, you can also use it to handle a standalone file. It was also designed to analyze syslog archives, but you can use it on any file.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 133.92pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>The Swatch open source project is maintained on Source Forge at <a href="http://swatch.sourceforge.net">http://swatch. sourceforge.net.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 48.96pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Another excellent tool is Splunk. You can use this tool to conduct real-time searches of different types of event logs from different systems.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>For more information about Splunk, go to <a href="http://www.splunk.com">http://www.splunk.com.</a> In addition,</span></span></div>
<div class=paragraph style=" padding:0.00pt 44.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;"><a href="http://www.loganalysis.org">http://www.loganalysis.org</a> includes information about numerous log parsers that can be used for forensic purposes.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Different systems have different log formats. If it is necessary to compare files, it can be challenging to match up fields. For example, logs from routers are not the same as logs from</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:62.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>162    </b>Chapter 5: Reacting to Security Incidents</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:55.20pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">firewalls or other networking devices. Similarly, logs from Linux or UNIX servers are not the same as logs from Windows systems. CS-MARS can help you analyze all these different types of logs. Also, some open source tools can help you analyze system logs from UNIX/Linux and Windows machines. The following sections include the most commonly used tools.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:162.96pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>Linux Forensics Tools</b></span></div>
<div class=paragraph style=" padding:3.60pt 50.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Two of the most commonly used Linux forensics tools are Autopsy and the Sleuth Kit. These programs are intuitive and are a compilation of the following:</span></div>
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;File system layer tools</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;File system journal tools</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Meta data layer tools</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Disk image file tools</span></div>
<div class=paragraph style=" padding:1.92pt 38.88pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Despite the fact that Autopsy and the Sleuth Kit run on Linux, they support the NTFS, FAT, Ext2/3, and UFS1/2 file systems. You can download Autopsy and the Sleuth Kit free from <a href="http://www.sleuthkit.org">http://www.sleuthkit.org.</a></span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44>Figure 5-2 is a screen shot of Autopsy.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 290.64pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 5-2   </b><span class=font43><i>Autopsy Linux Forensics Tool</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.00pt; height:220.80pt; padding:0.00pt 75.12pt 0.00pt 74.88pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-58.jpg" alt="" style=" width:336.00pt; height:220.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:82.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 384.72pt; text-align:justify;"><span class=font4>Forensics <span class=font44><b>163</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:87.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Figure 5-2 shows how you can use Autopsy to analyze the files and directories within a system. You can use this tool to see the names of deleted files. Autopsy can create timelines that contain entries for the &quot;Modified, Access, and Change&quot; times of both allocated and unallocated files. It also allows you to create a &quot;case&quot; to track each security incident.</span></div>
<div class=paragraph style=" padding:5.76pt 38.16pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">When collecting information from a Linux or UNIX-based system, you can also use simple tools and commands such as <b>netstat </b>and <b>pstree. </b>You can use the <b>netstat -tap </b>command as shown in Figure 5-3 to obtain information about the active connections in a system.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 303.84pt 0.00pt 36.48pt; text-align:justify;"><span class=font44><b>Figure 5-3    netstat </b><span class=font43><i>Command Output</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.24pt;">
<div class=paragraph style=" padding:0.00pt 315.36pt 0.00pt 77.52pt; text-align:left; text-indent:2.16pt;"><span class=font0 style=" line-height:7.92pt;">File   Edit   <span class=font41 style=" font-variant: small-caps;">V</span><span style=" font-variant: small-caps;"><b>iew   </b></span>lermiiial   Tabs Help <span class=font42><b>[roo№omar -]# netstat -tap</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 260.64pt 0.00pt 76.32pt; text-align:justify;"><span class=font42><b>Active Internet connections (servers and established)</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:304.80pt; height:157.44pt; padding:0.00pt 106.32pt 0.00pt 74.88pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:304.80pt; height:157.44pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:20.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:19.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:5.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:19.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:14.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:7.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:59.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.24pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font42><b>Proto</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.24pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>Recv-Q.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.24pt;">
<div class=paragraph style=" padding:0.24pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>Send-Q</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.24pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>Local Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.24pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font42><b>Foreign Address</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.24pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 16.08pt; text-align:left;"><span class=font42><b>State</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>PID/Program narae</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 2.16pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>32769</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2272/rpc.statd</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39 style=" letter-spacing:0.50pt;"><b><i>5301</i></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2069/Xvnc</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font42><b>mysql</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2717/raysqld</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>5601</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2069/Xvnc</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>sunrpc</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2252/portraap</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>6001</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2069/Xvnc</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>ftp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2648/vsftpd</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:62.40pt;">
<div class=block style=" width:62.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>localhost. localdoitiain</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font42><b>ipp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>4063/cupsd</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:62.40pt;">
<div class=block style=" width:62.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>localhost. localdoitiain</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>533 5</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2549/raDNSResponder</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="3" valign="top" style=" width:62.40pt;">
<div class=block style=" width:62.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>localhost. localdoitiain</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font42><b>smtp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2743/sendraail: acce</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font42><b>mysql</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font42><b>omar.cisco.com:40718</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 16.08pt; text-align:left;"><span class=font42><b>ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2717/raysqld</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font42><b>mysql</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font42><b>omar.cisco.com:40719</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 16.08pt; text-align:left;"><span class=font42><b>ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2717/raysqld</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font42><b>mysql</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font42><b>omar.cisco.com:40720</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 16.08pt; text-align:left;"><span class=font42><b>ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2717/raysqld</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>42165</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font42><b>omar.cisco.com:raysql</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 16.08pt; text-align:left;"><span class=font42><b>ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>4114/httpd</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>4072(1</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font42><b>omar.cisco.com:raysql</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 16.08pt; text-align:left;"><span class=font42><b>ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>4110/httpd</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>40719</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font42><b>omar.cisco.com:raysql</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 16.08pt; text-align:left;"><span class=font42><b>ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>41(17/http d</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>40 7 IS</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font42><b>omar.cisco.com:raysql</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 16.08pt; text-align:left;"><span class=font42><b>ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>4109/httpd</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>ftp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font42><b>rtp-osantos-vpn5.cisco</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>4071 ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>4220/vsftpd</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font42><b>mysql</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font42><b>omar.cisco.com:4216 5</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 16.08pt; text-align:left;"><span class=font42><b>ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2717/raysqld</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>5601</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font42><b>rtp-osantos-vpn5.cisco</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>4484 ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2069/Xvnc</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>http</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2774/httpd</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>6001</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:5.76pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2069/Xvnc</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>ssh</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:6.00pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2627/sshd</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 1.68pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:5.76pt;">
<div class=block style=" width:5.76pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:36.72pt;">
<div class=block style=" width:36.72pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font42><b>https</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:7.44pt;">
<div class=block style=" width:7.44pt; height:6.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.28pt;">
<div class=block style=" width:59.28pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39><b>*</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font42><b>LISTEN</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font42><b>2774/httpd</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt;">
<div class=block style=" width:16.80pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>tcp</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:20.40pt;">
<div class=block style=" width:20.40pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 1.92pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.20pt;">
<div class=block style=" width:19.20pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 1.44pt 0.00pt 0.00pt; text-align:right;"><span class=font42><b>0</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:42.48pt;">
<div class=block style=" width:42.48pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>oraar.cisco.com</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>ssh</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:14.88pt;">
<div class=block style=" width:14.88pt; height:6.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:66.72pt;">
<div class=block style=" width:66.72pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font42><b>rtp-osantos-vpn5.cisco</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:48.00pt;">
<div class=block style=" width:48.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>4483 ESTABLISHED</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:56.40pt;">
<div class=block style=" width:56.40pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font42><b>42 46/s shd: omar [pr</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:16.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:20.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:19.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:5.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:36.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:19.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:14.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:7.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:59.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:56.40pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.56pt;">
<div class=paragraph style=" padding:0.00pt 366.48pt 0.00pt 77.52pt; text-align:justify;"><span class=font42><b>[roo№omar -]# |</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:42.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">In Figure 5-3, you can see the output showing the different established connections on the system.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font44 style=" line-height:11.76pt;"><b>NOTE        </b>On UNIX- and Linux-based systems (including Mac OS X), use the <b>man netstat </b>command to obtain detailed documentation on the available options of the <b>netstat </b>command.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.88pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can also use the <b>pstree </b>utility on a Linux system to display the processes on the system in the form of a tree diagram. This allows you to have a better view of the processes running on the system that may be part of malicious software. Figure 5-4 includes a screen shot of the output of the <b>pstree -hp </b>command. The <b>-h </b>option is used to show the current process and its ancestors, and the <b>-p </b>option is used to display the process IDs (PID).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:64.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 257.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>164   </b>Chapter 5: Reacting to Security Incidents</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 306.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 5-4   </b><span class=font43><b>pstree </b><i>Command Output</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:328.32pt; height:285.12pt; padding:0.00pt 78.96pt 0.00pt 78.72pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-59.jpg" alt="" style=" width:328.32pt; height:285.12pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The detailed whitepaper titled &quot;Checking UNIX/LINUX Systems for Signs of Compromise&quot; supplies insightful information on the forensics of Linux and UNIX systems. You can download the whitepaper from <a href="http://www.ucl.ac.uk/cert/nix_intrusion.pdf">http://www.ucl.ac.uk/cert/nix_intrusion.pdf.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:23.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:147.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font8><b>Windows Forensics</b></span></div>
<div class=paragraph style=" padding:2.88pt 37.20pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The most commonly used toolkit for forensics in Windows-based systems is Systernals. <i>Systernals </i>is a compilation of several tools used for analysis, troubleshooting, and forensics of Windows machines. This toolkit was initially created by Mark Russinovich and Bryce Cogswell, and Microsoft acquired it in July 2006. Systernals toolkit includes the following:</span></div>
<div class=paragraph style=" padding:3.60pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;File and disk utilities</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Network statistical and analysis utilities</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Process illustration and analysis utilities</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Security configuration utilities</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;System resource usage and configuration tools</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:58.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.32pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 384.24pt; text-align:justify;"><span class=font4>Summary <b>165</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>Microsoft has an excellent whitepaper about Windows forensics best practices and</span></span></div>
<div class=paragraph style=" padding:0.00pt 43.68pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">methodologies at <a href="http://www.microsoft.com/technet/security/guidance/disasterrecovery/computer_investigation/default.mspx">http://www.microsoft.com/technet/security/guidance/disasterrecovery/ computer_investigation/default.mspx.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 42.72pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Guidance Software also develops sophisticated forensics tools. Its EnCase product suite includes different integrated tools that facilitate seamless sharing of evidentiary data and solve the resource drain of encrypted data.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 157.92pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:12.00pt;"><a name="bookmark42"><b>N</b></a><b>OTE        </b><span class=font44>For more information about the EnCase suite of tools, go to <a href="http://www.guidancesoftware.com">http://www.guidancesoftware.com.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">It is important to remember that no matter the vendor, the forensics tool you select must give you flexibility when conducting investigations and should help mask complexity when forensics data is shared with untrained individuals.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:90.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Summary</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 37.20pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In this chapter, you learned how important it is for any organization to have adequate incident handling policies and procedures. You also learned general information about the different laws and practices involved when you are investigating security incidents and computer crimes. This chapter also included detailed information about different tools you can use to mitigate attacks and other security incidents with your network infrastructure components. This chapter concluded with a discussion of basic computer forensics topics.</span></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://ciscoasa.org.ua/2010/02/chapter-5-reacting-to-security-incidents/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter 4 Traceback</title>
		<link>http://ciscoasa.org.ua/2010/02/chapter-4-traceback/</link>
		<comments>http://ciscoasa.org.ua/2010/02/chapter-4-traceback/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 20:59:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[critical information systems]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[denial of service dos]]></category>
		<category><![CDATA[engineer manager]]></category>
		<category><![CDATA[intrusion prevention systems]]></category>
		<category><![CDATA[network security technologies]]></category>
		<category><![CDATA[networked systems]]></category>
		<category><![CDATA[security engineer]]></category>
		<category><![CDATA[virtual private network]]></category>

		<guid isPermaLink="false">http://ciscoasa.org.ua/?p=250</guid>
		<description><![CDATA[

For many years, enterprises, service providers, the government, and many other organizations have tried to develop tools and techniques to aid in the traceback of attacks. This chapter covers several lessons learned and techniques developed over the past to successfully trace back attacks or prepare the infrastructure to make this process easier. The techniques to [...]]]></description>
			<content:encoded><![CDATA[<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:362.88pt;">
<div class=paragraph style=" padding:0.00pt 36.96pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">For many years, enterprises, service providers, the government, and many other organizations have tried to develop tools and techniques to aid in the traceback of attacks. This chapter covers several lessons learned and techniques developed over the past to successfully trace back attacks or prepare the infrastructure to make this process easier. The techniques to track individual packets in a network must be done in an efficient, scalable fashion. The main goal of the traceback process is to find the source of attack or malignant traffic. By analyzing the packet contents of the attack traffic, you can determine information that may lead you to the source.</span></div>
<div class=paragraph style=" padding:6.00pt 37.92pt 0.00pt 90.96pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The traceback level of effort and methodologies may not be the same in all organizations. For instance, Internet service providers may use different techniques than those used in enterprises.</span></div>
<div class=paragraph style=" padding:6.24pt 37.68pt 0.00pt 90.96pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">In the past, it was sometimes difficult to trace back attacks because of the use of spoofed packets. In addition, the packet stream may have been transmitted though many network devices that performed NAT, making it difficult for some enterprises and service providers to trace the original source IP address of the packet. Service providers and enterprises are now implementing antispoofing techniques that make it more difficult for spoofed attacks to succeed. For this reason, most attacks today are not sourced from spoofed IP addresses. Antispoofing techniques include the following:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Source address validation described in RFC 2827/BCP38 and RFC 3704/BCP84</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Denial of your address space from external sources</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Denial of RFC 1918 private address space in your Internet edge routers</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Denial of multicast source addresses</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Filtering for RFC 3330 special use IPv4 addresses</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 98.64pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Use of Unicast Reverse Path Forwarding (uRPF)</span></div>
<div class=paragraph style=" padding:2.16pt 47.52pt 0.00pt 112.56pt; text-align:justify; text-indent:-13.68pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Cable source verification—Enhancements within Cisco cable modem termination system (CMTS) products that protect against spoofed attacks in Data-over-Cable Service Interface Specifications (DOCSIS) cable systems</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:89.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:84.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:311.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 336.00pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>142    </b>Chapter 4: Traceback</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 43.20pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:11.76pt;"><a name="bookmark34"><b>N</b></a><b>OTE        </b><span class=font44>In Chapter 2, &quot;Preparation Phase,&quot; you learned these techniques and how to protect your infrastructure against spoofed packets. See Chapter 2 to learn how to implement these types of infrastructure protection mechanisms.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:210.00pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Traceback in the Service Provider Environment</b></a></span></div>
<div class=paragraph style=" padding:3.84pt 59.04pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">For the implementation of traceback techniques to be successful, they must meet the following requirements:</span></div>
<div class=paragraph style=" padding:6.00pt 42.00pt 0.00pt 111.12pt; text-align:left; text-indent:-13.68pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Do not violate current protocol semantics and can be successful without changes in the core routing structure</span></div>
<div class=paragraph style=" padding:4.32pt 48.00pt 0.00pt 111.12pt; text-align:left; text-indent:-13.68pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Are difficult for the attacker to detect and can function in a passive mode, without requiring much intervention</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Are useful in asymmetric environments</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Work through multiple hops, across jurisdictions</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:16.08pt;">•&nbsp;Allow you to generate a good postmortem after an attack has mitigated</span></div>
<div class=paragraph style=" padding:1.92pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In some cases, it is difficult for the implementation of traceback techniques to meet all the requirements previously listed, and it is especially difficult for service providers. This is why it is extremely important for service providers to cooperate with each other to successfully trace back attacks. This is especially true because attackers are aware of many traceback schemes.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:73.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>TIP&nbsp;</b><span class=font44>Major cooperative efforts exist between service providers and several organizations</span></span></div>
<div class=paragraph style=" padding:0.00pt 36.96pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">that promote these efforts. An example is the North American Network Operators Group (NANOG), which has excellent resources and information at <a href="http://www.nanog.org">http://www.nanog.org.</a></span></div>
<div class=paragraph style=" padding:2.88pt 93.12pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Another example is the Forum for Incident Response and Security Teams (FIRST), which has excellent resources and best practice guides at <a href="http://www.first.org/resources/guides">http://www.first.org/resources/guides.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">When there are large numbers of sources or when sources are well distributed, traceback solutions often become extremely complex and expensive. Speed is a significant limitation of hop-by-hop traceback; therefore, hop-by-hop traceback can be difficult. It also requires</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:112.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 236.40pt; text-align:justify;"><span class=font4>Traceback in the Service Provider Environment <b>143</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:53.28pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">substantial collaboration. For example, Figure 4-1 illustrates an old method being used by an individual who is attacking a victim who is numerous hops away from different service providers.</span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 4-1    </b><span class=font43><i>Hop-by-Hop Traceback</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:353.04pt; height:301.20pt; padding:0.00pt 66.72pt 0.00pt 66.24pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-50.jpg" alt="" style=" width:353.04pt; height:301.20pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In this case, collaboration between service providers may be needed, and hop-by-hop traceback may take longer than expected. However, this is not what we typically see today. Figure 4-2 illustrates a more interesting scenario.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:163.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 335.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>144   </b>Chapter 4: Traceback</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:411.84pt; height:504.96pt; padding:0.00pt 37.68pt 0.00pt 36.48pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-51.jpg" alt="" style=" width:411.84pt; height:504.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:72.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.72pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 236.40pt; text-align:justify;"><span class=font4>Traceback in the Service Provider Environment <b>145</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:38.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:207.12pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Figure 4-2, the attacker controls three different botnets or groups of zombies. In this case, hop-by-hop traceback can be time consuming and ineffective. Botnets can consist of several hundred compromised machines. Even a relatively small botnet with only a couple of hundred bots can cause significant damage. The IP distribution of these bots makes the implementation of ingress filters (or filtering) difficult, especially because separate organizations are involved. In most cases, botnets are used to infect or spread malware to other machines. In numerous cases, botnets are controlled by the attacker who is using encrypted tunnels to protect his own communication channel.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>Botnets come in hundreds of different types, some of which include:</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Agobot/Phatbot/Forbot/XtremBot</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;SDBot/RBot/UrBot/UrXBot</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;mIRC-based bots</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;DSNX bots</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Q8 bots</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;kaiten.cPerl-based bots</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:61.92pt;">
<div class=paragraph style=" padding:0.00pt 40.56pt 0.00pt 36.00pt; text-align:justify;"><span class=font4 style=" line-height:12.00pt;"><b>TIP&nbsp;</b><span class=font44>Shadowserver.com is an excellent website that reports botnet activity on the Internet on a</span></span></div>
<div class=paragraph style=" padding:0.24pt 58.08pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">daily basis. Many organizations use this information to become familiar with current trends. This site provides detailed graphics and metrics.</span></div>
<div class=paragraph style=" padding:3.36pt 104.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can also obtain technical information about different types of bots at <a href="http://www.cert.org">http://www.cert.org </a>or at <a href="http://packetstormsecurity.nl">http://packetstormsecurity.nl.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:147.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Attackers who launch DDoS attacks can gain a major advantage by using reflectors to complicate the traceback process; this is known as <i>attack obfuscation. </i>Instead of the victim being able to trace back the attack traffic from himself directly to the slave, he must induce the operator of one of the reflector sites to do so on his behalf which can be administratively cumbersome or difficult.</span></div>
<div class=paragraph style=" padding:5.76pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Tracking botnets is a dilemma for many service providers and other organizations. To successfully perform traceback, you need to gather a significant amount of data about existing botnets, in many cases by analyzing captured malware. Many organizations are engaged in research to learn more about botnets and new techniques to combat them. An example of this is the Honeynet Project (<a href="http://honeynet.org">http://honeynet.org).</a> Honeynets are a collection of purposefully insecure machines (or honeypots) that are placed on the Internet for attackers to compromise. Researchers can then investigate and learn more about current</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:95.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 336.00pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>146    </b>Chapter 4: Traceback</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:348.72pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">threats. At the minimum, honeynets collect the following information to learn more about botnets:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;DNS name or IP address of the Internet relay chat (IRC) server and port number</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;In some cases, passwords to connect to the IRC server (when applicable)</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Nickname of bot and ident (identification) structure</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;IRC channel to join and channel password</span></div>
<div class=paragraph style=" padding:2.16pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Many researchers have observed that updates on the botnet malware are performed frequently. To understand this process more fully, consider an old worm whose propagation started in several botnets, Zotob.x. Zotob was created by Farid Essebar (known by his handle as Diabl0). He was a small-time adware/spyware installer, using Mytob (a mass mailing worm) to infect machines and install adware for money. On August 25, 2005, Essebar was arrested in Morocco. The FBI stated that it holds evidence that Essebar was paid by Atilla Ekici (known as coder), who used stolen credit card numbers to build Mytob variants, as well as Zotob. Many service providers and other organizations spent numerous hours investigating this incident. One of the methods used was the <i>backscatter technique. </i>Backscatter is a system that Chris Morrow and Brian Gemberling created while they were working at a major service provider in the United States. This method addresses the need of finding the entry point of a spoofed attack. It combines sinkhole routers and remotely triggered black hole (RTBH) filtering to create a traceback system that provides a result within minutes.</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can use Border Gateway Protocol (BGP)-enabled routers to set specific prefixes to a known and individually handled &quot;next-hop&quot; and see interesting effects when you set the &quot;next-hop&quot; in BGP for a host that is under attack to a single address that will be routed locally. Typically, you set a static route to Null0 so that the attack traffic is advertised with the new &quot;next-hop.&quot; An Internet Control Message Protocol (ICMP) unreachable message is transmitted by a network device when it receives packets whose destination is unreachable (Null0). This &quot;unreachable noise&quot; is called a <i>backscatter.</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph style=" padding:0.00pt 40.80pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>Backscatter has been advocated by many people, but many also question its benefits. You can find more details about the backscatter technique at <a href="http://www.secsup.org/Tracking">http://www.secsup.org/Tracking. </a>Another good presentation on backscatter, which is by Barry Greene, a senior Cisco SP expert, is located at <a href="http://www.nanog.org/mtg-0110/ppt/greene.ppt">http://www.nanog.org/mtg-0110/ppt/greene.ppt.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Furthermore, if that traceback is then performed using a scheme that relies on observing a high volume of spoofed traffic, such as ITRACE or probabilistic packet marking, the attacker can undermine the traceback by spreading the trigger traffic of each slave across</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 313.68pt; text-align:justify;"><span class=font4>Traceback in the Enterprise <b>147</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:86.88pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;"><a name="bookmark35">m</a>any reflectors. Doing this greatly increases the amount of time required by the traceback scheme to gather sufficient traffic to analyze. These methodologies have been suggested due to research initiatives by several organizations (mainly educational institutions). However, the initiatives, in most cases, are considered &quot;science projects.&quot;</span></div>
<div class=paragraph style=" padding:6.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Many others have attempted IP traceback techniques such as probabilistic packet marking and deterministic packet markings; these attempts, however, have also been considered science projects.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph style=" padding:0.00pt 72.96pt 0.00pt 90.24pt; text-align:left; text-indent:-53.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>Wikipedia has a good, high-level description of probabilistic packet marking and deterministic packet markings at <a href="http://en.wikipedia.org/wiki/IP_Traceback">http://en.wikipedia.org/wiki/IP_Traceback.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:310.32pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font11><a href="#bookmark30"><b>Traceback in the Enterprise</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The ability to track where attacks are coming from and the techniques that are used within an enterprise depend on the type of attack. If the attacks are coming from external sources, such as the Internet, the enterprises often depend on their providers to be able to track down sources of attack. Additionally, the network telemetry techniques and features discussed in Chapter 3, &quot;Identifying and Classifying Security Threats,&quot; are extremely helpful for tracking where attack traffic is being generated.</span></div>
<div class=paragraph style=" padding:5.76pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">One of the most powerful tools is NetFlow because it can give macroanalytical information on the traffic traversing your network. Traceback goes hand in hand with the identification and classification phases of incident response. NetFlow, SYSLOGs, DNS, and other telemetry mechanisms in conjunction with event correlation tools such as Cisco Secure Monitoring and Response System (CS-MARS) and Arbor Peakflow X are particularly helpful to trace back security incidents.</span></div>
<div class=paragraph style=" padding:6.24pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Just from a router command line (CLI), you can use NetFlow to collect valuable information. For example, if you notice a sudden increase in traffic over TCP port 445, you can use the <b>show ip cache flow </b>command with the <b>include </b>option to see the hosts that are sending this type of traffic, as shown in the following example:</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23>myrouter&gt;show ip cache flow I include 01BD</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23>Fa1/0&nbsp;10.36.1.66&nbsp;Fa0/0&nbsp;172.18.85.178     06 C5BC 01BD 93123135</span></div>
<div class=paragraph style=" padding:5.52pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Because NetFlow uses hexadecimal numbers for the protocol, source, and destination ports, 01BD is used in the include statement (01BD hexadecimal = 445 decimal). As you can see from the output, the router has received 93123135 TCP port 445 packets on its FastEthernet 1/0 interface from a host with the IP address 10.36.1.66, which is destined to a host with the IP address 172.18.85.178 residing on the FastEthernet0/0 interface.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:94.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:233.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:128.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:123.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 336.00pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>148    </b>Chapter 4: Traceback</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the following example, CS-MARS is used in combination with NetFlow and a Cisco IPS sensor. In Figure 4-3, the CS-MARS alerts the administrator about a host spreading the Nachi worm and doing a DoS via ICMP ping. The incident ID is I:155164925.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 295.44pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 4-3    </b><span class=font43><i>Worm Incident in CS-MARS</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.12pt;">
<div class=paragraph style=" padding:0.00pt 87.12pt 0.00pt 233.52pt; text-align:justify;"><span class=font0>SUMMARY    <b>INCIDENTS   </b>QUERY .■ REPORTS     RULES    MANAGEMENT    ADMIN <b>HELP</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:233.52pt;">
<div class=block style=" width:233.52pt; height:5.04pt;">
<div class=paragraph style=" padding:0.72pt 77.28pt 0.00pt 81.36pt; text-align:justify;"><span class=font0><b>Incidents     False Positives Cesi</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:252.48pt;">
<div class=block style=" width:252.48pt; height:5.04pt;">
<div class=paragraph style=" padding:0.00pt 83.76pt 0.00pt 107.28pt; text-align:justify;"><span class=font0><b><u>Feb 9, 2007 6:39:53 PN EST </u></b><span class=font2><u>1</u></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:362.16pt;">
<div class=block style=" width:362.16pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 18.00pt 0.00pt 88.56pt; text-align:justify;"><span class=font0><b>' INCIDENTS  </b><span class=font2>I </span><b>CS-MARS Local Controller: RTP-MARS-50-A/rtp-mar5-50Av4.2 </b>Login: Local: Administrator (pnadmin)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:123.84pt;">
<div class=block style=" width:123.84pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 86.64pt 0.00pt 33.12pt; text-align:justify;"><span class=font44><b>□</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.32pt;">
<div class=paragraph style=" padding:0.00pt 340.56pt 0.00pt 82.08pt; text-align:justify;"><span class=font0>Select Case: I No Ca=e Selected...</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.76pt;">
<div class=paragraph style=" padding:0.00pt 139.68pt 0.00pt 319.68pt; text-align:justify;"><span class=font0>cidentlD: <span class=font43><b>Q</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.04pt;">
<div class=paragraph style=" padding:0.00pt 83.76pt 0.00pt 390.24pt; text-align:justify;"><span class=font41 style=" letter-spacing:-0.50pt;"><b><u>F1</u></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:12.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.28pt;">
<div class=paragraph style=" padding:0.00pt 318.48pt 0.00pt 78.48pt; text-align:justify;"><span class=font0><b>Recent Incidents for Last </b><u>| One Week <b>v</b></u></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:24.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:233.52pt;">
<div class=block style=" width:233.52pt; height:2.88pt;">
<div class=paragraph style=" padding:0.00pt 59.76pt 0.00pt 163.68pt; text-align:justify;"><span class=font0>ill <span class=font38 style=" font-variant: small-caps;">-.11</span></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:252.48pt;">
<div class=block style=" width:252.48pt; height:2.88pt;">
<div class=paragraph style=" padding:0.00pt 85.68pt 0.00pt 128.64pt; text-align:justify;"><span class=font0>All Case Statu = er: <b>v</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:325.68pt; height:122.40pt; padding:0.00pt 83.28pt 0.00pt 77.04pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:325.68pt; height:122.40pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:31.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:42.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:13.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:18.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:13.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:33.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:59.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.84pt;">
<div class=block style=" width:9.84pt; height:6.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:31.44pt;">
<div class=block style=" width:31.44pt; height:6.48pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0><b>Incident </b>ID</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:42.00pt;">
<div class=block style=" width:42.00pt; height:6.48pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font0><b>| Event Type</b></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:32.88pt;">
<div class=block style=" width:32.88pt; height:6.48pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font0><b>Matched Rule</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:6.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.44pt;">
<div class=block style=" width:13.44pt; height:6.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:6.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.72pt;">
<div class=block style=" width:72.72pt; height:6.48pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 23.76pt; text-align:left;"><span class=font0><b>Action Time</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.04pt;">
<div class=block style=" width:59.04pt; height:6.48pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font39>1 <span class=font0><b>|cases</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.84pt;">
<div class=block style=" width:9.84pt; height:15.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:31.44pt;">
<div class=block style=" width:31.44pt; height:15.84pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0>I;1551S49Z7_?</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:42.00pt;">
<div class=block style=" width:42.00pt; height:15.84pt;">
<div class=paragraph style=" padding:1.44pt 3.36pt 0.00pt 3.12pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">CS-MARS Detected Conflicting SSL Certificate [_]</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.92pt;">
<div class=block style=" width:13.92pt; height:15.84pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font0>Syste</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:18.96pt;">
<div class=block style=" width:18.96pt; height:15.84pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font0>n Rule: M</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:15.84pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font0>dify Network Co</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.44pt;">
<div class=block style=" width:13.44pt; height:15.84pt;">
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0>nfig_j</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:15.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.72pt;">
<div class=block style=" width:72.72pt; height:15.84pt;">
<div class=paragraph style=" padding:1.44pt 4.32pt 0.00pt 38.88pt; text-align:left;"><span class=font0 style=" line-height:4.08pt;">Feb Э, 2007 6:32:45 PM EST</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.04pt;">
<div class=block style=" width:59.04pt; height:15.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font41 style=" letter-spacing:1.00pt;"><b>SB</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.84pt;">
<div class=block style=" width:9.84pt; height:18.48pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font0>Г</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:31.44pt;">
<div class=block style=" width:31.44pt; height:18.48pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0>1:1551549 25_£</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:42.00pt;">
<div class=block style=" width:42.00pt; height:18.48pt;">
<div class=paragraph style=" padding:0.72pt 1.92pt 0.00pt 3.12pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">Nachi Worm Spread and DoS via ICMP Ping[_</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.92pt;">
<div class=block style=" width:13.92pt; height:18.48pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font0>Syste</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:18.96pt;">
<div class=block style=" width:18.96pt; height:18.48pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font0>n Rule; W</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:18.48pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font0>rm Propagation</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.44pt;">
<div class=block style=" width:13.44pt; height:18.48pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font0>- Atten</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:18.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.72pt;">
<div class=block style=" width:72.72pt; height:18.48pt;">
<div class=paragraph style=" padding:0.72pt 1.68pt 0.00pt 38.88pt; text-align:left;"><span class=font0 style=" line-height:4.08pt;">Feb Э, 2007 5:50:54 PM EST -Feb 9, 2007 6:30:07 PM EST</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.04pt;">
<div class=block style=" width:59.04pt; height:18.48pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font41 style=" letter-spacing:1.00pt;"><b>SB</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.84pt;">
<div class=block style=" width:9.84pt; height:18.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font2>г</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:31.44pt;">
<div class=block style=" width:31.44pt; height:18.72pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0>1:155164923</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:42.00pt;">
<div class=block style=" width:42.00pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 1.92pt 0.00pt 3.12pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">Nachi Worm Spread and DoS via ICMP <span class=font38>Р1гч[_</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.92pt;">
<div class=block style=" width:13.92pt; height:18.72pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font0>Syste</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:18.96pt;">
<div class=block style=" width:18.96pt; height:18.72pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font0>n Rule: W</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:18.72pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font0>rm Propagation</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.44pt;">
<div class=block style=" width:13.44pt; height:18.72pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font0>- Atten</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39>ptE</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.72pt;">
<div class=block style=" width:72.72pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 1.68pt 0.00pt 38.88pt; text-align:left;"><span class=font0 style=" line-height:4.08pt;">Feb 9, 2007 5:46:03 PM EST -Feb 9, 2007 6:25:52 PM EST</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.04pt;">
<div class=block style=" width:59.04pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font39 style=" letter-spacing:0.50pt;"><b><i>mm</i></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.84pt;">
<div class=block style=" width:9.84pt; height:15.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font2>г</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:31.44pt;">
<div class=block style=" width:31.44pt; height:15.36pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0>1:155L64-924__&quot;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:42.00pt;">
<div class=block style=" width:42.00pt; height:15.36pt;">
<div class=paragraph style=" padding:0.96pt 3.36pt 0.00pt 3.12pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">CS-MARS Detected Conflicting SSL Certificate [_]</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.92pt;">
<div class=block style=" width:13.92pt; height:15.36pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font0>Systa</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:18.96pt;">
<div class=block style=" width:18.96pt; height:15.36pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 0.96pt; text-align:left;"><span class=font0>l =-.ule: M</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:15.36pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font0>dify Network Co</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.44pt;">
<div class=block style=" width:13.44pt; height:15.36pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0>nfig^</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:15.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.72pt;">
<div class=block style=" width:72.72pt; height:15.36pt;">
<div class=paragraph style=" padding:0.96pt 4.32pt 0.00pt 38.88pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">Feb 9, 2007 6:25:L5 PM EST</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.04pt;">
<div class=block style=" width:59.04pt; height:15.36pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font39>LHH</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.84pt;">
<div class=block style=" width:9.84pt; height:18.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font2>г</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:31.44pt;">
<div class=block style=" width:31.44pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0>1:1551549 2.1__</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:42.00pt;">
<div class=block style=" width:42.00pt; height:18.72pt;">
<div class=paragraph style=" padding:0.72pt 3.36pt 0.00pt 3.12pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">CS-MARS Detected Conflicting SSL Certificate [_]</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.92pt;">
<div class=block style=" width:13.92pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font0>Systa</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:18.96pt;">
<div class=block style=" width:18.96pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font0>n Rule: M</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font0>dify Network Co</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.44pt;">
<div class=block style=" width:13.44pt; height:18.72pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0>nfig^</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:18.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.72pt;">
<div class=block style=" width:72.72pt; height:18.72pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 38.88pt; text-align:left;"><span class=font0>Feb 9, 2007</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 38.88pt; text-align:left;"><span class=font0>6:10:L5 PM EST -</span></div>
<div class=paragraph style=" padding:0.00pt 4.32pt 0.00pt 38.88pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">Feb 9, 2007 6:17<span class=font38>:4</span>-5 PM EST</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.04pt;">
<div class=block style=" width:59.04pt; height:18.72pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font39>LHH</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.84pt;">
<div class=block style=" width:9.84pt; height:18.72pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font2>г</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:31.44pt;">
<div class=block style=" width:31.44pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0>1:1551549 20.^</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:42.00pt;">
<div class=block style=" width:42.00pt; height:18.72pt;">
<div class=paragraph style=" padding:0.48pt 1.92pt 0.00pt 3.12pt; text-align:left;"><span class=font0 style=" line-height:4.80pt;">Nachi Worm Spread and DoS via ICMF PingS</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.92pt;">
<div class=block style=" width:13.92pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font0>Syste</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:18.96pt;">
<div class=block style=" width:18.96pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font0>n Rule: W</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font0>rm Propagation</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.44pt;">
<div class=block style=" width:13.44pt; height:18.72pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font0>-Atten</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:18.72pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39>тВ</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.72pt;">
<div class=block style=" width:72.72pt; height:18.72pt;">
<div class=paragraph style=" padding:0.72pt 1.68pt 0.00pt 38.88pt; text-align:left;"><span class=font0 style=" line-height:4.08pt;">Feb 9, 2007 5:34:L3 PM EST -Feb 9, 2007 6:14:03 PM EST</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.04pt;">
<div class=block style=" width:59.04pt; height:18.72pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font39>ii</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.84pt;">
<div class=block style=" width:9.84pt; height:10.08pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font39>г</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:31.44pt;">
<div class=block style=" width:31.44pt; height:10.08pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.48pt; text-align:left;"><span class=font0>I:155164919./_</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:42.00pt;">
<div class=block style=" width:42.00pt; height:10.08pt;">
<div class=paragraph style=" padding:0.72pt 1.92pt 0.00pt 3.12pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">Nachi Worm Spread and DoS via ICMP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.92pt;">
<div class=block style=" width:13.92pt; height:10.08pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font0>Syste</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:18.96pt;">
<div class=block style=" width:18.96pt; height:10.08pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font0>n Rule: W</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:30.96pt;">
<div class=block style=" width:30.96pt; height:10.08pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font0>rm Propagation</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:13.44pt;">
<div class=block style=" width:13.44pt; height:10.08pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font0>-Atten</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:33.36pt;">
<div class=block style=" width:33.36pt; height:10.08pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font39>pt0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:72.72pt;">
<div class=block style=" width:72.72pt; height:10.08pt;">
<div class=paragraph style=" padding:0.72pt 4.32pt 0.00pt 38.88pt; text-align:left;"><span class=font0 style=" line-height:4.32pt;">Feb 9, 2007 6:13:L2 PM EST</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.04pt;">
<div class=block style=" width:59.04pt; height:10.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font41 style=" letter-spacing:1.00pt;"><b>и</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:9.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:31.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:42.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:13.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:18.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:30.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:13.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:33.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:72.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:59.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.08pt;">
<div class=paragraph style=" padding:0.00pt 352.32pt 0.00pt 121.44pt; text-align:justify;"><span class=font0><b>Pir</b><span class=font2>«lS</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:92.88pt;">
<div class=paragraph style=" padding:0.00pt 48.72pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">When the administrator clicks the <b>Attack Path </b>icon on the right, a new screen with the attack topology is displayed, as shown in Figure 4-4.</span></div>
<div class=paragraph style=" padding:6.24pt 38.64pt 0.00pt 89.52pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">In Figure 4-4, you can see that the infected host is 172.19.124.35, and it is attacking a host with the IP address 172.18.124.67. This is a simple topology; however, CS-MARS is able to show you each hop based on the information imported and its configuration. Graphical representation like this one can save you many hours of investigation.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>An additional example is shown in Figure 4-5.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:152.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:233.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:128.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:123.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 313.68pt; text-align:justify;"><span class=font4>Traceback in the Enterprise <b>149</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 355.20pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 4-4   </b><span class=font43><i>Attack Path</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:231.84pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-52.jpg" alt="" style=" width:336.96pt; height:231.84pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.84pt;">
<div class=paragraph style=" padding:0.00pt 341.28pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 4-5   </b><span class=font43><i>Dot-Dot Attack</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:244.32pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="http://ciscoasa.org.ua/wp-content/uploads/2010/02/ciscoasa_org_ua-53.jpg" alt="" style=" width:336.96pt; height:244.32pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:53.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 336.00pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>150    </b>Chapter 4: Traceback</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:361.20pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Figure 4-5, a host with the IP address 10.10.1.10 (HQ-host1) is attempting to crash an IIS server (192.168.1.10 or HQ-web-1) by performing a dot-dot crash and running an attack. Notice that each hop in between is clearly represented, making the traceback process simple. CS-MARS correlated this information analyzing events from a Cisco IPS sensor and from firewall logs from a Cisco PIX security appliance.</span></div>
<div class=paragraph style=" padding:6.00pt 66.72pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Tracing botnet controllers and determining if you are a victim can be difficult. The following tips might help you or your organization if it has zombies:</span></div>
<div class=paragraph style=" padding:6.24pt 40.08pt 0.00pt 111.12pt; text-align:left; text-indent:-13.68pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;If you see a good deal of IRC traffic within your organization, it may be worth investigating further. IRC traffic is not common in most enterprises, and most of the botnets are organized and controlled over IRC.</span></div>
<div class=paragraph style=" padding:4.08pt 38.64pt 0.00pt 111.12pt; text-align:left; text-indent:-13.68pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;You can look for the most commonly used default IRC port (6667). In addition, you will want to expand to the full port range (from 6660 to 6669 or 7000). On the other hand, many botnet controllers can use nonstandard IRC ports. If you have a firewall within your organization, take a look at outbound connection attempts on any suspicious ports.</span></div>
<div class=paragraph style=" padding:4.08pt 64.08pt 0.00pt 111.12pt; text-align:left; text-indent:-13.68pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;IRC traffic usually manifests itself in cleartext, so sensors can be built to sniff particular IRC commands or other protocol keywords on a network gateway.</span></div>
<div class=paragraph style=" padding:4.08pt 44.16pt 0.00pt 111.12pt; text-align:left; text-indent:-13.68pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;If you notice that a large quantity of systems within your organization are trying to resolve the same DNS names or accessing the same server at once, you should immediately investigate further because those systems may be zombies. Also, periodically check your DNS caches. Many command and control tools will use a DNS domain that the herder (botnet administrator) can easily change as needed to relocate the botnet infrastructure.</span></div>
<div class=paragraph style=" padding:4.08pt 37.92pt 0.00pt 111.12pt; text-align:left; text-indent:-13.68pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;You can look for other obvious symptoms of being a victim. For example, if you see much port-scan traffic, it is a definite sign that machines are infected. You can use proper IDS/IPS signatures to find these and then investigate the source. In addition, if you see a lot of unexpected outbound SMTP traffic, you are likely to be hosting spam bots. You can use NetFlow to get statistics about these type of attacks.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt;">
<div class=block style=" width:89.76pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 29.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:396.24pt;">
<div class=block style=" width:396.24pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 0.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Chapter 12, &quot;Case Studies,&quot; includes case studies with examples of how different types of organizations identify, classify, trace, and react to security incidents. Common traceback mechanisms are used in those examples.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:151.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.32pt;">
<div class=paragraph style=" padding:0.00pt 37.68pt 0.00pt 384.24pt; text-align:justify;"><span class=font4>Summary <b>151</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:125.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark30"><a name="bookmark36"><b>S</b></a><b>ummary</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Tracing back the source of attacks, infected hosts in worm outbreaks, or any other security incident can be overwhelming for many network administrators and security professionals. Attackers can use hundreds or thousands of botnets or zombies that can greatly complicate traceback and hinder mitigation after traceback succeeds. This chapter covered several techniques that can help you successfully trace back the sources of such threats; covering both service provider and enterprise techniques. Remember, traceback mainly involves the packet source. Using network telemetry tools like NetFlow, syslog, DNS, and others in conjunction with event correlation systems can save you hundreds of work hours and, consequently, save you money.</span></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://ciscoasa.org.ua/2010/02/chapter-4-traceback/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chapter 3 Identifying and Classifying Security Threats</title>
		<link>http://ciscoasa.org.ua/2010/02/chapter-3-identifying-and-classifying-security-threats/</link>
		<comments>http://ciscoasa.org.ua/2010/02/chapter-3-identifying-and-classifying-security-threats/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 20:26:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[anomalies]]></category>
		<category><![CDATA[attacker]]></category>
		<category><![CDATA[internet control message protocol]]></category>
		<category><![CDATA[necessary tools]]></category>
		<category><![CDATA[network resources]]></category>
		<category><![CDATA[overflow vulnerability]]></category>
		<category><![CDATA[plug and play]]></category>
		<category><![CDATA[security attacks]]></category>
		<category><![CDATA[stack overflow]]></category>

		<guid isPermaLink="false">http://ciscoasa.org.ua/?p=248</guid>
		<description><![CDATA[

Identifying and Classifying Security Threats
Worms and denial of service (DoS) attacks are used maliciously to consume the resources of your hosts and network that would otherwise be used to serve legitimate users. In some cases, misconfigured hosts and servers can send traffic that consumes network resources unnecessarily. Having the necessary tools and mechanisms to identify [...]]]></description>
			<content:encoded><![CDATA[<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:391.92pt;">
<div class=paragraph style=" padding:0.00pt 121.20pt 0.00pt 36.96pt; text-align:left;"><span class=font16 style=" line-height:26.40pt;"><b>Identifying and Classifying Security Threats</b></span></div>
<div class=paragraph style=" padding:17.76pt 37.20pt 0.00pt 90.96pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Worms and denial of service (DoS) attacks are used maliciously to consume the resources of your hosts and network that would otherwise be used to serve legitimate users. In some cases, misconfigured hosts and servers can send traffic that consumes network resources unnecessarily. Having the necessary tools and mechanisms to identify and classify security threats and anomalies in the network is crucial. This chapter presents several best practices and methodologies you can use to successfully and quickly identify and classify such threats.</span></div>
<div class=paragraph style=" padding:6.24pt 37.20pt 0.00pt 90.96pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Most people classify security attacks into two separate categories: <i>logic attacks </i>and <i>resource attacks. </i>Logic attacks exploit existing software deficiencies and vulnerabilities to cause systems to crash, to substantially degrade their performance, or to enable attackers to gain access to a system. An example of this type of attack is the exploit of the Microsoft PnP MS05-039 Overflow Vulnerability, in which the attacker exploits a stack overflow in the Windows &quot;plug and play&quot; (PnP) service. You can exploit this vulnerability on Windows 2000 without a valid user account. Another example is the famous and old <i>ping-of-death, </i>whereby an attacker sends the system Internet Control Message Protocol (ICMP) packets that exceed the maximum legal length (65535 octets). You can prevent most of these attacks by either upgrading the vulnerable software or by filtering particular packet sequences.</span></div>
<div class=paragraph style=" padding:5.76pt 36.72pt 0.00pt 90.96pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The second category of attacks is referred to as resource attacks. The goal with these types of attacks is to overwhelm the victim system/network resources, such as CPU and memory. In most cases, this is done by sending numerous IP packets or forged requests. An attacker can build up a more powerful attack with a more sophisticated and effective method of compromising multiple hosts and installing small attack daemon(s). This is what many call <i>zombies </i>or <i>bot </i>hosts/nets. Subsequently, an attacker can launch a coordinated attack from thousands of zombies onto a single victim. This daemon typically contains both the code for sourcing a variety of attacks and some basic communications infrastructure to allow for remote control. A zombie attack is illustrated in Figure 3-1.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:131.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:84.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:311.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>100    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:25.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 3-1    </b><span class=font43><i>Zombies andBots</i></span></span></div>
<div class=paragraph style=" padding:9.12pt 119.28pt 0.00pt 0.00pt; text-align:right;"><span class=font23>Company A</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:0.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:409.44pt; height:412.56pt; padding:0.00pt 38.88pt 0.00pt 37.68pt;">
<img src="ciscoasa_org_ua-26.jpg" alt="" style=" width:409.44pt; height:412.56pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:137.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 355.68pt; text-align:justify;"><span class=font4>Network Visibility <b>101</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:369.12pt;">
<div class=paragraph style=" padding:0.00pt 42.24pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">In Figure 3-1, an attacker controls compromised hosts in Company A and Company B to attack a web server farm in another organization.</span></div>
<div class=paragraph style=" padding:6.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can use different mechanisms and methodologies to successfully identify and classify these threats/attacks depending on their type. In other words, depending on the threat, you can use specific techniques to identify and classify them accordingly. Following are the most common methodologies:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;The use of anomaly detection tools</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Network telemetry using flow-based analysis</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;The use of intrusion detection and intrusion prevention systems (IDS/IPS)</span></div>
<div class=paragraph style=" padding:2.40pt 38.40pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Analyzing network component logs (that is, SYSLOG from different network devices, accounting records, application logs, Simple Network Management Protocol (SNMP), and so on)</span></div>
<div class=paragraph style=" padding:4.32pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Complete visibility is one of the key requirements when identifying and classifying security threats. The following sections explain best practices for achieving complete network visibility and the use of the previously mentioned tools and mechanisms.</span></div>
<div class=paragraph style=" padding:23.28pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font11><a href="#bookmark23"><a name="bookmark28"><b>N</b></a><b>etwork Visibility</b></a></span></div>
<div class=paragraph style=" padding:3.84pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The first step in the process of preparing your network and staff to successfully identify security threats is achieving complete network visibility. You cannot protect against or mitigate what you cannot view/detect. You can achieve this level of network visibility through existing features on network devices you already have and on devices whose potential you do not even realize. In addition, you should create strategic network diagrams to clearly illustrate your packet flows and where, within the network, you may enable security mechanisms to identify, classify, and mitigate the threat. Remember that network security is a constant war. When defending against the enemy, you must know your own territory and implement defense mechanisms in place. Figure 3-2 illustrates a fairly simple high-level enterprise diagram.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:207.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:87.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:398.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>102    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 281.52pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-2   </b><span class=font43><i>High-Level Enterprise Diagram</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:87.84pt;">
<div class=block style=" width:28.32pt; height:22.08pt; padding:102.24pt 23.52pt 321.12pt 36.00pt;">
<img src="ciscoasa_org_ua-27.jpg" alt="" style=" width:28.32pt; height:22.08pt;"></div>
</td>
<td class=cell valign="top" style=" width:398.16pt;">
<div class=block style="position:relative;  width:332.16pt; height:445.44pt; padding:0.00pt 66.00pt 0.00pt 0.00pt;">
<img src="ciscoasa_org_ua-28.jpg" alt="" style=" width:332.16pt; height:445.44pt;">
<div class=block style=" width:36.96pt; height:28.32pt; position:absolute; left:69.12pt; top:29.28pt;">
<div class=paragraph style=" text-align:justify;"><span class=font13 style=" line-height:28.32pt; letter-spacing:2.00pt;"><b>□lit</b></span></div>
</div>
<div class=block style=" width:43.20pt; height:49.92pt; position:absolute; left:123.36pt; top:34.56pt;">
<div class=paragraph style=" text-align:justify;"><span class=font17 style=" line-height:23.04pt; letter-spacing:1.50pt;">□iii <span style=" letter-spacing:-2.50pt;">г?</span></span></div>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.16pt;">
<div class=paragraph style=" padding:0.00pt 265.68pt 0.00pt 152.64pt; text-align:justify;"><span class=font16 style=" line-height:20.16pt; letter-spacing:-2.50pt;"><b>7Ш</b><span style=" letter-spacing:0.00pt;"><b> </b></span><span class=font11 style=" letter-spacing:5.00pt; font-variant: small-caps;"><b>i«</b></span><span class=font26 style=" letter-spacing:0.00pt; font-variant: small-caps;">b</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:87.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:398.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 355.68pt; text-align:justify;"><span class=font4>Network Visibility <span class=font44><b>103</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:409.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>In Figure 3-2, the following sections are numbered:</span></div>
<div class=paragraph style=" padding:6.96pt 41.76pt 0.00pt 111.84pt; text-align:left; text-indent:-12.00pt;"><span class=font44 style=" line-height:12.00pt;"><b>1&nbsp;The Internet edge: </b>In this example, the enterprise headquarters is connected to the Internet via redundant links. Two Cisco Adaptive Security Appliances (ASA) are configured to protect the infrastructure.</span></div>
<div class=paragraph style=" padding:4.08pt 48.48pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font44 style=" line-height:12.00pt;"><b>2&nbsp;Site-to-Site VPN: </b>The headquarters office is connected to two branches via IPsec site-to-site VPN tunnels terminated on two Cisco IOS routers.</span></div>
<div class=paragraph style=" padding:6.00pt 66.72pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font44 style=" line-height:12.00pt;"><b>3&nbsp;End users: </b>The headquarters building has its sales, finance, engineering, and marketing departments on four separate floors.</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 99.60pt; text-align:left;"><span class=font44><b>4&nbsp;Call center: </b>There is a call center with more than 100 agents on the 5<sup>th</sup> floor.</span></div>
<div class=paragraph style=" padding:6.96pt 57.60pt 0.00pt 111.36pt; text-align:left; text-indent:-12.00pt;"><span class=font44 style=" line-height:11.76pt;"><b>5&nbsp;Data center: </b>The data center includes e-commerce, e-mail, database, and other application servers.</span></div>
<div class=paragraph style=" padding:6.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can create this type of diagram not only to understand the architecture of your organization but also to strategically identify places within the infrastructure where you can implement telemetry mechanisms like NetFlow and identify choke points where you can mitigate an incident. Notice that the access, distribution, and core layers/boundaries are clearly defined.</span></div>
<div class=paragraph style=" padding:5.76pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Look at the example illustrated in Figure 3-3. A workstation at the call center usually communicates over TCP port 80 (HTTP) to a server in the data center. This traffic is allowed within the access control lists because it is legitimate traffic to the server. However, the traffic from this specific workstation increased more than 400 percent over normal. Subsequently, performance on the server is degraded, and the infrastructure is congested with unnecessary packets.</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In this case, NetFlow was configured at the distribution layer switch, and the administrator was able to detect the anomaly. The administrator then configures a host-specific ACL to deny the traffic from the call center workstation, as shown in Figure 3-4. In more sophisticated environments, you can even implement remotely triggered black hole (RTBH) routing to mitigate this incident.</span></div>
<div class=paragraph style=" padding:6.00pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the example illustrated in Figure 3-4, the problem was a defect within the call center workstation application. The administrator was able to perform detailed analysis and patch the machine while preventing disruption of service.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:167.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>104   </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:403.20pt; height:492.00pt; padding:0.00pt 47.28pt 0.00pt 35.52pt;">
<img src="ciscoasa_org_ua-29.jpg" alt="" style=" width:403.20pt; height:492.00pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:75.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:270.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:115.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 355.68pt; text-align:justify;"><span class=font4>Network Visibility <b>105</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 303.60pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-4   </b><span class=font43><i>Abnormal Traffic Stopped</i></span></span></div>
<div class=paragraph style=" padding:37.68pt 0.00pt 0.00pt 154.08pt; text-align:left;"><span class=font16 style=" letter-spacing:-2.50pt;"><b>till</b></span></div>
<div class=paragraph style=" padding:1.92pt 0.00pt 0.00pt 154.08pt; text-align:left;"><span class=font49 style=" line-height:24.72pt; letter-spacing:-2.50pt;"><b>nil</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:75.36pt;">
<div class=block style=" width:28.80pt; height:22.56pt; padding:101.76pt 11.04pt 2.88pt 35.52pt;">
<img src="ciscoasa_org_ua-30.jpg" alt="" style=" width:28.80pt; height:22.56pt;"></div>
</td>
<td class=cell colspan="3" rowspan="2" valign="top" style=" width:410.64pt;">
<div class=block style=" width:364.32pt; height:444.96pt; padding:0.00pt 46.32pt 0.00pt 0.00pt;">
<img src="ciscoasa_org_ua-31.jpg" alt="" style=" width:364.32pt; height:444.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:75.36pt;">
<div class=block style=" width:75.36pt; height:317.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 49.20pt; text-align:left;"><span class=font0><b><u>Jan   I</u> </b><span class=font23>Л</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 54.24pt; text-align:left;"><span class=font11 style=" letter-spacing:5.00pt; font-variant: small-caps;"><b>1</b><span class=font6 style=" letter-spacing:-1.00pt; font-variant: normal;">.1</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 55.68pt; text-align:left;"><span class=font43><b>со з= \.</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:345.36pt;">
<div class=block style=" width:345.36pt; height:14.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:25.20pt;">
<div class=block style=" width:25.20pt; height:14.88pt;">
<div class=paragraph style=" text-align:justify;"><span class=font36 style=" line-height:14.88pt; letter-spacing:0.50pt;"><b>НИ</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:115.44pt;">
<div class=block style=" width:115.44pt; height:14.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:85.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:75.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:270.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:25.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:115.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:147.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:128.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:59.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:150.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>106    </b>Chapter <span class=font24 style=" letter-spacing:-1.00pt;">3: </span>Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:92.88pt;">
<div class=paragraph style=" padding:0.00pt 42.72pt 0.00pt 36.00pt; text-align:justify;"><span class=font4 style=" line-height:11.76pt;"><b>TIP&nbsp;</b><span class=font44>To detect abnormal and possibly malicious activity, you must first establish a baseline of</span></span></div>
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">normal network activity, traffic patterns, and other factors. NetFlow, as well as other mechanisms, can be enabled within your infrastructure to successfully identify and classify threats and anomalies. Prior to implementing an anomaly-detection system, you should perform traffic analysis to gain an understanding of general traffic rates and patterns. In anomaly detection systems, learning is generally performed over a significant interval, including both the peaks and valleys of network activity. Anomaly detection and telemetry are covered in detail later in this chapter.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:91.44pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can also develop a different type of diagram to visualize operational risks within your organization. These diagrams are based on device roles and can be developed for critical systems you want to protect. For example, identify a critical system within your organization and create a layered diagram similar to the one in Figure 3-5. In this example, a database called ABC is the most critical application/data source for this company. The diagram presents ABC Database Server in the center.</span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 3-5   </b><span class=font43><i>Layered Diagram for Visualizing Risk</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:147.12pt;">
<div class=block style=" width:147.12pt; height:81.12pt;">
<div class=paragraph style=" padding:63.12pt 19.92pt 0.00pt 76.08pt; text-align:justify;"><span class=font3>Internet *&amp;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:128.88pt;">
<div class=block style=" width:128.88pt; height:81.12pt;">
<div class=paragraph style=" padding:16.56pt 0.00pt 0.00pt 57.12pt; text-align:left;"><span class=font3>Sales</span></div>
<div class=paragraph style=" padding:1.68pt 30.48pt 0.00pt 57.36pt; text-align:justify;"><span class=font3>Department</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:210.00pt;">
<div class=block style=" width:210.00pt; height:81.12pt;">
<div class=paragraph style=" padding:0.00pt 72.00pt 0.00pt 59.52pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">ABC Database Server in the Data Center</span></div>
<div class=paragraph style=" padding:7.68pt 69.12pt 0.00pt 59.28pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">Data Center Access and Distribution Layers (Data Center Firewalls reside here)</span></div>
<div class=paragraph style=" padding:10.80pt 0.00pt 0.00pt 59.76pt; text-align:left;"><span class=font3>Core</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 88.80pt 0.00pt 335.52pt; text-align:justify;"><span class=font3>Distribution Layer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:335.28pt;">
<div class=block style=" width:82.56pt; height:82.32pt; padding:0.00pt 105.60pt 0.00pt 147.12pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:82.56pt; height:82.32pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:41.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:41.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:41.28pt;">
<div class=block style=" width:41.28pt; height:41.04pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:41.28pt;">
<div class=block style=" width:41.28pt; height:41.04pt;">
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 0.96pt; text-align:left;"><span class=font18 style=" line-height:40.32pt; letter-spacing:-6.00pt; font-variant: small-caps;"><b>^0</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:41.28pt;">
<div class=block style=" width:41.28pt; height:41.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:41.28pt;">
<div class=block style=" width:41.28pt; height:41.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:41.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:41.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:150.72pt;">
<div class=block style=" width:150.72pt; height:82.32pt;">
<div class=paragraph style=" padding:31.92pt 102.00pt 0.00pt 0.72pt; text-align:justify;"><span class=font3>Access Layer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:147.12pt;">
<div class=block style=" width:147.12pt; height:14.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 113.28pt; text-align:left;"><span class=font44>4&gt;</span></div>
<div class=paragraph style=" padding:0.00pt 24.24pt 0.00pt 70.08pt; text-align:justify;"><span class=font3>Branch <span class=font43><i>Q,</i></span></span></div>
</div>
</td>
<td class=cell colspan="3" rowspan="2" valign="top" style=" width:338.88pt;">
<div class=block style=" width:338.88pt; height:20.88pt;">
<div class=paragraph style=" padding:8.88pt 147.60pt 0.00pt 128.88pt; text-align:justify;"><span class=font3>Call Center Users</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:147.12pt;">
<div class=block style=" width:147.12pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 52.80pt 0.00pt 70.08pt; text-align:justify;"><span class=font3>Offices</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:96.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:147.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:128.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:59.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:150.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:69.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:263.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:152.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 355.68pt; text-align:justify;"><span class=font4>Network Visibility <b>107</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:56.88pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can use this type of diagram to audit device roles and the type of services they should be running. For example, you can decide in what devices you can run services like Cisco NetFlow or where to enforce security policies. In addition, you can see the life of a packet within your infrastructure depending on the source and destination. An example is illustrated in Figure 3-6.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 303.12pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-6   </b><span class=font43><i>Illustrating a Packet Flow</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="4" valign="top" style=" width:69.60pt;">
<div class=block style=" width:69.60pt; height:273.36pt;">
<div class=paragraph style=" padding:69.84pt 0.00pt 0.00pt 68.64pt; text-align:justify;"><span class=font3>Internet</span></div>
</div>
</td>
<td class=cell rowspan="4" valign="top" style=" width:263.52pt;">
<div class=block style="position:relative;  width:263.52pt; height:264.48pt; padding:8.88pt 0.00pt 0.00pt 0.00pt;">
<img src="ciscoasa_org_ua-32.jpg" alt="" style=" width:263.52pt; height:264.48pt;">
<div class=block style=" width:41.28pt; height:17.28pt; position:absolute; left:135.36pt; top:14.16pt;">
<div class=paragraph style=" text-align:left;"><span class=font3>Sales</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 0.24pt; text-align:justify;"><span class=font3>Department</span></div>
</div>
<div class=block style=" width:24.48pt; height:17.04pt; position:absolute; left:4.56pt; top:233.28pt;">
<div class=paragraph style=" text-align:justify;"><span class=font3 style=" line-height:9.60pt;">Branch Offices</span></div>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:152.88pt;">
<div class=block style=" width:152.88pt; height:102.00pt;">
<div class=paragraph style=" padding:0.00pt 71.28pt 0.00pt 3.12pt; text-align:justify;"><span class=font3 style=" line-height:9.60pt;">ABC Database Server in the Data Center</span></div>
<div class=paragraph style=" padding:7.68pt 68.40pt 0.00pt 2.88pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">Data Center Access and Distribution Layers (Data Center Firewalls reside here)</span></div>
<div class=paragraph style=" padding:11.04pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font3>Core</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:152.88pt;">
<div class=block style=" width:152.88pt; height:41.76pt;">
<div class=paragraph style=" padding:0.00pt 88.08pt 0.00pt 3.12pt; text-align:justify;"><span class=font3>Distribution Layer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:152.88pt;">
<div class=block style=" width:152.88pt; height:90.48pt;">
<div class=paragraph style=" padding:0.00pt 101.28pt 0.00pt 3.60pt; text-align:justify;"><span class=font3>Access Layer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:152.88pt;">
<div class=block style=" width:152.88pt; height:39.12pt;">
<div class=paragraph style=" padding:0.00pt 146.40pt 0.00pt 0.00pt; text-align:justify;"><span class=font3>Call Center Users</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:18.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 50.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Figure 3-6 shows the packet flow that occurs when a user from the sales department accesses an Internet site. You know exactly where the packet is going based on your architecture and your security and routing policies. This is a simple example; however, you can use this concept to visualize risks and to prepare your isolation policies.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.20pt;">
<div class=paragraph style=" padding:0.00pt 68.40pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>Additional examples and techniques are covered in Chapter 7, &quot;Proactive Security Framework.&quot;</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:104.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:69.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:263.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:152.88pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>108    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:235.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font11><a href="#bookmark22"><a name="bookmark29"><b>T</b></a><b>elemetry and Anomaly Detection</b></a></span></div>
<div class=paragraph style=" padding:3.36pt 45.36pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Anomaly detection systems passively monitor network traffic, looking for any deviation from &quot;normal&quot; or &quot;baseline&quot; behavior that may indicate a security threat or a misconfiguration. You can use several commercial tools and even open source tools to successfully identify security threats within your network. These tools include the following:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco NetFlow</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Security Monitoring, Analysis and Response System (CS-MARS)</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Traffic Anomaly Detectors and Cisco Guard DDoS Mitigation Appliances</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco IPS sensors (Version 6.x and later)</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Network Analysis Module (NAM)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Open Source Monitoring tools</span></div>
<div class=paragraph style=" padding:1.92pt 40.08pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The following are other technologies and tools you can use to achieve complete visibility of what is happening within your network:</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Syslog</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;SNMP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:220.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.72pt; text-align:left;"><span class=font8><b>NetFlow</b></span></div>
<div class=paragraph style=" padding:3.60pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Cisco NetFlow was initially introduced as a packet accounting system for network administration and, in some cases, for billing. However, today you can use NetFlow to listen to the network itself, thereby gaining valuable insight into the overall security state of the network. This is why it is classified as a form of telemetry that provides information about traffic passing through or directly to each router or switch.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44>NetFlow is supported in the following Cisco platforms:</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco 1700</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco 1800</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco 2800</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco 3800</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco 4500</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco 7200</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco 7300</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco 7500</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:92.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>109</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:39.12pt;">
<div class=paragraph style=" padding:0.00pt 168.72pt 0.00pt 111.60pt; text-align:justify;"><span class=font44>Cisco 7600/6500 (hybrid and native configurations)</span></div>
<div class=paragraph style=" padding:2.88pt 324.48pt 0.00pt 111.60pt; text-align:justify;"><span class=font44 style=" line-height:15.84pt;">Cisco 10000 Cisco 12000</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph style=" padding:0.00pt 113.76pt 0.00pt 36.48pt; text-align:right;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>Indicated models have platform-specific considerations. Please refer to <a href="http://www.cisco.com/go/netflow">http://www.cisco.com/go/netflow</a> for more compatibility information.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:384.72pt;">
<div class=paragraph style=" padding:0.00pt 64.32pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The word <i>netflow </i>is a combination of <i>net </i>(or network) and <i>flow. </i>What is a <i>flow? </i>An individual flow comprises, at a minimum, the following elements:</span></div>
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Source IP address.</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Destination IP address.</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Protocol.</span></div>
<div class=paragraph style=" padding:1.92pt 51.60pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.24pt;">•&nbsp;Source port number. (With certain protocols, this can be a type/code or any other construct—for example, ICMP.)</span></div>
<div class=paragraph style=" padding:3.60pt 38.16pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Destination port number. (With certain protocols, this can be a type/code or any other construct—for example, ICMP.)</span></div>
<div class=paragraph style=" padding:4.08pt 41.04pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">NetFlow also can give you information about network traffic. This information varies somewhat depending on what version of NetFlow Data Export (NDE) you run. The most commonly deployed versions are Versions 5 and 9. Following is some of the additional information you can obtain from a flow in NetFlow Version 5:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Start time of the flow.</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;End time of the flow.</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Number of packets in the flow.</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Amount of data transferred in the flow.</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Type of Service (ToS) bits present in the flow or Differentiated Services Code Point</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 111.84pt; text-align:left;"><span class=font44>(DSCP) type.</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Logical OR of all TCP flags present in TCP-based flows (platform-specific caveats</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 111.60pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">apply).</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Input interface ifIndex.</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Output interface ifIndex.</span></div>
<div class=paragraph style=" padding:2.40pt 55.44pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Origin-AS or destination-AS information, if Border Gateway Protocol (BGP) is enabled on the routers/Layer 3 switches in question. (The selection of origin- or destination-AS reporting is made during the configuration of NetFlow on each device.)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:65.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>110    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:123.12pt;">
<div class=paragraph style=" padding:0.00pt 53.76pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;BGP next-hop information, if BGP is enabled on the routers/Layer 3 switches in question.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Fragmentation information (known as <i>fragmentation bit).</i></span></div>
<div class=paragraph style=" padding:4.56pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">All this information can be exported to monitoring systems for further analysis. NetFlow Version 9 supports the same reporting capabilities as NetFlow Version 5 with some additional information. One of the biggest advantages of NetFlow Version 9 is its ability to be configured by the use of templates to use various features to export additional or different information to external systems. In NetFlow Version 5 and earlier, you can export the flow data over UDP. NetFlow Version 9 supports NDE via TCP and SCTP, as well as the classic UDP mode.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 147.36pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>All new NetFlow development is based on NetFlow Version 9.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:111.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In NetFlow Version 9, you can use a template describing the NDE fields within the flow information. This template information is contained in the first NetFlow Version 9 NDE packets sent to the NDE destination (monitoring system) after NDE is enabled on the router or switch. This information is also periodically retransmitted. When the configuration of NDE fields is changed on the router or switch, the updated template is immediately transmitted.</span></div>
<div class=paragraph style=" padding:6.24pt 44.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The IETF Internet Protocol Flow Information eXport (IPFIX) working group (WG) has been tasked with developing a common standard for IP-based flow export. This working group has selected Cisco NetFlow Version 9 as the technology of choice.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.20pt;">
<div class=paragraph style=" padding:0.00pt 46.08pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>The IPFIX requirements are defined in RFC 3917. RFC 3954 explains the evaluation of NetFlow Version 9 in IPFIX. The actual outcome and the criteria for the selection of NetFlow Version 9 as the basis for the IPFIX standard are defined in RFC 3955.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">It is recommended that you use an isolated out-of-band (OOB) management network to allow you to access and control NetFlow-enabled devices over the network, even when you are under attack or during any security incident or network malfunction. When you transmit network telemetry over the OOB network, you reduce the chance for disruption of the information that provides insightful network visibility.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:111.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.68pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>111</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:112.32pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font6>Enabling NetFlow</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>Typically, enabling NetFlow on software-based platforms consists of one or two steps:</span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Enabling NetFlow on the relevant physical and logical interfaces</span></div>
<div class=paragraph style=" padding:5.04pt 38.64pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;(Optional) Enabling the device (NDE) to export the flow information from the device to an external monitoring system</span></div>
<div class=paragraph style=" padding:4.08pt 38.16pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">When you configure NetFlow, you must decide between ingress or egress NetFlow for each device. This decision depends on the use and the topology. You can also enable NetFlow for both ingress and egress.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 58.32pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>Egress NetFlow is dependent on the version of Cisco IOS you are running. For more information, go to <a href="http://www.cisco.com/go/fn">http://www.cisco.com/go/fn.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:34.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:91.68pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The following example shows how you can enable <i>ingress </i>NetFlow on a particular interface (GigabitEthernet0/0 in this case):</span></div>
<div class=paragraph style=" padding:6.48pt 197.04pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myrouter#configure terminal myrouter(config)#interface GigabitEthernet0/0 myrouter(config-if)#ip flow ingress</span></div>
<div class=paragraph style=" padding:5.52pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>To enable egress NetFlow, use the <b>ip flow egress </b>interface subcommand as follows:</span></div>
<div class=paragraph style=" padding:7.20pt 197.04pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myrouter(config)#interface GigabitEthernet0/0 myrouter(configif)#ip flow egress</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:78.96pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 89.76pt; text-align:justify; text-indent:-53.28pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE </b><span class=font44>Ingress NetFlow is the most commonly used method. Egress NetFlow is more commonly used with MPLS VPN. The MPLS Egress NetFlow Accounting feature allows you to capture IP flow information for packets undergoing MPLS label disposition. In other words, it captures packets that arrive on a router as MPLS packets and are transmitted as IP packets. Egress NetFlow accounting might adversely affect network performance because of the additional accounting-related computations that occur in the traffic-forwarding path of the router.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:52.32pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The following example shows how to configure the NetFlow-enabled device to export the flow data to a monitoring system:</span></div>
<div class=paragraph style=" padding:6.48pt 124.08pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">myrouter(config)#ip flow-export version 5 myrouter(config)#ip flow-export source loopback 0 myrouter(config)#ip flow-export destination 172.18.85.190 2055</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:89.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:161.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:142.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:182.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>112    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:114.48pt;">
<div class=paragraph style=" padding:0.00pt 54.24pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In this example, NDE Version 5 is used. All NetFlow export packets are sourced from a loopback interface configured in the router (loopback 0). The destination is a Cisco Secure Monitoring and Response System (CS-MARS) box with the IP address 172.18.85.190 and the destination UDP port 2055.</span></div>
<div class=paragraph style=" padding:6.00pt 42.24pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">It is recommended that you alter the setting of the active flow timeout parameter from its default of 30 minutes to the minimum value of one minute. This helps you achieve an environment that is closer to real time. You can do this with the <b>ip flow-cache timeout active </b>command, as shown here:</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23>myrouter(config)#ip flow-cache timeout active 1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.84pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>The default value for the number of minutes that an active flow remains in the cache before it times out is 30.</span></span></div>
<div class=paragraph style=" padding:3.12pt 52.32pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The default value for the number of seconds that an inactive flow remains in the cache before it times out is 15.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:37.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:53.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font6>Collecting NetFlow Statistics from the CLI</span></div>
<div class=paragraph style=" padding:3.84pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">To view the basic NetFlow information from the CLI, you can use the <b>show ip cache flow </b>command, as shown in Example 3-1:</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 3-1   </b><span class=font43><i>Output of the </i><b>show ip cache flow </b><i>Command</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>myrouter#show ip cache flow</span></div>
<div class=paragraph style=" padding:1.92pt 177.12pt 0.00pt 97.20pt; text-align:justify;"><span class=font23>IP packet size distribution (9257M total packets):</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:303.84pt;">
<div class=block style=" width:303.84pt; height:14.88pt;">
<div class=paragraph style=" padding:0.00pt 6.72pt 0.00pt 109.92pt; text-align:justify;"><span class=font23 style=" line-height:9.84pt;">1-32 64 96 128 160 192 224 256 288 .088  .314  .011   .011   .027  .001   .007 .001 .013</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:182.16pt;">
<div class=block style=" width:182.16pt; height:14.88pt;">
<div class=paragraph style=" padding:0.00pt 60.00pt 0.00pt 2.88pt; text-align:justify;"><span class=font23>320  352  384  416  448 480</span></div>
<div class=paragraph style=" padding:1.92pt 60.24pt 0.00pt 0.00pt; text-align:justify;"><span class=font23>.016  .002 .002  .000  .001 .000</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:84.48pt;">
<div class=paragraph style=" padding:0.00pt 145.92pt 0.00pt 0.00pt; text-align:right;"><span class=font23>512  544  576 1024 1536 2048 2560 3072 3584 4096 4608</span></div>
<div class=paragraph style=" padding:1.20pt 145.68pt 0.00pt 0.00pt; text-align:right;"><span class=font23>.000 .001 .002 .043 .452 .000 .000 .000 .000 .000 .000</span></div>
<div class=paragraph style=" padding:11.28pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23>IP Flow Switching Cache, 4456704 bytes</span></div>
<div class=paragraph style=" padding:0.96pt 192.96pt 0.00pt 104.88pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">43 active, 65493 inactive, 884110623 added 3341579080 ager polls, 0 flow alloc failures Active flows timeout in 30 minutes Inactive flows timeout in 15 seconds last clearing of statistics never</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:161.52pt;">
<div class=block style=" width:161.52pt; height:37.68pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23>Protocol</span></div>
<div class=paragraph style=" padding:10.32pt 23.28pt 0.00pt 96.72pt; text-align:justify;"><span class=font23 style=" line-height:9.84pt;">TCP-Telnet TCP-FTP</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:324.48pt;">
<div class=block style=" width:324.48pt; height:37.68pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23 style=" line-height:9.84pt;">Total&nbsp;Flows&nbsp;Packets Bytes&nbsp;Packets Active(Sec)&nbsp;Idle(Sec)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.40pt; text-align:left;"><span class=font23 style=" line-height:9.84pt;">Flows&nbsp;/Sec&nbsp;/Flow   /Pkt        /Sec        /Flow&nbsp;/Flow</span></div>
<div class=paragraph style=" text-align:left;"><span class=font23 style=" line-height:9.84pt;">1072696&nbsp;0.2&nbsp;17   578       4.4        9.8&nbsp;15.3</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font23 style=" line-height:9.84pt;">33386&nbsp;0.0&nbsp;2392     57      18.6      697.2&nbsp;7.6</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="3" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:114.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:161.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:142.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:182.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:10.56pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>113</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph style=" padding:0.00pt 191.28pt 0.00pt 36.24pt; text-align:justify;"><span class=font3><b>Example 3-1   </b><span class=font43><i>Output of the </i><b>show ip cache flow </b><i>Command (Continued)</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:355.44pt; height:380.40pt; padding:0.00pt 35.28pt 0.00pt 95.28pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:355.44pt; height:380.40pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:71.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:27.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:46.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:12.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:22.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:19.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:45.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:10.32pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>TCP-FTPD</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:10.32pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 30.48pt; text-align:left;"><span class=font23>2967</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:10.32pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:10.32pt;">
<div class=paragraph style=" padding:1.20pt 5.28pt 0.00pt 0.00pt; text-align:right;"><span class=font23>2869</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:10.32pt;">
<div class=paragraph style=" padding:1.20pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>1049</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:10.32pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 19.68pt; text-align:left;"><span class=font23>1.9</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:10.32pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:10.32pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>4.3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:10.32pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:10.32pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>TCP-WWW</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 17.52pt; text-align:left;"><span class=font23>9091735</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>2.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 5.28pt 0.00pt 0.00pt; text-align:right;"><span class=font23>222</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>904</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.56pt; text-align:left;"><span class=font23>470.3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>6.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 3.84pt; text-align:left;"><span class=font23>5.6</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>TCP-SMTP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.60pt; text-align:left;"><span class=font23>538619</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 6.72pt 0.00pt 0.00pt; text-align:right;"><span class=font23>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>59</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.44pt; text-align:left;"><span class=font23>0.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>6.9</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.9</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>TCP-X</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 30.24pt; text-align:left;"><span class=font23>3246</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 5.28pt 0.00pt 0.00pt; text-align:right;"><span class=font23>44</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>909</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.44pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>0.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>13.4</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>TCP-BGP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.84pt; text-align:left;"><span class=font23>280550</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 5.52pt 0.00pt 0.00pt; text-align:right;"><span class=font23>2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>44</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.44pt; text-align:left;"><span class=font23>0.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>7.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.8</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>TCP-NNTP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 30.48pt; text-align:left;"><span class=font23>2306</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 6.72pt 0.00pt 0.00pt; text-align:right;"><span class=font23>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>46</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.44pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>18.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>TCP-Frag</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 43.44pt; text-align:left;"><span class=font23>7</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 5.52pt 0.00pt 0.00pt; text-align:right;"><span class=font23>19</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>152</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.44pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>8.8</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.4</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>TCP-other</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:107.28pt;">
<div class=block style=" width:107.28pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.20pt; text-align:left;"><span class=font23>48037166 11.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 5.52pt 0.00pt 0.00pt; text-align:right;"><span class=font23>115</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>887</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 6.96pt; text-align:left;"><span class=font23>1289.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>4.5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font23>6.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>UDP-DNS</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 18.00pt; text-align:left;"><span class=font23>1043579</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 5.52pt 0.00pt 0.00pt; text-align:right;"><span class=font23>2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>74</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.44pt; text-align:left;"><span class=font23>0.4</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>3.9</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.9</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>UDP-NTP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 21.84pt; text-align:left;"><span class=font23>891663</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 6.72pt 0.00pt 0.00pt; text-align:right;"><span class=font23>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>79</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.44pt; text-align:left;"><span class=font23>0.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>UDP-TFTP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 22.08pt; text-align:left;"><span class=font23>138376</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 5.52pt 0.00pt 0.00pt; text-align:right;"><span class=font23>7</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>55</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.44pt; text-align:left;"><span class=font23>0.2</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:34.80pt;">
<div class=block style=" width:34.80pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 4.56pt; text-align:center;"><span class=font23>21.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>UDP-Frag</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 30.24pt; text-align:left;"><span class=font23>9736</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 5.52pt 0.00pt 0.00pt; text-align:right;"><span class=font23>182</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>1366</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.44pt; text-align:left;"><span class=font23>0.4</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:34.80pt;">
<div class=block style=" width:34.80pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.60pt; text-align:center;"><span class=font23>22.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.4</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>UDP-other</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:107.28pt;">
<div class=block style=" width:107.28pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 9.12pt; text-align:left;"><span class=font23>816395802 190.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 6.72pt 0.00pt 0.00pt; text-align:right;"><span class=font23>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>109</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.56pt; text-align:left;"><span class=font23>316.9</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>0.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>18.8</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>ICMP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 17.76pt; text-align:left;"><span class=font23>6533952</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>1.5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 5.52pt 0.00pt 0.00pt; text-align:right;"><span class=font23>13</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>95</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 15.12pt; text-align:left;"><span class=font23>20.5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>8.3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>GRE</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 34.80pt; text-align:left;"><span class=font23>239</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 6.48pt 0.00pt 0.00pt; text-align:right;"><span class=font23>41</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>97</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.44pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:34.80pt;">
<div class=block style=" width:34.80pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 4.56pt; text-align:center;"><span class=font23>66.9</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>IP-other</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 25.92pt; text-align:left;"><span class=font23>34558</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 5.28pt 0.00pt 0.00pt; text-align:right;"><span class=font23>3907</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>156</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 14.88pt; text-align:left;"><span class=font23>31.4</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:34.80pt;">
<div class=block style=" width:34.80pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.60pt; text-align:center;"><span class=font23>66.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>15.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font23>Total:</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:107.28pt;">
<div class=block style=" width:107.28pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 9.12pt; text-align:left;"><span class=font23>884110583 205.8</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 5.52pt 0.00pt 0.00pt; text-align:right;"><span class=font23>10</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:27.60pt;">
<div class=block style=" width:27.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 7.20pt 0.00pt 0.00pt; text-align:right;"><span class=font23>750</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:46.32pt;">
<div class=block style=" width:46.32pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font23>2155.4</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>0.5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 0.00pt; text-align:left;"><span class=font23>17.9</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font23>SrcIf</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 13.44pt; text-align:left;"><span class=font23>SrcIPaddress</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 10.08pt; text-align:left;"><span class=font23>DstIf</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 8.40pt; text-align:left;"><span class=font23>DstIPaddress</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>Pr</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>SrcP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>DstP</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>Pkts</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.38.1.9</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 10.08pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.40pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>0044</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0043</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.60pt; text-align:left;"><span class=font23>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.44pt; text-align:left;"><span class=font23>0.0.0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 10.08pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.40pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>0044</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0043</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 12.72pt; text-align:left;"><span class=font23>209</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>172.18.173.68</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.1.208</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>05BC</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>01BB</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 12.48pt; text-align:left;"><span class=font23>452</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>172.18.173.68</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.1.186</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>0631</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>01BB</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 12.48pt; text-align:left;"><span class=font23>388</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.36.1.120</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 10.08pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>008A</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>008A</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.12pt; text-align:left;"><span class=font23>3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.36.1.120</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 10.08pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>008A</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>008A</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.12pt; text-align:left;"><span class=font23>3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>172.18.124.223</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.197.213</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>8107</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>2323</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>1547</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>172.18.124.66</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 10.08pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.1.184</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>EC83</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>01BB</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.60pt; text-align:left;"><span class=font23>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.36.8.48</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>172.18.124.154</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font23>15FE</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0FA5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.60pt; text-align:left;"><span class=font23>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.36.8.48</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>172.18.124.154</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font23>15FF</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0FA5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.60pt; text-align:left;"><span class=font23>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.36.8.48</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>172.18.124.154</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font23>15FD</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0FA5</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.60pt; text-align:left;"><span class=font23>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.36.1.3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>172.18.123.69</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>01</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>0000</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0303</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.12pt; text-align:left;"><span class=font23>3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.36.8.36</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>172.18.124.66</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>0202</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0202</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 21.12pt; text-align:left;"><span class=font23>4</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.36.99.77</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>172.18.124.225</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>01BB</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>137C</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 17.04pt; text-align:left;"><span class=font23>85</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.36.197.213</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>172.18.124.223</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>2323</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>8107</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 12.72pt; text-align:left;"><span class=font23>780</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>172.18.124.223</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.1.203</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>8105</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>2323</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>19992167</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>172.18.85.169</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 9.60pt; text-align:left;"><span class=font23>Local</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.1.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>8E5E</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0017</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 16.80pt; text-align:left;"><span class=font23>97</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>172.18.124.225</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.99.77</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font23>137C</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>01BB</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 17.04pt; text-align:left;"><span class=font23>85</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>172.18.124.128</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.1.128</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>916E</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>2323</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 12.96pt; text-align:left;"><span class=font23>138</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>172.18.124.128</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>14.36.1.128</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>916D</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>2323</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 16.80pt; text-align:left;"><span class=font23>54</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt;">
<div class=block style=" width:48.24pt; height:10.32pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:71.76pt;">
<div class=block style=" width:71.76pt; height:10.32pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font23>14.36.1.208</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:35.52pt;">
<div class=block style=" width:35.52pt; height:10.32pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 10.32pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:10.32pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:73.92pt;">
<div class=block style=" width:73.92pt; height:10.32pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 8.64pt; text-align:left;"><span class=font23>172.18.173.68</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.72pt;">
<div class=block style=" width:12.72pt; height:10.32pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:22.08pt;">
<div class=block style=" width:22.08pt; height:10.32pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.36pt; text-align:left;"><span class=font23>01BB</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:10.32pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>05BC</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:45.12pt;">
<div class=block style=" width:45.12pt; height:10.32pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 12.72pt; text-align:left;"><span class=font23>678</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:71.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:35.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:27.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:46.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:12.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:22.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:19.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:45.12pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:17.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.64pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In the highlighted line, you can see that a host (172.18.124.223 is sending 19,992,167 packets to 14.36.1.203. This may be abnormal behavior or an infected machine. The protocol is 06 (TCP), the source port is 33029 (Hex 8105), and the destination port is 8995 (Hex 2323).</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:119.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>114   </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph style=" padding:0.00pt 41.04pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">You can also obtain export flow information using the <b>show ip flow export </b>command, as shown in Example 3-2:</span></div>
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 3-2  </b><span class=font43><i>Output of the </i><b>show ip flow export </b><i>Command</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:113.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">myrouter#show ip flow export</span></div>
<div class=paragraph style=" padding:0.00pt 180.24pt 0.00pt 105.12pt; text-align:left; text-indent:-7.92pt;"><span class=font23 style=" line-height:9.60pt;">Flow export v5 is enabled for main cache Exporting flows to 172.18.85.190 (2055) Exporting using source IP address 172.18.124.47 Version 5 flow records</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">884111088 flows exported in 31352026 udp datagrams</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">0 flows failed due to lack of export packet</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.12pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">4 export packets were sent up to process level</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">0 export packets were dropped due to no fib</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">0 export packets were dropped due to adjacency issues</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">0 export packets were dropped due to fragmentation failures</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.36pt; text-align:left;"><span class=font23 style=" line-height:9.60pt;">0 export packets were dropped due to encapsulation fixup failures</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:22.08pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:144.00pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Example 3-2, you can see that the router is exporting the NetFlow information to the 172.18.85.190 device (a CS-MARS in this case) over UDP port 2055. The source IP address is 172.18.124.47. A total of 884,111,088 flows have been exported in 31,352,026 UDP datagrams. Please note that all protocol numbers, source ports, and TCP/UDP destination ports are shown in hexadecimal. ICMP packets are represented with the source port field set to 0000, the first two bytes of the destination field set to the ICMP type, and the second two bytes to the ICMP code. If you are using features such as policy-based routing (PBR), Web Cache Communications Protocol (WCCP), Network Address Translation (NAT), or Unicast Reverse Path Forwarding (uRPF) ACLs, you will see a (DstIf) value of <i>Null. </i>To see packet drops caused by ACLs, uRPF, PBR, or null routes, use the <b>show ip cache flow </b>with the <b>include Null </b>option, as shown in Example 3-3:</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 3-3  </b><span class=font43><i>Output of the </i><b>show ip cache flow | include Null </b><i>Command</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph style=" padding:0.00pt 212.88pt 0.00pt 96.96pt; text-align:justify;"><span class=font23>myrouter#show ip cache flow | include Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:1.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:346.32pt; height:58.80pt; padding:0.00pt 45.60pt 0.00pt 94.08pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:346.32pt; height:58.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:83.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:87.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:12.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:83.04pt;">
<div class=block style=" width:83.04pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 19.92pt; text-align:left;"><span class=font23>14.36.1.8</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:87.60pt;">
<div class=block style=" width:87.60pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 21.84pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.96pt;">
<div class=block style=" width:12.96pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>0044</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0043</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 11.52pt 0.00pt 0.00pt; text-align:right;"><span class=font23>1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>Fa1/1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:83.04pt;">
<div class=block style=" width:83.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.68pt; text-align:left;"><span class=font23>0.0.0.0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:87.60pt;">
<div class=block style=" width:87.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 21.84pt; text-align:left;"><span class=font23>255.255.255.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.96pt;">
<div class=block style=" width:12.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>0044</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0043</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 11.28pt 0.00pt 0.00pt; text-align:right;"><span class=font23>891</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:83.04pt;">
<div class=block style=" width:83.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 19.92pt; text-align:left;"><span class=font23>172.18.124.66</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:87.60pt;">
<div class=block style=" width:87.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 22.08pt; text-align:left;"><span class=font23>14.36.1.184</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.96pt;">
<div class=block style=" width:12.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>80AC</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>01BB</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 10.32pt 0.00pt 0.00pt; text-align:right;"><span class=font23>3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>Fa0/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:83.04pt;">
<div class=block style=" width:83.04pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.92pt; text-align:left;"><span class=font23>14.1.17.111</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:87.60pt;">
<div class=block style=" width:87.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 22.08pt; text-align:left;"><span class=font23>14.38.201.1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.96pt;">
<div class=block style=" width:12.96pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>06</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>51CD</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>00B3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.84pt;">
<div class=paragraph style=" padding:0.48pt 10.32pt 0.00pt 0.00pt; text-align:right;"><span class=font23>2</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:83.04pt;">
<div class=block style=" width:83.04pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 19.92pt; text-align:left;"><span class=font23>172.18.124.11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:87.60pt;">
<div class=block style=" width:87.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 22.08pt; text-align:left;"><span class=font23>172.18.124.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.96pt;">
<div class=block style=" width:12.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>0089</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>0089</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:9.60pt;">
<div class=paragraph style=" padding:0.48pt 10.32pt 0.00pt 0.00pt; text-align:right;"><span class=font23>18</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:10.80pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>Fa1/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:83.04pt;">
<div class=block style=" width:83.04pt; height:10.80pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 19.92pt; text-align:left;"><span class=font23>172.18.124.153</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font23>Null</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:87.60pt;">
<div class=block style=" width:87.60pt; height:10.80pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 22.08pt; text-align:left;"><span class=font23>172.18.124.255</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:12.96pt;">
<div class=block style=" width:12.96pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 3.12pt; text-align:left;"><span class=font23>11</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:21.60pt;">
<div class=block style=" width:21.60pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.88pt; text-align:left;"><span class=font23>008A</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:26.16pt;">
<div class=block style=" width:26.16pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>008A</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:28.56pt;">
<div class=block style=" width:28.56pt; height:10.80pt;">
<div class=paragraph style=" padding:0.48pt 10.08pt 0.00pt 0.00pt; text-align:right;"><span class=font23>3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:83.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:87.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:12.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:21.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:26.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:28.56pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:98.16pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">To see flows that contain thousands or millions of packets, you can use <b>show ip cache flow | include K </b>or <b>show ip cache flow | include M </b>commands, respectively.</span></div>
<div class=paragraph style=" padding:6.00pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The Cisco Catalyst 6500 switches and Cisco 7600 router obtain NetFlow information via the Multilayer Switching (MLS) cache. In addition, the amount and type of data recorded in the table must be selected. The <b>mls flow ip interface-full </b>command provides the most useful information and can be configured as follows:</span></div>
<div class=paragraph style=" padding:6.24pt 213.84pt 0.00pt 97.20pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">CAT6k(config)# mls flow ip interface-full CAT6k(config)# mls nde interface</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:59.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:90.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>115</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:44.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:139.68pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>TIP&nbsp;</b><span class=font44>If your NetFlow table has too many entries, you can try to reduce the MLS aging time.</span></span></div>
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">For PFC2, set the aging time high enough to keep the number of entries within the 32,000 flow range of the PFC2. For PFC3, set the aging time high enough to keep the number of entries within the 64,000 flow range of the PFC3.</span></div>
<div class=paragraph style=" padding:2.88pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Make sure you set the aging time to 1 second when using bridged-flow statistics with a Supervisor Engine 2 (SUP2). If some protocols have fewer packets per flow running, reduce the MLS fast aging time.</span></div>
<div class=paragraph style=" padding:3.12pt 39.12pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The following site includes detailed configuration and design information for NetFlow on Catalyst 6500 switches:</span></div>
<div class=paragraph style=" padding:3.12pt 130.80pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;"><a href="http://www.cisco.com/en/US/partner/products/hw/switches/ps708/products_configuration_guide_chapter09186a0080207758.html">http://www.cisco.com/en/US/partner/products/hw/switches/ps708/ products_configuration_guide_chapter09186a0080207758.html</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:86.64pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><b>SYSLOG</b></span></div>
<div class=paragraph style=" padding:3.12pt 40.56pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">System logs or SYSLOG provide you with information for monitoring and troubleshooting devices within your infrastructure. In addition, they give you excellent visibility into what is happening within your network. You can enable SYSLOG on network devices such as routers, switches, firewalls, VPN devices, and others. This section covers how to enable SYSLOG on routers, switches, the Cisco ASA, and Cisco PIX security appliances.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:25.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:101.04pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font6>Enabling Logging (SYSLOG) on Cisco IOS Routers and Switches</span></div>
<div class=paragraph style=" padding:3.84pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">The logging facility on Cisco IOS routers and switches allows you to save SYSLOG messages locally or to a remote host. By default, routers send logging messages to a logging process. The logging process controls the delivery of logging messages to various destinations, such as the logging buffer, terminal lines, a SYSLOG server, or a monitoring event correlation system such as CS-MARS. You can set the severity level of the messages to control the type of messages displayed, in addition to a time stamp to successfully track the reported information.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:90.00pt;">
<div class=block style=" width:90.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 40.80pt 0.00pt 36.00pt; text-align:justify;"><span class=font4><b>TIP</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:396.00pt;">
<div class=block style=" width:396.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 0.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">It is extremely important that your SYSLOG and other messages are time-stamped with the correct date and time. This is why the use of NTP is strongly recommended <i>(see the NTP example in Chapter 2, &quot;Preparation Phase&quot;).</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:117.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:90.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>116    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:210.00pt;">
<div class=paragraph style=" padding:0.00pt 44.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The following example shows the commands necessary to configure SYSLOG on Cisco IOS devices:</span></div>
<div class=paragraph style=" padding:6.48pt 205.20pt 0.00pt 97.44pt; text-align:justify;"><span class=font23 style=" line-height:8.16pt;">myrouter#configure terminal myrouter(config)#logging on myrouter(config)#logging host 172.18.85.190</span></div>
<div class=paragraph style=" padding:4.56pt 41.28pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In this example, the router is configured to send the SYSLOG messages to a host with IP address 172.18.85.190. (This is the CS-MARS used in the examples of the previous sections.)</span></div>
<div class=paragraph style=" padding:6.00pt 43.44pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">On Cisco IOS routers, the log messages are not time-stamped by default. To enable time stamping of log messages, use the <b>service timestamps log datetime </b>command. The following example shows the different options of this command:</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myrouter(config)#service timestamps log datetime ?</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.32pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">localtime&nbsp;Use local time zone for timestamps</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.08pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">msec&nbsp;Include milliseconds in timestamp</span></div>
<div class=paragraph style=" padding:0.00pt 153.60pt 0.00pt 106.08pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">show-timezone   Add time zone information to timestamp year&nbsp;Include year in timestamp</span></div>
<div class=paragraph style=" padding:4.56pt 37.92pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">You can specify the severity level of the SYSLOG messages. The following are the different levels you can configure:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:108.00pt; height:124.08pt; padding:0.00pt 282.00pt 0.00pt 96.00pt;">
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:108.00pt; height:124.08pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.32pt;">
<div class=block style=" width:10.32pt; height:13.92pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:13.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font44><b>Level</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:10.08pt;">
<div class=block style=" width:10.08pt; height:13.92pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font44><b>0:</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.08pt;">
<div class=block style=" width:58.08pt; height:13.92pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font44>Emergencies</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.32pt;">
<div class=block style=" width:10.32pt; height:15.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:15.60pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font44><b>Level</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:10.08pt;">
<div class=block style=" width:10.08pt; height:15.60pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font44><b>1:</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.08pt;">
<div class=block style=" width:58.08pt; height:15.60pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font44>Alerts</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.32pt;">
<div class=block style=" width:10.32pt; height:16.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:16.08pt;">
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font44><b>Level</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:10.08pt;">
<div class=block style=" width:10.08pt; height:16.08pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font44><b>2:</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.08pt;">
<div class=block style=" width:58.08pt; height:16.08pt;">
<div class=paragraph style=" padding:2.88pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font44>Critical</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.32pt;">
<div class=block style=" width:10.32pt; height:16.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:16.08pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font44><b>Level</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:10.08pt;">
<div class=block style=" width:10.08pt; height:16.08pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font44><b>3:</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.08pt;">
<div class=block style=" width:58.08pt; height:16.08pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font44>Errors</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.32pt;">
<div class=block style=" width:10.32pt; height:16.56pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:16.56pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font44><b>Level</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:10.08pt;">
<div class=block style=" width:10.08pt; height:16.56pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font44><b>4:</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.08pt;">
<div class=block style=" width:58.08pt; height:16.56pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 1.68pt; text-align:left;"><span class=font44>Warnings</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.32pt;">
<div class=block style=" width:10.32pt; height:15.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:15.60pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font44><b>Level</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:10.08pt;">
<div class=block style=" width:10.08pt; height:15.60pt;">
<div class=paragraph style=" padding:2.16pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font44><b>5:</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.08pt;">
<div class=block style=" width:58.08pt; height:15.60pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font44>Notifications</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.32pt;">
<div class=block style=" width:10.32pt; height:15.84pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:15.84pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font44><b>Level</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:10.08pt;">
<div class=block style=" width:10.08pt; height:15.84pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font44><b>6:</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.08pt;">
<div class=block style=" width:58.08pt; height:15.84pt;">
<div class=paragraph style=" padding:2.40pt 0.00pt 0.00pt 2.16pt; text-align:left;"><span class=font44>Informational</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.32pt;">
<div class=block style=" width:10.32pt; height:14.40pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:29.52pt;">
<div class=block style=" width:29.52pt; height:14.40pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 5.04pt; text-align:left;"><span class=font44><b>Level</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:10.08pt;">
<div class=block style=" width:10.08pt; height:14.40pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 1.44pt; text-align:left;"><span class=font44><b>7:</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:58.08pt;">
<div class=block style=" width:58.08pt; height:14.40pt;">
<div class=paragraph style=" padding:2.64pt 0.00pt 0.00pt 1.92pt; text-align:left;"><span class=font44>Debugging</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.32pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:29.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:10.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:58.08pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:5.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:137.28pt;">
<div class=paragraph style=" padding:0.00pt 45.12pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">To set the severity level of log messages sent to a SYSLOG server, use the <b>logging trap </b>command. The following example shows the options of this command:</span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">myrouter(config)#logging trap ?</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">&lt;0-7&gt;&nbsp;Logging severity level</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.08pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">alerts&nbsp;Immediate action needed&nbsp;(severity=1)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.08pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">critical&nbsp;Critical conditions&nbsp;(severity=2)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.08pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">debugging&nbsp;Debugging messages&nbsp;(severity=7)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.08pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">emergencies&nbsp;System is unusable&nbsp;(severity=0)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.08pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">errors&nbsp;Error conditions&nbsp;(severity=3)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.32pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">informational&nbsp;Informational messages&nbsp;(severity=6)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.32pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">notifications&nbsp;Normal but significant conditions (severity=5)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.60pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">warnings&nbsp;Warning conditions&nbsp;(severity=4)</span></div>
<div class=paragraph style=" padding:4.56pt 38.88pt 0.00pt 89.04pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">It is recommended that you send SYSLOG messages over a separate management segment, just as you learned to do earlier in this chapter in the &quot;NetFlow&quot; section.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:92.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>117</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:144.48pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 35.76pt; text-align:left;"><span class=font6>Enabling Logging Cisco Catalyst Switches Running CATOS</span></div>
<div class=paragraph style=" padding:4.08pt 38.64pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">To enable the logging of system messages to a SYSLOG server on Cisco Catalyst switches running Catalyst Operating System (CATOS), use the following commands:</span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">set&nbsp;logging&nbsp;server enable</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">set&nbsp;logging&nbsp;server syslog server 172.18.85.190</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">set&nbsp;logging&nbsp;timestamp enable</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">set&nbsp;logging&nbsp;server severity 4</span></div>
<div class=paragraph style=" padding:4.56pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In this example, the switch is configured to send the SYSLOG messages to the host with IP address 172.18.85.190. Time stamp is enabled, and the severity level of the messages sent to the external server is set to 4 or warnings. Setting logging to the debugging level can cause performance problems. A good rule of thumb is to set the logging severity to 4 or warnings.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>A good whitepaper describing best practices when managing Cisco Catalyst switches</span></span></div>
<div class=paragraph style=" padding:0.00pt 43.92pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">running CATOS is located at <a href="http://www.cisco.com/en/US/products/hw/switches/ps663/products_tech_note09186a0080094713.shtml">http://www.cisco.com/en/US/products/hw/switches/ps663/ products_tech_note09186a0080094713.shtml.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:230.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font6>Enabling Logging on Cisco ASA and Cisco PIX Security Appliances</span></div>
<div class=paragraph style=" padding:3.84pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The commands used to enable logging and to send SYSLOG messages to a SYSLOG server are the same on the Cisco ASA and the Cisco PIX security appliances. To enable logging, use the <b>logging on </b>command. To configure the ASA or PIX to send logs to a SYSLOG server, use the <b>logging host </b>command, and to change the log severity level, use the <b>logging trap </b>command. The following example demonstrates the use of these commands.</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">ciscoasa(config)# logging on</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">ciscoasa(config)# logging host inside 172.18.85.190</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">ciscoasa(config)# logging trap informational</span></div>
<div class=paragraph style=" padding:4.56pt 45.84pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In this example, the Cisco ASA is configured to send its logs to the host with IP address 172.18.85.190, and the severity level is set to informational.</span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">On the Cisco ASA and Cisco PIX security appliances, all SYSLOG messages begin with a percent sign (%) and are designed as follows:</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 97.20pt; text-align:left;"><span class=font23>%PIX|ASA   Level Message_number: Message_text</span></div>
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The following is an example of a SYSLOG message.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23>Apr 09 2007 07:35:56: %ASA-6-302021: Teardown ICMP connection for faddr</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.68pt; text-align:left;"><span class=font23>192.168.202.22/0 gaddr 192.168.202.40/0 laddr 192.168.202.40/0</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:104.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>118    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:259.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;<b>PIX|ASA: </b>A static value indicating that the log message is generated by a Cisco ASA</span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 111.60pt; text-align:left;"><span class=font44>or Cisco PIX.</span></div>
<div class=paragraph style=" padding:5.28pt 40.08pt 0.00pt 111.60pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;<b>Level: </b>The severity level (1-7). For most environments, it is recommended that you set the severity level to 4 to avoid performance issues. You may want to temporally increase it to a higher value when troubleshooting a specific problem.</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;<b>Message number: </b>A unique 6-digit number that identifies the SYSLOG message.</span></div>
<div class=paragraph style=" padding:4.80pt 70.80pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;<b>Message text: </b>The description of the log message. It sometimes includes IP addresses, port numbers, or usernames.</span></div>
<div class=paragraph style=" padding:4.32pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">You can filter SYSLOG messages on the Cisco ASA, Cisco PIX, and Cisco FWSM to send only specific events to a particular output destination. In other words, you can configure the device to send all SYSLOG messages to one output destination and also to send a subset of those SYSLOG messages to a different output destination. You can also configure the Cisco ASA, Cisco PIX, and Cisco FWSM to send SYSLOG messages based on specific criteria, such as the following:</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Message ID number (range of 104024 to 105999)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Severity level</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Message class</span></div>
<div class=paragraph style=" padding:1.92pt 51.12pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.24pt;">For example, you can use the <b>logging class &lt;message_class&gt; </b>command to specify the specific class.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.32pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>TIP&nbsp;</b><span class=font44>All Cisco ASA and Cisco PIX messages are defined in detail at <a href="http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/syslog/logmsgs.htm">http://www.cisco.com/</a></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;"><a href="http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/syslog/logmsgs.htm">univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/syslog/logmsgs.htm.</a></span></div>
<div class=paragraph style=" padding:3.36pt 39.12pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">This site also includes the different SYSLOG message classes and associated message ID numbers.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:130.80pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><b>SNMP</b></span></div>
<div class=paragraph style=" padding:3.60pt 42.48pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">SNMP is one of the most basic forms of getting information from your network. It is a Layer 7 protocol designed to obtain information from network devices. This information includes but is not limited to the following:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Device health statistics (CPU, memory, and so on)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Device errors</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Network traffic statistics</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Packet rates</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Packet errors</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:74.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>119</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:171.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The SNMP solution has three components:</span></div>
<div class=paragraph style=" padding:6.72pt 61.68pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;An SNMP manager: </b>The system used to control and monitor the activities of network hosts using SNMP.</span></div>
<div class=paragraph style=" padding:4.32pt 38.64pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;An SNMP agent: </b>The software component within the managed device that maintains the data for the device and reports this data, as needed, to managing systems.</span></div>
<div class=paragraph style=" padding:3.60pt 39.12pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;A Management Information Base (MIB): </b>An information storage medium that contains a collection of managed objects (MIB modules) within each device. MIB modules are written in the SNMP MIB module language, as defined in STD 58, RFC</span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 111.60pt; text-align:left;"><span class=font44>2578, RFC 2579, and RFC 2580.</span></div>
<div class=paragraph style=" padding:5.28pt 39.12pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In Chapter 2, you learned about the three versions of SNMP and the security implications of each version. That chapter also showed you how to protect SNMP environments. This section covers the basic commands on how to enable SNMP on Cisco IOS and the Cisco ASA and Cisco PIX security appliances.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:281.52pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font6>Enabling SNMP on Cisco IOS Devices</span></div>
<div class=paragraph style=" padding:3.84pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">As a best practice, you should set the system contact, location, and serial number of the SNMP agent so that your management servers can obtain these descriptions. This information is useful when responding to incidents. The following example shows how to enter the contact information on the Cisco IOS device:</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myrouter#configure terminal</span></div>
<div class=paragraph style=" padding:0.00pt 145.20pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myrouter(config)#snmp-server contact John Route myrouter(config)#snmp-server location 1st Floor NY Office myrouter(config)#snmp-server chassis-id ABC12345</span></div>
<div class=paragraph style=" padding:4.56pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">In the previous example, the name of the administrator is John Route, the device is located on the 1<sup>st</sup> floor of an office in New York, and the chassis identification number is</span></div>
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>ABC12345.</span></div>
<div class=paragraph style=" padding:7.20pt 50.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The following example shows how you can configure SNMP Version 3 on a Cisco IOS device:</span></div>
<div class=paragraph style=" padding:6.72pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23>myrouter(config)#snmp-server group mygroup v3 auth</span></div>
<div class=paragraph style=" padding:4.80pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">SNMP Version 3 supports authentication. In the previous example, an SNMP group named mygroup is configured for SNMP Version 3. Authentication is also enabled with the <b>auth </b>keyword. When you configure the <b>snmp-server group </b>command, there are no default values for authentication. To specify authentication user parameters, use the <b>snmp-server user </b>command, as shown in the following example:</span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">myrouter(config)#snmp-server user admin1 mygroup v3 auth md5 zxasqw12</span></div>
<div class=paragraph style=" padding:0.00pt 54.72pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">*Feb   8 15:45:04.902: Configuring snmpv3 USM user, persisting snmpEngineBoots. Please Wait...</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:95.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>120    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:170.16pt;">
<div class=paragraph style=" padding:0.00pt 41.28pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In the previous example, a user <i>(adminl) </i>is configured and mapped to the SNMP group <i>mygroup. </i>Authentication is done with MD5, and the password is <i>zxasqw12. </i>After you invoke this command, the preceding warning message is displayed. You should match all this information in your SNMP management server.</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>To verify the configuration, you can invoke the <b>show snmp user </b>command as follows:</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">myrouter#show snmp user</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">User name: admin1</span></div>
<div class=paragraph style=" padding:0.00pt 222.24pt 0.00pt 96.96pt; text-align:left;"><span class=font23 style=" line-height:7.92pt;">Engine ID: 8000000903000013C4EC5528 storage-type: nonvolatile active Authentication Protocol: MD5 Privacy Protocol: DES Group-name: mygroup</span></div>
<div class=paragraph style=" padding:4.32pt 41.28pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">To view SNMP group information, invoke the <b>show snmp group </b>command, as shown in Example 3-4.</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font3><b>Example 3-4 </b><span class=font43><i>Output of the </i><b>show snmp group </b><i>Command</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:361.20pt; height:127.44pt; padding:0.00pt 35.28pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:361.20pt; height:127.44pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:59.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:180.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:10.08pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>myrouter#show snmp group</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:10.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:10.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>groupname: ILMI</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:9.60pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:9.60pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font23>security model:v1</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font23>readview : *ilmi</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:9.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.12pt; text-align:left;"><span class=font23>writeview: *ilmi</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:10.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23>notifyview: &lt;no notifyview</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:10.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>specified&gt;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:10.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font23>row status: active</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:9.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:9.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:10.08pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>groupname: ILMI</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:10.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:10.08pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font23>security model:v2c</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font23>readview : *ilmi</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:9.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.12pt; text-align:left;"><span class=font23>writeview: *ilmi</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:10.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23>notifyview: &lt;no notifyview</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:10.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>specified&gt;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:10.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font23>row status: active</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:9.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:9.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:10.08pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 7.44pt; text-align:left;"><span class=font23>groupname: mygroup</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:10.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:10.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.84pt; text-align:left;"><span class=font23>security model:v3 auth</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:9.36pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font23>readview : v1default</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:9.36pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:9.36pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 15.12pt; text-align:left;"><span class=font23>writeview: &lt;no writeview specified&gt;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:10.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 7.68pt; text-align:left;"><span class=font23>notifyview: &lt;no notifyview</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:10.08pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 2.64pt; text-align:left;"><span class=font23>specified&gt;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:10.08pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt;">
<div class=block style=" width:120.72pt; height:10.56pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 7.92pt; text-align:left;"><span class=font23>row status: active</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:59.52pt;">
<div class=block style=" width:59.52pt; height:10.56pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:180.96pt;">
<div class=block style=" width:180.96pt; height:10.56pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:120.72pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:59.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:180.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:19.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 134.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44>The configured group (mygroup) is shown in the highlighted line.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:150.24pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>NOTE        </b><span class=font44>The following site includes detailed information on how to configure SNMP Version 1</span></span></div>
<div class=paragraph style=" padding:1.68pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>and 2:</span></div>
<div class=paragraph style=" padding:3.84pt 47.04pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.24pt;"><a href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124tcg/tnm_c/snmp/confsnmp.htm%23wp1032846">http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124tcg/tnm_c/snmp/ confsnmp.htm#wp1032846</a></span></div>
<div class=paragraph style=" padding:3.36pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>This document also includes the following information:</span></div>
<div class=paragraph style=" padding:0.72pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>•&nbsp;</b><span class=font44>Configuring the router as an SNMP manager</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>•&nbsp;</b><span class=font44>Enabling the SNMP Agent Shutdown mechanism</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>•&nbsp;</b><span class=font44>Defining the maximum SNMP Agent packet size</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>•&nbsp;</b><span class=font44>Disabling the SNMP Agent</span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font4 style=" line-height:18.00pt;"><b>•&nbsp;</b><span class=font44>Limiting the number of Trivial File Transfer Protocol (TFTP) servers used via SNMP</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:63.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>121</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:75.12pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font44>•&nbsp;Configuring SNMP notifications</span></div>
<div class=paragraph style=" padding:6.96pt 38.40pt 0.00pt 115.20pt; text-align:left; text-indent:-10.80pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Configuring interface index display and interface indexes and configuring long name support</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font44>•&nbsp;Configuring SNMP support for VPNs</span></div>
<div class=paragraph style=" padding:7.68pt 0.00pt 0.00pt 104.40pt; text-align:left;"><span class=font44>•&nbsp;Configuring MIB persistence</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:35.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:210.48pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.96pt; text-align:left;"><span class=font6>Enabling SNMP on Cisco ASA and Cisco PIX Security Appliances</span></div>
<div class=paragraph style=" padding:3.84pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco ASA and the Cisco PIX security appliances support only SNMP Versions 1 and 2c. They both support traps and SNMP read access; however, SNMP write access is not supported. The following example shows how to configure an ASA to receive SNMP Version 2c requests from host 172.18.85.190 on the inside interface:</span></div>
<div class=paragraph style=" padding:6.24pt 107.28pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">ciscoasa(config)# snmp-server host inside 172.18.85.190 Version 2c ciscoasa(config)# snmp-server location Raleigh NC Branch ciscoasa(config)# snmp-server contact Jeff Firewall ciscoasa(config)# snmp-server community th1s1sacommstrng</span></div>
<div class=paragraph style=" padding:4.56pt 38.16pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">The ASA in this example is located in a branch office in Raleigh, North Carolina. The point of contact is Jeff Firewall, and the community string is &lt;th1s1sacommstrng&gt;. You can use the <b>snmp deny version </b>command to deny SNMP packets from other SNMP versions. The following example shows the available options:</span></div>
<div class=paragraph style=" padding:6.48pt 230.64pt 0.00pt 97.44pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">ciscoasa(config)# snmp deny version ? configure mode commands/options:</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 106.32pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">1&nbsp;SNMP version 1</span></div>
<div class=paragraph style=" padding:0.00pt 223.20pt 0.00pt 106.08pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">2&nbsp;SNMP version 2 (party based) 2c   SNMP version 2c (community based)</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 105.84pt; text-align:left;"><span class=font23 style=" line-height:8.16pt;">3&nbsp;SNMP version 3</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:29.04pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 39.36pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>You can obtain the MIBs for any Cisco device at <a href="http://www.cisco.com/public/sw-center/netmgmt/cmtk/mibs.shtml">http://www.cisco.com/public/sw-center/ netmgmt/cmtk/mibs.shtml.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:101.76pt;">
<div class=paragraph style=" padding:0.00pt 87.36pt 0.00pt 36.24pt; text-align:left;"><span class=font8 style=" line-height:15.12pt;"><b>Cisco Security Monitoring, Analysis and Response System (CS-MARS)</b></span></div>
<div class=paragraph style=" padding:2.64pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">CS-MARS enables you to identify, classify, validate, and mitigate security threats. In the previous sections in this chapter, you learned different mechanisms that give you visibility of the network and its devices, such as NetFlow, SYSLOGs, and SNMP. The analysis and manipulation of the data provided by these features can be a time-consuming process and, in some environments, may even be impossible because of the staff requirements.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:70.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>122    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:215.04pt;">
<div class=paragraph style=" padding:0.00pt 50.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">CS-MARS supports the correlation of events from numerous networking devices from different vendors. The supported devices include:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco IOS routers and switches</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco ASA</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco PIX</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;NetFlow</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Security Agent</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco Secure ACS</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Cisco IDS/IPS</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Third-party firewalls such as Checkpoint and Netscreen</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Third-party antivirus software</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Third-party IDS/IPS systems such as snort</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Operating system (Windows and UNIX/Linux) events</span></div>
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Application-specific events</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph style=" padding:0.00pt 54.72pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>A complete of list of supported devices can be found at <a href="http://www.cisco.com/en/US/products/ps6241/products_device_support_tables_list.html">http://www.cisco.com/en/US/ products/ps6241/products_device_support_tables_list.html.</a></span></span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 89.76pt; text-align:left;"><span class=font44>For a complete list of available CS-MARS models, go to <a href="http://www.cisco.com/go/mars">http://www.cisco.com/go/mars.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:177.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">CS-MARS provides a powerful and interactive dashboard with several key items. It includes a topology map that comprises real-time hotspots, incidents, attack paths, and detailed investigation with full incident disclosure, allowing immediate verification of valid threats. Figure 3-7 shows the CS-MARS main dashboard.</span></div>
<div class=paragraph style=" padding:6.24pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Note that the system has processed more than 22,000,000 NetFlow events (or flows) over a period of 24 hours, and more than 44,000,000 security and network events. This automated process is accomplished by analyzing device logs such as firewalls and by using intrusion prevention applications, third-party vulnerability assessment data, and Cisco Security MARS endpoint scans to eliminate false positives. Users can quickly fine-tune the system to further reduce false positives. This will be impossible to successfully analyze without the use of a system such as CS-MARS.</span></div>
<div class=paragraph style=" padding:6.24pt 41.28pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Figure 3-8 shows the bottom part of the CS-MARS main dashboard. There you can see a topology map of devices within the network, an attack diagram, and event statistics and graphs.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>123</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 295.92pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-7    </b><span class=font43><i>CS-MARS Main Dashboard</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:320.16pt; height:240.00pt; padding:0.00pt 82.80pt 0.00pt 83.04pt;">
<img src="ciscoasa_org_ua-33.jpg" alt="" style=" width:320.16pt; height:240.00pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 168.96pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-8    </b><span class=font43><i>CS-MARS Topology Map, Attack Diagram, and Event Statistics</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:320.16pt; height:240.00pt; padding:0.00pt 82.80pt 0.00pt 83.04pt;">
<img src="ciscoasa_org_ua-34.jpg" alt="" style=" width:320.16pt; height:240.00pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:49.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>124   </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:65.28pt;">
<div class=paragraph style=" padding:0.00pt 44.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can view the topology map and attack diagram in full view, as shown in Figure 3-9. Obtaining information about the security incident is simple. If you click on any of the arrows representing the traffic flow, a new window displays with information about the specific incident or session.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 3-9    </b><span class=font43><i>CS-MARS Attack Diagram Full View</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.72pt; height:252.48pt; padding:0.00pt 74.88pt 0.00pt 74.40pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:336.72pt; height:252.48pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:316.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:19.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:336.72pt;">
<div class=block style=" width:336.72pt; height:64.80pt;">
<div class=paragraph style=" padding:3.12pt 0.00pt 0.00pt 4.08pt; text-align:left;"><span class=font39>Cisco <span class=font41 style=" font-variant: small-caps;">S</span><span class=font53 style=" font-variant: small-caps;"><b>ystems</b></span></span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 3.60pt; text-align:left;"><span class=font6 style=" letter-spacing:-1.00pt;">■HI<span style=" letter-spacing:0.00pt;">                                                                                                           </span><span class=font0 style=" letter-spacing:0.00pt;"><b>|<sub>S</sub>UMM«V|| INCIDENTS </b>|| QUERY , REPORTS || RULES || WAN AG EWENI | ADMIN || <b>HELP |</b></span></span></div>
<div class=paragraph style=" padding:9.84pt 0.00pt 0.00pt 4.80pt; text-align:left;"><span class=font43><b>^3</b><span class=font0><b>^SUMA*ARY   |  CSMAH5 Standalone: pnmarsv4.2                                                           </b>Login: <b>sales, usa (usasales) :: | </b></span><span class=font38 style=" font-variant: small-caps;">l^cuc </span><span class=font0><b>| :; | </b>Activate |</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:316.80pt;">
<div class=block style=" width:316.80pt; height:6.48pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 4.32pt; text-align:left;"><span class=font0><b>Attack Diagram</b></span></div>
</div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:19.92pt;">
<div class=block style=" width:19.92pt; height:180.48pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:316.80pt;">
<div class=block style=" width:316.80pt; height:174.00pt;">
<div class=paragraph style=" padding:0.24pt 0.00pt 0.00pt 277.20pt; text-align:left;"><span class=font0>1   Aboard   || Help |</span></div>
<div class=paragraph style=" padding:51.12pt 0.00pt 0.00pt 106.56pt; text-align:left;"><span class=font43><b>Д __——&quot;------</b><i>~Z^~^^^^^<sup>m</sup> </i><b>т<sup>36</sup>^&quot;^~~~-&quot;~-—</b></span></div>
<div class=paragraph style=" padding:36.48pt 0.00pt 0.00pt 69.12pt; text-align:left;"><span class=font0><b>^^^^^^^^^^^^ 17</b><span class=font43><b>_3Jra</b></span>_.21</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:336.72pt;">
<div class=block style=" width:336.72pt; height:7.20pt;">
<div class=paragraph style=" padding:1.44pt 0.00pt 0.00pt 254.88pt; text-align:left;"><span class=font0>@ Internet                         *„ 100% '</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:316.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:19.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:110.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44>The hosts are color-coded:</span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Brown means that the host is the attacker.</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Red means that the host is being attacked.</span></div>
<div class=paragraph style=" padding:4.80pt 63.12pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;">•&nbsp;Purple means that the host is being attacked and is attacking other hosts in the network.</span></div>
<div class=paragraph style=" padding:4.32pt 38.64pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">CS-MARS can do a reverse DNS lookup to give you exact information on the specific hosts and devices. You can run numerous reports in CS-MARS. Figure 3-10 shows an example of reports and graphics you can obtain in CS-MARS.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:125.28pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>125</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 245.28pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-10 </b><span class=font43><i>CS-MARS Detailed Graphics and Reports</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:252.96pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="ciscoasa_org_ua-35.jpg" alt="" style=" width:336.96pt; height:252.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:69.12pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Figure 3-10, you can see a summary of the most used ports and protocols within a given period. These graphics are based on NetFlow information. The graphic on the right shows the traffic trend. Notice that the traffic starts increasing during normal business hours of 8:00 a.m. to around 5:00 p.m. (0800 to 1700). These types of graphics can help you to create a baseline of what is normal within your network. Then you can identify anomalies and possible security incidents.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>Chapter 12, &quot;Case Studies,&quot; includes a case study in which CS-MARS is used to</span></span></div>
<div class=paragraph style=" padding:0.00pt 40.32pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">successfully identify, classify, and mitigate an attack. It also includes examples of how to add monitored devices into CS-MARS.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:75.84pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font8><b>Cisco Network Analysis Module (NAM)</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Cisco Network Analysis Module (NAM) is designed to analyze and monitor traffic in the Catalyst 6500 series switches and Cisco 7600 series Internet routers. It uses remote monitoring (RMON), RMON extensions for switched networks (SMON), and SNMP MIBs to obtain information from the device. The NAM can also collect and analyze NetFlow information on remote devices.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:55.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>126    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:55.20pt;">
<div class=paragraph style=" padding:0.00pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">To use the NAM to collect NetFlow data from a remote device, you must configure the remote device to export NDE packets to UDP port 3000 on the NAM. By default, the local supervisor engine of the switch is always available as an NDE device. Optionally, SNMP community strings are used to upload convenient textual strings for interfaces on the remote devices that are monitored in NetFlow records.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:31.20pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>A complete NAM installation and configuration guide is located at <a href="http://www.cisco.com/en/US/products/sw/cscowork/ps5401/products_installation_and_configuration_guides_list.html">http://www.cisco.com/ en/US/products/sw/cscowork/ps5401/products_installation_and_configuration_guides_ list.html.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:86.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.24pt; text-align:left;"><span class=font8><b>Open Source Monitoring Tools</b></span></div>
<div class=paragraph style=" padding:3.12pt 42.24pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can use several open source monitoring tools in conjunction with NetFlow. If your organization is small, or if you do not have the budget for more sophisticated monitoring tools, you can take advantage of any of these open source tools that are freely available. Table 3-1 includes the most commonly used open source monitoring tools.</span></div>
<div class=paragraph style=" padding:11.28pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font4><b>Table 3-1      </b><span class=font43><i>Open Source Monitoring Tools</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.48pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:360.48pt; height:221.04pt; padding:0.00pt 36.00pt 0.00pt 89.52pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:360.48pt; height:221.04pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:200.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font4><b>Tool Name</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:19.44pt;">
<div class=paragraph style=" padding:5.28pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font4><b>Website</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Caida's Cflowd Analysis Software</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43><a href="http://www.caida.org/tools/measurement/cflowd">http://www.caida.org/tools/measurement/cflowd</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:30.00pt;">
<div class=paragraph style=" padding:3.60pt 31.92pt 0.00pt 6.48pt; text-align:left;"><span class=font43 style=" line-height:11.04pt;">My Netflow Reporting System by Dynamic Networks</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:30.00pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43><a href="http://www.dynamicnetworks.us/netflow/index.html">http://www.dynamicnetworks.us/netflow/index.html</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:19.20pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>OSU Flow-tools</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:19.20pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43><a href="http://www.splintered.net/sw/flow-tools">http://www.splintered.net/sw/flow-tools</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:18.96pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Flow Viewer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:18.96pt;">
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43><a href="http://ensight.eos.nasa.gov/FlowViewer">http://ensight.eos.nasa.gov/FlowViewer</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Flowd</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43><a href="http://www.mindrot.org/projects/flowd">http://www.mindrot.org/projects/flowd</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:18.96pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>NetFlow Monitor (NF)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43><a href="http://netflow.cesnet.cz">http://netflow.cesnet.cz</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Ntop</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43><a href="http://ntop.ethereal.com/ntop.html">http://ntop.ethereal.com/ntop.html</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:18.96pt;">
<div class=paragraph style=" padding:3.84pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43>Panoptis</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:18.96pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43><a href="http://panoptis.sourceforge.net">http://panoptis.sourceforge.net</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:19.20pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.48pt; text-align:left;"><span class=font43>Plixer's Scrutinizer</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:19.20pt;">
<div class=paragraph style=" padding:4.80pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43><a href="http://www.plixer.com/products/free-netflow.php">http://www.plixer.com/products/free-netflow.php</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt;">
<div class=block style=" width:159.84pt; height:19.44pt;">
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 6.72pt; text-align:left;"><span class=font43>Stager</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:200.64pt;">
<div class=block style=" width:200.64pt; height:19.44pt;">
<div class=paragraph style=" padding:4.56pt 0.00pt 0.00pt 6.24pt; text-align:left;"><span class=font43><a href="http://software.uninett.no/stager">http://software.uninett.no/stager</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:159.84pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:200.64pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:13.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:21.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Most of these tools are designed to run in common *NIX-type operating systems, including Linux, FreeBSD, Mac OS/X, and Solaris. Some of these tools support the storage of data</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:76.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>127</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:69.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">in databases such as MySQL and Oracle. Despite the fact that these open source tools are free, they are extremely useful for collecting NetFlow from routers and storing the raw flows for auditing and forensic purposes. The most commonly used tool is the OSU flow-tool, which is typically used in conjunction with other packages that provide detailed graphs, charts, and on-demand queries. Visit each of the websites listed in Table 3-1 to learn more about which tool is most suitable for your environment.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:377.76pt;">
<div class=paragraph style=" padding:0.00pt 41.76pt 0.00pt 36.00pt; text-align:justify;"><span class=font8 style=" line-height:14.88pt;"><b>Cisco Traffic Anomaly Detectors and Cisco Guard DDoS Mitigation Appliances</b></span></div>
<div class=paragraph style=" padding:2.88pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">The Cisco traffic anomaly detectors and DDoS mitigation appliances provide a new approach that not only detects increasingly complex and unrepresentative denial of service attacks but also mitigates their effect to ensure business continuity and resource availability. The Cisco DDos solution has two distinct appliances:</span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Cisco Traffic Anomaly Detector (TAD) XT</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Cisco Guard XT</span></div>
<div class=paragraph style=" padding:5.04pt 38.88pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">This solution is also available in the form of two individual modules for the Catalyst 6500 series switches and the Cisco 7600 Internet routers:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Catalyst 6500/Cisco 7600 Router Anomaly Guard Module</span></div>
<div class=paragraph style=" padding:5.76pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Catalyst 6500/Cisco 7600 Router Traffic Anomaly Detector Module</span></div>
<div class=paragraph style=" padding:4.80pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The detectors (whether the appliances or the modules) are designed to promiscuously monitor network traffic while looking for any variation from what is &quot;normal,&quot; which may indicate a DDoS attack or a worm outbreak. The Cisco TAD XT alerts the Cisco Guard XT when it detects an anomaly by providing detailed reports and specific alerts.</span></div>
<div class=paragraph style=" padding:6.00pt 51.36pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This solution uses a Multiverification Process (MVP) architecture integrating different verification, analysis, and enforcement techniques. The MVP has five components:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Static and dynamic DDoS filters</span></div>
<div class=paragraph style=" padding:4.56pt 40.32pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.24pt;">•&nbsp;Active verification (anti-spoofing) implementing source-authentication mechanisms that help ensure proper identification of legitimate traffic</span></div>
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Anomaly recognition</span></div>
<div class=paragraph style=" padding:6.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44>•&nbsp;Protocol analysis designed to identify Layer 7 attacks, such as HTTP error attacks</span></div>
<div class=paragraph style=" padding:5.04pt 41.28pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;">•&nbsp;Rate limiting that prevents flows from overwhelming the target while more detailed monitoring is taking place</span></div>
<div class=paragraph style=" padding:5.04pt 0.00pt 0.00pt 4.08pt; text-align:center;"><span class=font44>Figure 3-11 illustrates how the Cisco TAD XT and the Cisco Guard XT work.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:103.44pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:95.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:390.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>128    </b>Chapter <span class=font24 style=" letter-spacing:-1.00pt;">3: </span>Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 169.68pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-11  </b><span class=font43><i>Cisco TAD XT Detects an Anomaly and Updates the Guard XT</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:59.76pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style="position:relative; z-index:2; width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 352.80pt 0.00pt 89.52pt; text-align:justify;"><span class=font3>Cisco Guard</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:3.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:95.04pt;">
<div class=block style=" width:16.80pt; height:34.08pt; padding:0.00pt 5.28pt 0.00pt 72.96pt;">
<img src="ciscoasa_org_ua-36.jpg" alt="" style=" width:16.80pt; height:34.08pt;"></div>
</td>
<td class=cell valign="top" style=" width:390.96pt;">
<div class=block style="position:relative; z-index:1; width:390.96pt; height:34.08pt;">
<div class=block style="float:right; width:273.84pt; height:4.80pt; clear:right;"><span style="line-height:0pt;"></span></div>
<div class=block style="float:right; width:251.76pt; height:0.48pt; clear:right;"><span style="line-height:0pt;"></span></div>
<div class=paragraph style=" padding:0.48pt 227.28pt 0.00pt 41.04pt; text-align:justify;"><span class=font43><i>m        </i><span class=font1>3. Route Update   ^       ■ ■</span></span></div>
<div class=paragraph style=" padding:0.00pt 225.36pt 0.00pt 40.80pt; text-align:justify;"><span class=font16 style=" line-height:24.00pt;"><b>и</b><span class=font0><b>—</b></span><b>нт</b></span></div>
<div class=block style=" width:112.80pt; height:66.24pt; position:absolute; left:117.12pt; top:-60.96pt; z-index:-1;">
<img src="ciscoasa_org_ua-37.jpg" alt="" style=" width:112.80pt; height:66.24pt;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.08pt;">
<div class=paragraph style=" padding:0.00pt 359.76pt 0.00pt 95.04pt; text-align:justify;"><span class=font1>2. Detected!</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:4.08pt;">
<div class=paragraph style=" padding:0.00pt 300.00pt 0.00pt 155.04pt; text-align:justify;"><span class=font1>1. Detected!</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.00pt;">
<div class=paragraph style=" padding:0.00pt 372.96pt 0.00pt 69.60pt; text-align:justify;"><span class=font3>Cisco Traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:343.68pt; height:95.76pt; padding:0.00pt 67.68pt 0.00pt 74.64pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:343.68pt; height:95.76pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:90.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.80pt;">
<div class=block style=" width:124.80pt; height:43.92pt;">
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 2.40pt; text-align:left;"><span class=font3>Detector</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:89.52pt;">
<div class=block style=" width:89.52pt; height:43.92pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 31.92pt; text-align:left;"><span class=font54 style=" letter-spacing:1.50pt;"><b>Y Y YY</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:39.36pt;">
<div class=block style=" width:39.36pt; height:43.92pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:90.00pt;">
<div class=block style=" width:90.00pt; height:43.92pt;">
<div class=paragraph style=" padding:4.32pt 0.00pt 0.00pt 0.24pt; text-align:center;"><span class=font52 style=" line-height:39.36pt;"><b><i>&amp;</i></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.80pt;">
<div class=block style=" width:124.80pt; height:40.56pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:89.52pt;">
<div class=block style=" width:89.52pt; height:40.56pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 26.16pt; text-align:left;"><span class=font16 style=" line-height:24.72pt; letter-spacing:-2.50pt;"><b><i>w</i></b></span></div>
<div class=paragraph style=" padding:11.76pt 0.00pt 0.00pt 13.68pt; text-align:left;"><span class=font3>Protected Zone 1:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:39.36pt;">
<div class=block style=" width:39.36pt; height:40.56pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:90.00pt;">
<div class=block style=" width:90.00pt; height:40.56pt;">
<div class=paragraph style=" padding:0.00pt 0.72pt 0.00pt 0.00pt; text-align:center;"><span class=font16 style=" line-height:32.16pt; letter-spacing:-2.50pt;"><b><i>W</i></b></span></div>
<div class=paragraph style=" padding:8.16pt 0.72pt 0.00pt 0.00pt; text-align:center;"><span class=font3>Protected Zone 2:</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.80pt;">
<div class=block style=" width:124.80pt; height:11.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:89.52pt;">
<div class=block style=" width:89.52pt; height:11.28pt;">
<div class=paragraph style=" padding:0.96pt 0.00pt 0.00pt 22.08pt; text-align:left;"><span class=font3>Web Servers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:39.36pt;">
<div class=block style=" width:39.36pt; height:11.28pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:90.00pt;">
<div class=block style=" width:90.00pt; height:11.28pt;">
<div class=paragraph style=" padding:0.96pt 0.24pt 0.00pt 0.00pt; text-align:center;"><span class=font3>Email Servers</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:124.80pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:39.36pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:90.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:171.12pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Figure 3-11, two zones are protected by the Cisco TAD XT: a web server farm and an e­mail server farm. The Cisco Guard is placed at the Internet edge, and the Cisco TAD XT resides a couple of hops in the inside of the corporate network. The following are the steps illustrated in Figure 3-11.</span></div>
<div class=paragraph style=" padding:6.24pt 88.80pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 1   </b><span class=font44>An attacker starts a DDoS from the Internet, and the Cisco TAD XT detects the anomaly (spike of traffic).</span></span></div>
<div class=paragraph style=" padding:6.00pt 77.28pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 2  </b><span class=font44>The Cisco TAD XT updates the Cisco Guard XT. The Cisco Guard XT can be triggered in several ways:</span></span></div>
<div class=paragraph style=" padding:7.20pt 0.00pt 0.00pt 133.20pt; text-align:left;"><span class=font44>—&nbsp;Through direct use of the web-based device manager</span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 132.96pt; text-align:left;"><span class=font44>—&nbsp;Via the CLI</span></div>
<div class=paragraph style=" padding:6.96pt 110.16pt 0.00pt 148.56pt; text-align:left; text-indent:-15.36pt;"><span class=font44 style=" line-height:12.00pt;">—&nbsp;Through automatic use of the &quot;protect by packet&quot; feature (illustrated in this example)</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:76.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:95.04pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:390.96pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:199.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:85.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:158.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 288.24pt; text-align:justify;"><span class=font4>Telemetry and Anomaly Detection <b>129</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:161.28pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 3  </b><span class=font44>After the Cisco Guard XT is activated, the Cisco Guard XT performs</span></span></div>
<div class=paragraph style=" padding:0.96pt 74.16pt 0.00pt 126.00pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">additional screening, and then the traffic destined to the zone under attack is diverted to the Cisco Guard XT in any of the following ways:</span></div>
<div class=paragraph style=" padding:6.00pt 91.20pt 0.00pt 148.08pt; text-align:left; text-indent:-14.88pt;"><span class=font44 style=" line-height:12.00pt;">—&nbsp;The Cisco Guard XT can issue a BGP route update telling the router to divert the traffic to the Cisco Guard TX.</span></div>
<div class=paragraph style=" padding:6.00pt 74.64pt 0.00pt 148.08pt; text-align:left; text-indent:-14.88pt;"><span class=font44 style=" line-height:11.76pt;">—&nbsp;If you are using the Catalyst 6500/7600 modules, the Route Health Injection (RHI) feature can trigger the packet diversion.</span></div>
<div class=paragraph style=" padding:6.24pt 0.00pt 0.00pt 133.20pt; text-align:left;"><span class=font44>—&nbsp;A route is injected externally into the network.</span></div>
<div class=paragraph style=" padding:6.96pt 86.16pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 4 </b><span class=font44>The attack traffic is redirected to the Cisco Guard XT, and legitimate traffic is allowed to the protected zone, as illustrated in Figure 3-12.</span></span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 3-12 </b><span class=font43><i>Attack Traffic Redirected</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:258.24pt; height:94.80pt; padding:0.00pt 161.04pt 0.00pt 66.72pt;">
<img src="ciscoasa_org_ua-38.jpg" alt="" style=" width:258.24pt; height:94.80pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:2.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.68pt;">
<div class=paragraph style=" padding:0.00pt 391.68pt 0.00pt 88.32pt; text-align:justify;"><span class=font44>A</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.36pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph style=" padding:0.00pt 253.68pt 0.00pt 204.96pt; text-align:center;"><span class=font1 style=" line-height:7.20pt;">Legitimate Traffic</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:20.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:199.20pt;">
<div class=block style="position:relative;  width:49.44pt; height:30.24pt; padding:0.00pt 83.04pt 0.00pt 66.72pt;">
<img src="ciscoasa_org_ua-39.jpg" alt="" style=" width:49.44pt; height:30.24pt;">
<div class=block style=" width:18.24pt; height:11.76pt; position:absolute; left:79.92pt; top:12.72pt;">
<div class=paragraph style=" text-align:justify;"><span class=font9><b><i>Ж</i></b></span></div>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:43.20pt;">
<div class=block style=" width:43.20pt; height:30.24pt;">
<div class=paragraph style=" padding:12.72pt 16.80pt 0.00pt 22.32pt; text-align:justify;"><span class=font10>-</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:243.60pt;">
<div class=block style=" width:243.60pt; height:30.24pt;">
<div class=paragraph style=" padding:4.32pt 225.36pt 0.00pt 0.00pt; text-align:justify;"><span class=font16 style=" line-height:22.56pt; letter-spacing:-2.50pt;"><b><i><sup>r</sup>9</i></b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:2.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:199.20pt;">
<div class=block style=" width:199.20pt; height:110.16pt;">
<div class=paragraph style=" padding:0.00pt 86.16pt 0.00pt 76.08pt; text-align:left; text-indent:-6.48pt;"><span class=font3 style=" line-height:9.60pt;">Cisco Traffic Anomaly Detector</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:128.64pt;">
<div class=block style=" width:90.24pt; height:95.52pt; padding:14.64pt 38.40pt 0.00pt 0.00pt;">
<img src="ciscoasa_org_ua-40.jpg" alt="" style=" width:90.24pt; height:95.52pt;"></div>
</td>
<td class=cell valign="top" style=" width:158.16pt;">
<div class=block style=" width:90.72pt; height:95.52pt; padding:14.64pt 67.44pt 0.00pt 0.00pt;">
<img src="ciscoasa_org_ua-41.jpg" alt="" style=" width:90.72pt; height:95.52pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:111.12pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:199.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:43.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:85.44pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:158.16pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:181.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:153.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:101.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>130    </b>Chapter <span class=font24 style=" letter-spacing:-1.00pt;">3: </span>Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:93.12pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco Guard can also be deployed with other anomaly detection systems. Examples of this include Arbor's Peakflow SP and Peakflow X. Arbor's Peakflow SP is designed for service providers, and Peakflow X is designed for enterprises. Typically, enterprises deploy the Cisco Guard XT at their Internet edge, or they co-locate it at their Internet service provider network to avoid the unnecessary traffic consuming their bandwidth. Because of this, numerous service providers offer managed network DDoS protection, hosting DDoS protection, peering point DDoS protection, and infrastructure protection services. This is based on a solution that Cisco makes available to service providers called &quot;clean pipes.&quot;</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:9.12pt;">
<div class=paragraph style=" padding:0.00pt 62.88pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE        </b><span class=font44>For more information about clean pipes, go to <a href="http://www.cisco.com/go/cleanpipes">http://www.cisco.com/go/cleanpipes.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:57.36pt;">
<div class=paragraph style=" padding:0.00pt 48.48pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">Figure 3-13 illustrates the protection cycle that the Cisco Guard XT follows to analyze, filter, and rate-limit the traffic.</span></div>
<div class=paragraph style=" padding:10.08pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 3-13 </b><span class=font43><i>Cisco Guard XT Protection Cycle</i></span></span></div>
<div class=paragraph style=" padding:8.64pt 0.24pt 0.00pt 0.00pt; text-align:center;"><span class=font4>Control Feedback</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.92pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="3" valign="top" style=" width:181.92pt;">
<div class=block style=" width:116.64pt; height:147.36pt; padding:0.00pt 2.40pt 15.60pt 62.88pt;">
<img src="ciscoasa_org_ua-42.jpg" alt="" style=" width:116.64pt; height:147.36pt;"></div>
</td>
<td class=cell colspan="2" valign="top" style=" width:202.80pt;">
<div class=block style=" width:83.04pt; height:58.56pt; padding:3.84pt 119.76pt 2.16pt 0.00pt;">
<img src="ciscoasa_org_ua-43.jpg" alt="" style=" width:83.04pt; height:58.56pt;"></div>
</td>
<td class=cell rowspan="2" valign="top" style=" width:101.28pt;">
<div class=block style=" width:101.28pt; height:120.72pt;">
<div class=paragraph style=" padding:59.76pt 76.56pt 0.00pt 0.00pt; text-align:center;"><span class=font1 style=" line-height:7.20pt;">Traffic to Protected Zone</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="2" valign="top" style=" width:153.60pt;">
<div class=block style=" width:120.48pt; height:98.40pt; padding:0.00pt 32.64pt 0.00pt 0.48pt;">
<table class=main frame="box" rules="all" border="1" cellspacing="0" cellpadding="0" style=" width:120.48pt; height:98.40pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:23.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:7.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:41.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.48pt;">
<div class=block style=" width:48.48pt; height:37.20pt;">
<div class=paragraph style=" padding:4.32pt 6.96pt 0.00pt 6.96pt; text-align:center;"><span class=font3 style=" line-height:9.60pt;">Basic Protection Level</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:23.52pt;">
<div class=block style=" width:23.52pt; height:37.20pt;">
<div class=paragraph style=" padding:12.96pt 0.00pt 0.00pt 0.24pt; text-align:left;"><span class=font38 style=" font-variant: small-caps;">—<span class=font35 style=" font-variant: normal;"><b><i>&gt;</i></b></span></span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:48.48pt;">
<div class=block style=" width:48.48pt; height:37.20pt;">
<div class=paragraph style=" padding:9.12pt 7.68pt 0.00pt 7.44pt; text-align:left;"><span class=font3 style=" line-height:9.60pt;">Statistical Analysis</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.48pt;">
<div class=block style=" width:48.48pt; height:24.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:30.72pt;">
<div class=block style=" width:30.72pt; height:24.24pt;">
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 27.60pt; text-align:left;"><span class=font43><i>i</i></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:41.28pt;">
<div class=block style=" width:41.28pt; height:24.24pt;">
<div class=paragraph style=" padding:1.20pt 0.00pt 0.00pt 1.20pt; text-align:left;"><span class=font3>к</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell rowspan="2" valign="top" style=" width:48.48pt;">
<div class=block style=" width:48.48pt; height:36.96pt;">
<div class=paragraph style=" padding:3.84pt 6.96pt 0.00pt 6.96pt; text-align:center;"><span class=font3 style=" line-height:9.60pt;">Strong Protection Level</span></div>
</div>
</td>
<td class=cell colspan="2" valign="top" style=" width:30.72pt;">
<div class=block style=" width:30.72pt; height:18.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:41.28pt;">
<div class=block style=" width:41.28pt; height:18.24pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:30.72pt;">
<div class=block style=" width:30.72pt; height:18.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:41.28pt;">
<div class=block style=" width:41.28pt; height:18.72pt;">
<div class=paragraph style=" text-align:left;"></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:48.48pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:23.52pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:7.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:41.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
</div>
</td>
<td class=cell valign="top" style=" width:49.20pt;">
<div class=block style=" width:49.20pt; height:56.16pt;">
<div class=paragraph style=" padding:9.12pt 20.16pt 0.00pt 2.40pt; text-align:left; text-indent:5.52pt;"><span class=font3 style=" line-height:9.60pt;">Rate Limiting</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:150.48pt;">
<div class=block style=" width:150.48pt; height:42.24pt;">
<div class=paragraph style=" padding:0.00pt 138.24pt 0.00pt 0.00pt; text-align:justify;"><span class=font1>Drop</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:81.12pt;">
<div class=paragraph style=" padding:0.00pt 38.88pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">When the traffic is redirected to the Cisco Guard XT, it first filters the traffic using several filtering techniques. If the Cisco Guard XT determines that the packets are malicious, it drops them at this stage. If the packets are not malicious, the packets are sent to different protection levels using several types of authentication methods. Subsequently, the Cisco Guard XT analyzes the traffic flow, drops the traffic that exceeds the defined rate that the zone can handle, and then injects the legitimate traffic back to the zone. A closed-loop feedback cycle dynamically adjusts its protection policies.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="4" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:85.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:181.92pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:153.60pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:49.20pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:101.28pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 37.92pt 0.00pt 171.36pt; text-align:justify;"><span class=font4>Intrusion Detection and Intrusion Prevention Systems (IDS/IPS) <b>131</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left; text-indent:-53.28pt;"><span class=font4 style=" line-height:11.76pt;"><a name="bookmark31"><b>N</b></a><b>OTE        </b><span class=font44>For more detailed information on how to configure the Cisco Guard XT and the Cisco TAD XT, go to <a href="http://www.cisco.com/en/US/products/ps5888/products_installation_and_configuration_guides_list.html">http://www.cisco.com/en/US/products/ps5888/ products_installation_and_configuration_guides_list.html.</a></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.88pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:180.00pt;">
<div class=paragraph style=" padding:0.00pt 42.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font11 style=" line-height:18.24pt;"><a href="#bookmark30"><b>Intrusion Detection and Intrusion Prevention Systems </b></a><b>(IDS/IPS)</b></span></div>
<div class=paragraph style=" padding:3.12pt 38.40pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">In Chapter 1, &quot;Overview of Network Security Technologies,&quot; you learned the basics about IDS and IPS systems. IDSs are devices that in promiscuous mode detect malicious activity within the network. IPS devices are capable of detecting all these security threats; however, they are also able to drop noncompliant packets inline. Traditionally, IDS systems have provided excellent application layer attack-detection capabilities; however, they were not able to protect against day-zero attacks using valid packets. The problem is that most attacks today use valid packets. On the other hand, now IPS systems such as the Cisco IPS software Version 6.x and later offer anomaly-based capabilities that help you detect such attacks. This is a big advantage, since it makes the IPS devices less dependent on signature updates for protection against DDoS, worms, and any day-zero threats. Just like any other anomaly detection systems, the sensors need to learn what is &quot;normal.&quot; In other words, they need to create a baseline of legitimate behavior.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:26.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:110.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 39.60pt; text-align:left;"><span class=font8><b>The Importance of Signatures Updates</b></span></div>
<div class=paragraph style=" padding:3.12pt 39.36pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Traditionally, IPS and IDS systems depend on signatures to operate. Because of this, it is extremely important to tune the IPS/IDS device accordingly and to develop policies and procedures to continuously update the signatures. The Cisco IPS software allows you to automatically download signatures from a management station. Signature updates are posted to <a href="http://Cisco.com">Cisco.com</a> almost on a weekly basis. In Chapter 2, you learned about the Cisco Security Center (historically named mySDN or my Self Defending Network). This is an excellent resource to obtain information about the latest IPS signatures and other security intelligence information.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:85.20pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>NOTE        </b><span class=font44>The Cisco Security Center site is <a href="http://www.cisco.com/security">http://www.cisco.com/security.</a></span></span></div>
<div class=paragraph style=" padding:3.60pt 49.44pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco Security Center provides up-to-date security intelligence data, in addition to detailed IDS/IPS signature information.</span></div>
<div class=paragraph style=" padding:3.12pt 41.04pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">Although the IPS sensors can work without a license key, you must have a license key to obtain signature updates from Cisco.com. To obtain a license key, you must have a Cisco Service for IPS service contract. For more information, go to <a href="http://www.cisco.com/go/license">http://www.cisco.com/go/ license.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:67.68pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>132    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The Cisco IPS Device Manager (IDM) is a web-based configuration utility used to manage individual IPS sensors, Catalyst 6500 IPS modules, and the Advanced Inspection and Prevention Security Services Module (AIP-SSM) for the Cisco ASA. You can configure the IPS device via IDM to automatically obtain and install signatures from an FTP or SCP server.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:27.60pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:81.12pt;">
<div class=paragraph style=" padding:0.00pt 42.24pt 0.00pt 36.48pt; text-align:justify;"><span class=font4 style=" line-height:12.00pt;"><b>NOTE        </b><span class=font44>You cannot automatically download service pack and signature updates from <a href="http://Cisco.com">Cisco.com</a>.</span></span></div>
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You need to download service packs and signatures updates from Cisco.com to an FTP or SCP server. Then you can configure your IPS device to access the files on your server. You can also use the Cisco Security Manager IPS Manager Console (IPSMC) to manage your IPS devices. You can configure IPSMC to automatically download the signature updates and service packs from <a href="http://Cisco.com">Cisco.com</a> and then install them in your IPS devices. For more information about IPSMC, go to <a href="http://www.cisco.com/go/security">http://www.cisco.com/go/security.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:30.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:339.12pt;">
<div class=paragraph style=" padding:0.00pt 38.40pt 0.00pt 90.00pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Complete the following steps to configure IDM to automatically download signatures from your FTP or SCP server.</span></div>
<div class=paragraph style=" padding:6.00pt 117.12pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 1   </b><span class=font44>Log in to IDM with an administrator account and navigate to <b>Configuration &gt; Auto Update.</b></span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 2  </b><span class=font44>Select the <b>Enable Auto Update </b>check box.</span></span></div>
<div class=paragraph style=" padding:6.72pt 76.56pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 3 </b><span class=font44>Enter the IP address of the remote server where the signature update or service packs are saved.</span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 4  </b><span class=font44>Select either <b>FTP </b>or <b>SCP </b>for your transport mechanism/server type.</span></span></div>
<div class=paragraph style=" padding:6.96pt 74.40pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 5 </b><span class=font44>Enter the path to the directory on the remote server where the updates are located in the <b>Directory Path.</b></span></span></div>
<div class=paragraph style=" padding:6.24pt 84.96pt 0.00pt 126.24pt; text-align:left; text-indent:-36.00pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 6 </b><span class=font44>Enter the username and password of the account in your FTP or SCP server.</span></span></div>
<div class=paragraph style=" padding:6.24pt 74.16pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 7 </b><span class=font44>You can configure the IPS device to check for updates hourly or on a weekly basis. If you want your IPS device to check for updates hourly, check the <b>Hourly </b>check box. Then enter the time you want the updates to start and the hour interval at which you want the IPS device to contact your remote server for updates. The IPS sensor checks the directory you specified for new files in your server. Only one update is installed per cycle even if there are multiple available files.</span></span></div>
<div class=paragraph style=" padding:6.00pt 74.40pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:11.76pt;"><b>Step 8  </b><span class=font44>Check the <b>Daily </b>check box if you want the IPS device to automatically check for updates on a daily basis. Then enter the time you want the updates to start and check the days you want the IPS device to check for updates in your SCP or FTP server.</span></span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 9  </b><span class=font44>To save and apply your configuration, click <b>Apply.</b></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:53.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 171.36pt; text-align:justify;"><span class=font4>Intrusion Detection and Intrusion Prevention Systems (IDS/IPS) <b>133</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:254.88pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font8><b>The Importance of Tuning</b></span></div>
<div class=paragraph style=" padding:3.36pt 38.40pt 0.00pt 89.76pt; text-align:justify;"><span class=font44 style=" line-height:11.76pt;">Chapter 1 showed you the important factors to consider when tuning your IPS/IDS devices. Each IPS/IDS device comes with a preset number of signatures enabled. These signatures are suitable in most cases; however, it is important that you tune your IPS/IDS devices when you first deploy them and then tune them again periodically. You could receive numerous false positive events (false alarms), which could cause you to overlook real security incidents. The initial tuning will probably take more time than any subsequent tuning. The initial tuning process is hard to perform manually, especially in large environments where several IPS/IDS devices are deployed and hundreds of events are generated in short periods. This is why it is important to use event correlation systems to alleviate this process and save numerous hours. CS-MARS is used in the following example to perform initial tuning and event analysis.</span></div>
<div class=paragraph style=" padding:6.00pt 72.00pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">In this example, several IPS devices are sending their events to a CS-MARS. The administrator completes the following steps to perform initial tuning:</span></div>
<div class=paragraph style=" padding:6.96pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 1  </b><span class=font44>Log in to the CS-MARS via the web interface.</span></span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 2 </b><span class=font44>Click <b>Query/Reports </b>tab.</span></span></div>
<div class=paragraph style=" padding:6.72pt 74.64pt 0.00pt 126.24pt; text-align:justify; text-indent:-36.00pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 3 </b><span class=font44>Select the <b>Activity: All-Top Event Types (Peak View) </b>option from the second pull-down menu under the <b>Load Report as On-Demand Query with Filter </b>section, as shown in Figure 3-14.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 304.80pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-14 </b><span class=font43><i>CS-MARS Query/Reports</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.48pt; height:214.56pt; padding:0.00pt 74.64pt 0.00pt 74.88pt;">
<img src="ciscoasa_org_ua-44.jpg" alt="" style=" width:336.48pt; height:214.56pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:80.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>134   </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:53.28pt;">
<div class=paragraph style=" padding:0.00pt 74.64pt 0.00pt 126.00pt; text-align:justify; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 4 </b><span class=font44>Click the <b>Edit </b>button to select the time interval for the query and enter <b>1 </b>day under the <b>Filter by time </b>section to trigger the CS-MARS to display the top event types in the past 24 hours, as shown in Figure 3-15.</span></span></div>
<div class=paragraph style=" padding:10.32pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font4><b>Figure 3-15 </b><span class=font43><i>Selecting the Query Time Interval</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:214.56pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="ciscoasa_org_ua-45.jpg" alt="" style=" width:336.96pt; height:214.56pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:14.16pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:141.12pt;">
<div class=paragraph style=" padding:0.00pt 79.44pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 5  </b><span class=font44>Click <b>Apply </b>and <b>Submit Inline </b>in the next screen to obtain the report. The report in Figure 3-16 is shown. In this report, the administrator notices that there have been more than 480 ARP Reply-to-Broadcast events detected in the past 24 hours.</span></span></div>
<div class=paragraph style=" padding:6.00pt 74.16pt 0.00pt 125.76pt; text-align:left; text-indent:-35.52pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 6  </b><span class=font44>Click the event to obtain more information and read the following from the CS-MARS details screen: &quot;This signature detects an ARP Reply packet where the destination MAC address in the ARP payload is a layer 2 broadcast address. This is not normal traffic and can indicate an ARP poisoning attack.&quot;</span></span></div>
<div class=paragraph style=" padding:5.76pt 72.96pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.24pt;"><b>Step 7  </b><span class=font44>Click <b>q </b>by the event and select <b>Source IP Address Ranking </b>under the <b>Result format </b>section to investigate the source, as shown in Figure 3-17.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:146.40pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 171.36pt; text-align:justify;"><span class=font4>Intrusion Detection and Intrusion Prevention Systems (IDS/IPS) <b>135</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.24pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 338.16pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-16 </b><span class=font43><i>Top Event Types</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:320.16pt; height:240.48pt; padding:0.00pt 82.80pt 0.00pt 83.04pt;">
<img src="ciscoasa_org_ua-46.jpg" alt="" style=" width:320.16pt; height:240.48pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:15.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 333.60pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-17 </b><span class=font43><i>Verifying Sources</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:7.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:320.16pt; height:240.00pt; padding:0.00pt 82.80pt 0.00pt 83.04pt;">
<img src="ciscoasa_org_ua-47.jpg" alt="" style=" width:320.16pt; height:240.00pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:49.20pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.24pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>136    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.12pt;">
<div class=paragraph style=" padding:0.00pt 76.32pt 0.00pt 90.24pt; text-align:justify;"><span class=font4 style=" line-height:12.00pt;"><b>Step 8  </b><span class=font44>Click <b>Apply </b>and <b>Submit Inline </b>in the following screen to obtain the</span></span></div>
<div class=paragraph style=" padding:0.00pt 79.92pt 0.00pt 125.76pt; text-align:justify;"><span class=font44 style=" line-height:12.00pt;">new report, including the source IP addresses for the <i>ARP Reply-to-Broadcast </i>events. The report is shown as illustrated in Figure 3-18.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:11.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 330.72pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>Figure 3-18 </b><span class=font43><i>IP Sources Report</i></span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:6.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:336.96pt; height:252.96pt; padding:0.00pt 74.64pt 0.00pt 74.40pt;">
<img src="ciscoasa_org_ua-48.jpg" alt="" style=" width:336.96pt; height:252.96pt;"></div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:16.32pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:171.12pt;">
<div class=paragraph style=" padding:0.00pt 82.08pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The administrator notices that only one device (10.10.1.254) is triggering these events. After further investigation, he discovers that this is the normal behavior of an application that is running on that machine and marks this incident as a <b>False Positive </b>in CS-MARS.</span></div>
<div class=paragraph style=" padding:6.00pt 72.00pt 0.00pt 125.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">The administrator notices that these events are not shown anymore in CS-MARS; however, they are still shown using the <b>show events </b>command in the CLI of the IPS sensors. This is because when you mark an incident/ event/session in CS-MARS as a <b>False Positive, </b>it does not disable or tune this signature in the actual IPS device. The events are still sent to the CS-MARS from the IPS devices; however, CS-MARS does not process these events. If you do not want the IPS sensor to send or process the events, you must tune or disable the signature on the IPS device. You can tune signatures based on source and destination. For example, in this case, you can tune the IPS signature not to alert you if the host with the</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:75.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.48pt 0.00pt 171.36pt; text-align:justify;"><span class=font4>Intrusion Detection and Intrusion Prevention Systems (IDS/IPS) <b>137</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.72pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:212.16pt;">
<div class=paragraph style=" padding:0.00pt 74.64pt 0.00pt 126.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">IP address 10.10.1.254 sends this type of packet. However, you can configure the IPS signature to alert you if any other device generates this type of traffic.</span></div>
<div class=paragraph style=" padding:24.00pt 0.00pt 0.00pt 36.00pt; text-align:left;"><span class=font8><b>Anomaly Detection Within Cisco IPS Devices</b></span></div>
<div class=paragraph style=" padding:3.60pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">When you configure a Cisco IPS device running Versions 6.x and later with anomaly detection services, the IPS device initially goes through a learning process. This is done to configure a set of policy thresholds based on the normal behavior of your network. Three different modes of operation take place when an IPS device is configured with anomaly detection:</span></div>
<div class=paragraph style=" padding:4.08pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Learning mode</span></div>
<div class=paragraph style=" padding:0.48pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Detect mode</span></div>
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 97.44pt; text-align:left;"><span class=font44 style=" line-height:15.84pt;">•&nbsp;Inactive mode</span></div>
<div class=paragraph style=" padding:1.92pt 47.28pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.24pt;">The initial learning mode is performed over a period of 24 hours, by default. The initial baseline is referred to as the knowledge base (KB) of your traffic.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:28.80pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:83.04pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 36.00pt; text-align:justify;"><span class=font4 style=" line-height:12.00pt;"><b>TIP&nbsp;</b><span class=font44>The IPS sensor does not detect attacks during the initial learning phase. If you experience</span></span></div>
<div class=paragraph style=" padding:0.24pt 38.16pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">an attack during this period, your results will not reflect a baseline of normal network behavior. This is an important point to take into consideration. Depending on your environment, you may want to have the IPS device in learning mode longer than the default 24 hours because this is a configurable value. Do not initially enable your IPS device with anomaly detection over a weekend if your organization operates mostly during normal business hours and days. This is a huge mistake that many people make.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:153.12pt;">
<div class=paragraph style=" padding:0.00pt 39.36pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">To configure the IPS sensor using IDM to start the learning mode, go to <b>Configuration &gt; Policies &gt; Anomaly Detections &gt; ad0 &gt; Learning Accept Mode </b>and select the <b>Automatically accept learning knowledge base </b>check box. In that section, you can also specify the learning period length.</span></div>
<div class=paragraph style=" padding:6.00pt 38.40pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">After the learning process, a KB is created that replaces the initial KB. The IPS device then automatically goes into detect mode. Any traffic flows that violate thresholds in the KB trigger the IPS device to generate alerts. The IPS device also keeps track of gradual changes to the KB that do not violate the thresholds and adjusts its configuration.</span></div>
<div class=paragraph style=" padding:5.76pt 40.08pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">You can turn off the anomaly detection functionality on your IPS device. This is called being in <i>inactive mode. </i>In certain circumstances, this is needed. An example is when you have an asymmetric environment and the IPS device gets traffic from different directions, causing it to operate incorrectly.</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:65.52pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 204.48pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>138    </b>Chapter 3: Identifying and Classifying Security Threats</span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:46.56pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:45.12pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 90.00pt; text-align:left; text-indent:-53.52pt;"><span class=font4 style=" line-height:11.76pt;"><b>NOTE        </b><span class=font44>The traffic anomaly engine in Cisco IPS devices uses nine anomaly detection signatures covering TCP, UDP, and other protocols. Each signature has two subsignatures: one for the scanner and the other for the worm-infected host. All of these signatures are enabled by default, and they are in the 13000 range.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:33.84pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:253.20pt;">
<div class=paragraph style=" padding:0.00pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Similarly to the Cisco TAD XT, the anomaly detection feature in Cisco IPS devices uses zones. The purpose of configuring zones is to make sure that you do not have false positives and false negatives. A <i>zone </i>is a set of destination IP addresses. Three different zones exist:</span></div>
<div class=paragraph style=" padding:6.24pt 60.96pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;Internal: </b>You configure this zone with the IP address range of your internal network.</span></div>
<div class=paragraph style=" padding:4.08pt 40.08pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:12.00pt;"><b>•&nbsp;Illegal: </b>You configure this zone with IP address ranges that should never be seen in normal traffic. Here you should use unallocated IP addresses or bogon IP addresses.</span></div>
<div class=paragraph style=" padding:4.08pt 48.96pt 0.00pt 111.36pt; text-align:left; text-indent:-13.92pt;"><span class=font44 style=" line-height:11.76pt;"><b>•&nbsp;External: </b>This is the default zone. By default, it has the Internet range of 0.0.0.0­255.255.255.255.</span></div>
<div class=paragraph style=" padding:5.28pt 37.20pt 0.00pt 90.00pt; text-align:justify;"><span class=font44>To configure the Internal zone in your IPS device using IDM, complete the following steps:</span></div>
<div class=paragraph style=" padding:6.48pt 78.96pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.24pt;"><b>Step 1   </b><span class=font44>Navigate to <b>Configuration &gt; Policies &gt; Anomaly Detections &gt; ad0 &gt; Internal Zone. </b>The Internal Zone tab appears.</span></span></div>
<div class=paragraph style=" padding:6.48pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 2  </b><span class=font44>Click the <b>General </b>tab.</span></span></div>
<div class=paragraph style=" padding:7.92pt 0.00pt 0.00pt 90.24pt; text-align:left;"><span class=font4><b>Step 3  </b><span class=font44>Select the <b>Enable the Internal Zone </b>check box.</span></span></div>
<div class=paragraph style=" padding:6.96pt 88.80pt 0.00pt 126.00pt; text-align:left; text-indent:-35.76pt;"><span class=font4 style=" line-height:12.00pt;"><b>Step 4  </b><span class=font44>Enter your internal subnets/IP address range in the <b>Service Subnets </b>field. IDM also allows you to configure protocol and other specific thresholds.</span></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:32.64pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt;">
<div class=block style=" width:89.76pt; height:32.88pt;">
<div class=paragraph style=" padding:0.00pt 29.76pt 0.00pt 36.48pt; text-align:justify;"><span class=font4><b>NOTE</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:396.24pt;">
<div class=block style=" width:396.24pt; height:32.88pt;">
<div class=paragraph style=" padding:0.00pt 36.24pt 0.00pt 0.00pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">For more information on how to configure other thresholds and anomaly detection functionality, refer to the Cisco IPS configuration guides located at <a href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids13/idmguide/index.htm">http://www.cisco.com/ univercd/cc/td/doc/product/iaabu/csids/csids13/idmguide/index.htm.</a></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell colspan="2" valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:168.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:89.76pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:396.24pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
</table>
<table class=main frame="box" rules="all" border="0" cellspacing="0" cellpadding="0" style=" width:486.00pt; height:658.80pt;">
<tr class=row>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt; height:0.00pt;">
</td>
<td class=cell valign="top" style=" width:0.00pt; height:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.96pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:8.64pt;">
<div class=paragraph style=" padding:0.00pt 36.72pt 0.00pt 384.24pt; text-align:justify;"><span class=font4>Summary <b>139</b></span></div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:36.00pt;">
<div class=paragraph>
</div>
</div>
</td>
<td class=cell valign="top" style=" width:0.00pt;">
</td>
</tr>
<tr class=row valign="top">
<td class=cell valign="top" style=" width:0.00pt;">
</td>
<td class=cell valign="top" style=" width:486.00pt;">
<div class=block style=" width:486.00pt; height:155.76pt;">
<div class=paragraph style=" padding:0.00pt 0.00pt 0.00pt 36.48pt; text-align:left;"><span class=font11><a href="#bookmark30"><a name="bookmark32"><b>S</b></a><b>ummary</b></a></span></div>
<div class=paragraph style=" padding:3.60pt 38.64pt 0.00pt 89.76pt; text-align:left;"><span class=font44 style=" line-height:11.76pt;">Identification and classification of security threats mainly concerns visibility. In this chapter, you learned how important it is to have complete network visibility and control to successfully identify and classify security threats in a timely fashion. This chapter also covered different technologies and tools that can be used to obtain information from your network and detect anomalies that can be malicious activity. This chapter provided overviews of Cisco NetFlow, SYSLOG, and SNMP. You also learned about robust event correlation systems, such as CS-MARS and open source monitoring systems that can be used in conjunction with NetFlow to allow you to gain better visibility in your network.</span></div>
<div class=paragraph style=" padding:6.00pt 38.88pt 0.00pt 90.00pt; text-align:left;"><span class=font44 style=" line-height:12.00pt;">This chapter also provided an overview of anomaly detection solutions, in addition to tips on IPS/IDS tuning and the new anomaly detection features that Cisco IPS software supports.</span></div>
]]></content:encoded>
			<wfw:commentRss>http://ciscoasa.org.ua/2010/02/chapter-3-identifying-and-classifying-security-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

