Table Of Contents
Firewall Services User Interface Reference
AAA Rules Page
Add and Edit AAA Rules Dialog Boxes
Edit AAA Option Dialog Box
AuthProxy Dialog Box
Edit AAA Server Group Dialog Box
Access Rules Page
Add and Edit Access Rule Dialog Boxes
Advanced and Edit Options Dialog Boxes
Edit Firewall Rule Expiration Settings Dialog Box
Inspection Rules Page
Add and Edit Inspection Rule Dialog Boxes
Add Inspect/Application FW Rule Wizard Inspected Protocol Page and Edit Inspected Protocol Dialog Boxes
Protocols Supporting Configuration Options
Limit Inspection Between Source and Destination IP Addresses
(ASA, FWSM 3.x) Page
Match Traffic by Custom Destination Ports Page
Match Traffic by Destination Address and Port (IOS) Page
Match Traffic by Source and Destination Address and Port
(ASA, FWSM 3.x) Page
Configure DNS Dialog Box
Configure SMTP Dialog Box
Custom Protocol Dialog Box
Configure ESMTP Dialog Box
Configure Fragments Dialog Box
Configure IMAP Dialog Box
Configure POP3 Dialog Box
Configure RPC Dialog Box
Configuring Protocol Platform Dialog Box
Botnet Traffic Filter Rules Page
Dynamic Blacklist Configuration Tab
Traffic Classification Tab
Traffic Classification Dialog Box
Whitelist/Blacklist Tab
Device Whitelist or Device Blacklist Dialog Box
Transparent Rules Page
Add and Edit Transparent Firewall Rule Dialog Boxes
Edit Transparent EtherType Dialog Box
Edit Transparent Mask Dialog Box
Web Filter Rules Page (PIX/ASA)
Add and Edit PIX/FWSM/ASA Rules Dialog Boxes
Edit Web Filter Type Dialog Box
Edit Web Filter Options Dialog Box
Web Filter Rules Page (IOS)
IOS Web Filter Rule and Applet Scanner Dialog Box
IOS Web Filter Exclusive Domain Name Dialog Box
Zone-based Firewall Rules Page
Adding and Editing Zone-based Firewall Rules
Zone-based Firewall Rule: Advanced Options Dialog Box
Protocol Selector Dialog Box
Configure Protocol Dialog Box
Common Firewall Services Dialog Boxes
Add or Edit Sources or Destinations Dialog Boxes
Add or Edit Services Dialog Boxes
Add or Edit Interfaces or Zones Dialog Boxes
Edit Category Dialog Box
Edit Description Dialog Box
Show Contents Dialog Boxes
Firewall Settings
Access Control Settings Page
Firewall ACL Setting Dialog Box
Inspection Settings Page
AAA Firewall Page, Advanced Setting Tab
Interactive Authentication Configuration Dialog Box
Clear Connection Configuration Dialog Box
AAA Firewall Page, MAC-Exempt List Tab
Firewall AAA MAC Exempt Setting Dialog Box
AuthProxy Page
AuthProxy General Tab (IOS)
AuthProxy Timeout Tab (IOS)
Web Filter Settings Page
Web Filter Server Configuration Dialog Box
Zone Based Firewall Page
Zone Based Firewall Page - Content Filter Tab
Zone Dialog Box
Add and Edit Rule Section Dialog Boxes
Find and Replace Dialog Box
Rule Analysis Results Page
Import Rules Wizard—Enter Parameters Page
Import Rules Wizard—Status Page
Import Rules Wizard—Preview Page
Querying Device or Policy Dialog Box
Policy Query Results Dialog Box
Hit Count Selection Summary Dialog Box
Hit Count Query Results Page
Combine Rules Selection Summary Dialog Box
Rule Combiner Results Dialog Box
Firewall Services User Interface Reference
Firewall services policies are used to define firewall configurations for your devices. These reference topics describe the pages and dialog boxes used to configure firewall services policies.
This chapter contains the following topics:
•
AAA Rules Page
•
Access Rules Page
•
Inspection Rules Page
•
Botnet Traffic Filter Rules Page
•
Transparent Rules Page
•
Web Filter Rules Page (PIX/ASA)
•
Web Filter Rules Page (IOS)
•
Zone-based Firewall Rules Page
•
Common Firewall Services Dialog Boxes
•
Firewall Settings
•
Add and Edit Rule Section Dialog Boxes
•
Find and Replace Dialog Box
•
Rule Analysis Results Page
•
Import Rules Wizard—Enter Parameters Page
•
Querying Device or Policy Dialog Box
•
Hit Count Selection Summary Dialog Box
•
Combine Rules Selection Summary Dialog Box
AAA Rules Page
Use the AAA Rules page to identify AAA rules defined in Security Manager. For more information, see Working with AAA Rules, page 11-40.
From the AAA Rules page, you can add, edit, and delete rules, reorder rules, and enable or disable rules in the table. You perform these tasks using either the shortcut menu, which is accessed by right-clicking a table cell, or by selecting the appropriate buttons located below the table.
From the AAA Rules page, you can also generate reports to discover object groups that are being used and identify policies associated with a particular device.
Navigation Path
To access the AAA Rules page, do one of the following:
•
(Device view) Select a device, then select Firewall >AAA Rules from the Device selector.
•
(Policy view) Select Firewall >AAA Rules from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Policies > AAA Rules.
Related Topics.
•
Working with AAA Rules, page 11-40
•
Filtering Tables, page 2-16
Field Reference
Table I-1 AAA Rules Page
Element
|
Description
|
No.
|
Identifies the ordered rule number in the table.
|
Permit
|
Whether the rule permits or denies traffic based on the conditions set.
• Permit—Shown as a green check mark.
• Deny—Shown as a red circle with slash.
|
Source
|
Identifies the source network object names or addresses of hosts and networks, for example, 10.1.1.1, 10.1.1.1/32, 10.1.1.1/255.255.255.255 and net10. Interface roles can also be used to identify a source. Multiple entries are displayed as separate subfields within the table cell. See:
• Understanding Network/Host Objects, page 8-65.
• Understanding Interface Role Objects, page 8-33.
Note If you manually enter 0.0.0.0/0 for the source, it automatically matches the "any" predefined object.
|
Destination
|
Identifies the destination network object names or addresses of hosts and networks, for example, 10.1.1.1, 10.1.1.1/32, 10.1.1.1/255.255.255.255 and net10. Interface roles can also be used to identify a destination. Multiple entries are displayed as separate subfields within the table cell. See:
• Understanding Network/Host Objects, page 8-65.
• Understanding Interface Role Objects, page 8-33.
Note If you manually enter 0.0.0.0/0 for the destination, it automatically matches the "any" predefined object.
|
Service
|
Identifies service objects that specify protocol and port information. Multiple entries are displayed as separate subfields within the table cell. See Understanding and Specifying Services and Service and Port List Objects, page 8-75.
Note If you manually enter a service, such as TCP / 80, and that data translates directly to a predefined service object, such as HTTP, the rule takes the predefined object as its value.
|
Interface
|
Identifies the logical name of the interface (interface role) or physical interface to which a rule is assigned. Multiple entries are displayed as separate subfields within the table cell. See Understanding Interface Role Objects, page 8-33.
For example:
• All DMZs
• All FastEthernets
• All Interfaces
• FastEthernet0
Note Interface roles are objects that are used to help you configure firewall rules. The objects are replaced with the actual interface names when the configuration is generated for each device.
|
Action
|
Identifies the AAA methods.
• Authentication—indicates that the rule controls traffic based on who the user is.
• Authorization—indicates that the rule controls traffic based on what the user is allowed to do.
• Accounting—indicates that the rule controls traffic based on what the user did.
|
AuthProxy
|
Identifies the authentication proxy method used for IOS devices.
|
Server Group
|
Identifies the AAA server group.
Note The AAA server group must have at least one AAA server defined.
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Description
|
Shows a user-defined description to help you identify a rule when viewing the rules table. A maximum of 1024 characters is allowed.
|
Tools button
|
Click this button to select tools that you can use with this type of policy. You can select from the following tools:
• Combine Rules—To improve performance and memory usage by combining similar rules. This reduces the number of rules in the policy. See Combining Rules, page 11-9.
• Query—To run policy queries, which can help you evaluate your rules and identify ineffective rules that you can delete. See Generating Policy Query Reports, page 11-12
|
Find and Replace button (binoculars icon)
|
Searches for values in rules tables, such as IP addresses and policy object names, to facilitate locating and making changes to rules in tables. See Finding and Replacing Items in Rules Tables, page 11-6.
|
Up Row and Down Row buttons (arrow icons)
|
Click these buttons to move the selected rules up or down within a scope or section. For more information, see Moving Rules and the Importance of Rule Order, page 11-7.
|
Add button
|
Adds a rule to the table.
|
Edit button
|
Edits an existing rule in the table.
|
Delete button
|
Deletes a rule from the table.
|
Add and Edit AAA Rules Dialog Boxes
Use the Add and Edit AAA Rules dialog box to add and edit AAA rules.
Navigation Path
To access the Add and Edit AAA Rules dialog boxes, do one of the following:
•
(Device view) Select a device, then select Firewall > AAA Rules from the Device selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
•
(Policy view) Select Firewall > AAA Rules from the Policy selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
Related Topics
•
Adding AAA Rules, page 11-40
•
Editing Rules, page 11-5
•
Working with AAA Rules, page 11-40
Field Reference
Table I-2 Add and Edit AAA Rules Dialog Boxes
Element
|
Description
|
Enable Rule
|
When selected, indicates that the rule becomes active on a device after the configuration is generated and deployed.
When viewing the main rules tables:
• An enabled rule is shown without hash marks.
• A disabled rule is shown with hash marks.
Note A disabled rule is not generated and deployed to devices; however, it is retained in the rules table for debugging purposes.
|
Authentication Action
|
When selected, indicates that the rule controls traffic based on who the user is.
|
Authorization Action (PIX/ASA/FWSM)
|
When selected, indicates that the rule controls traffic based on what the user is allowed to do.
|
Accounting Action (PIX/ASA/FWSM)
|
When selected, indicates that the rule controls traffic based on what the user did.
|
Action
|
Describes what should occur based on the conditions set.
• Permit—Allows traffic.
• Deny—Denies traffic.
|
Sources
Destinations
|
The source or destination of the traffic. You can enter more than one value by separating the items with commas.
You can enter any combination of the following address types to define the source or destination of the traffic. For more information, see Specifying IP Addresses During Policy Definition, page 8-68.
• Network/host object. Enter the name of the object or click Select to select it from a list. You can also create new network/host objects from the selection list.
• Host IP address, for example, 10.10.10.100.
• Network address, including subnet mask, in either the format 10.10.10.0/24 or 10.10.10.0/255.255.255.0.
• A range of IP addresses, for example, 10.10.10.100-10.10.10.200.
• An IP address pattern in the format 10.10.0.10/255.255.0.255, where the mask is a discontiguous bit mask (see Contiguous and Discontiguous Network Masks, page 8-65).
• Interface role object. Enter the name of the object or click Select to select it from a list (you must select Interface Role as the object type). When you use an interface role, the rule behaves as if you supplied the IP address of the selected interface. This is useful for interfaces that get their address through DHCP, because you do not know what IP address will be assigned to the device. For more information, see Understanding Interface Role Objects, page 8-33.
If you select an interface role as a source, the dialog box displays tabs to differentiate between hosts or networks and interface roles.
|
Services
|
The services that define the type of traffic to act on. You can enter more than one value by separating the items with commas.
You can enter any combination of service objects and service types (which are typically a protocol and port combination). If you type in a service, you are prompted as you type with valid values. You can select a value from the list and press Enter or Tab.
For complete information on how to specify services, see Understanding and Specifying Services and Service and Port List Objects, page 8-75.
Note Due to an issue in PIX 6.3 and FWSM devices, when a source port is specified in an AAA ACL, no traffic is authenticated. Therefore, the source address is ignored when the CLI is generated.
|
AAA Server Group (PIX,ASA,FWSM)
|
Identifies the AAA server group. See Understanding AAA Server and Server Group Objects, page 8-15.
Enter the AAA Server Object in the field provided or click Select, which opens the Object Selector dialog box from which to make your selections. You can also create an object by clicking the Create button in the Object Selector dialog box.
|
Interface
|
Identifies the logical name of the interface (interface role) or physical interface to which a rule is assigned. See Understanding Interface Role Objects, page 8-33.
For example:
• All DMZs
• All FastEthernets
• All Interfaces
• FastEthernet0
Click Edit, which opens the Interface Selector dialog box from which to make your selection. You can also create an interface role by clicking the Create button in the Interface Selector dialog box.
Note Interface roles are objects that are used to help you configure firewall rules. The objects are replaced with the actual interface names when the configuration is generated for each device.
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Description
|
Shows a user-defined description to help you identify a rule when viewing the rules table. A maximum of 1024 characters is allowed.
|
HTTP Traffic Type Applies to Authentication Proxy (IOS)
|
When selected, specifies HTTP to trigger the authentication proxy.
|
FTP Traffic Type Applies to Authentication Proxy (IOS)
|
When selected, specifies FTP to trigger the authentication proxy.
|
Telnet Traffic Type Applies to Authentication Proxy (IOS)
|
When selected, specifies Telnet to trigger the authentication proxy.
|
Edit AAA Option Dialog Box
Use the Edit AAA Option dialog box to edit the method for access entry.
Navigation Path
To access the Edit AAA Option dialog box, do one of the following:
•
(Device view) Select a device, then select Firewall >AAA Rules from the Device selector. Right-click the entry in the Action column of the AAA Rules table, then click Edit AAA.
•
(Policy view) Select Firewall >AAA Rules from the Policy selector. Right-click the entry in the Action column of the AAA Rules table, then click Edit AAA.
Related Topics
•
Adding AAA Rules, page 11-40
•
Editing Rules, page 11-5
•
Working with AAA Rules, page 11-40
Field Reference
Table I-3 Edit AAA Option Dialog Box
Element
|
Description
|
Authentication
|
When selected, indicates that the rule controls traffic based on who the user is. Authentication provides the method of identifying users, including login and password dialog, challenge and response, messaging support, and, depending on the security protocol you select, encryption. Authentication is the way a user is identified prior to being allowed access to the network and network services.
|
Authorization (PIX/ASA)
|
When selected, indicates that the rule controls traffic based on what the user is allowed to do. Authorization provides the method for remote access control, including one-time authorization or authorization for each service, per-user account list and profile, user group support, and support of IP and Telnet. AA authorization works by assembling a set of attributes that describe what the user is authorized to perform.
|
Accounting (PIX/ASA)
|
When selected, indicates that the rule controls traffic based on what the user did. Accounting provides the method for collecting and sending security server information used for billing, auditing, and reporting, such as user identities, start and stop times, executed commands (such as PPP), number of packets, and number of bytes. Accounting enables you to track the services users are accessing as well as the amount of network resources they are consuming.
|
AuthProxy Dialog Box
Use the AuthProxy dialog box to edit an IOS traffic type entry in a table.
Navigation Path
To access the AuthProxy dialog box, right-click the entry in the AuthProxy column of the AAA Rules table, then click Edit AuthProxy.
Related Topics
•
Adding AAA Rules, page 11-40
•
Editing Rules, page 11-5
•
Working with AAA Rules, page 11-40
Field Reference
Table I-4 AuthProxy Dialog Box
Element
|
Description
|
HTTP
|
Specifies HTTP to trigger the authentication proxy.
|
FTP
|
Specifies FTP to trigger the authentication proxy.
|
Telnet
|
Specifies Telnet to trigger the authentication proxy.
|
Edit AAA Server Group Dialog Box
Use the Edit AAA Server Group dialog box to edit a server group entry in a table.
Navigation Path
To access the Edit AAA Server Group dialog box, right-click the entry in the Server Group column of the AAA Rules table, then click Edit Server Group.
Related Topics
•
Adding AAA Rules, page 11-40
•
Editing Rules, page 11-5
•
Working with AAA Rules, page 11-40
•
Understanding AAA Server and Server Group Objects, page 8-15
Field Reference
Table I-5 Edit AAA Server Group Dialog Box
Element
|
Description
|
AAA Server Group
|
Identifies the AAA Server Group.
Enter the AAA Server Object in the field provided or click Select, which opens the Object Selector dialog box from which to make your selections. You can also create an object by clicking the Create button in the Object Selector dialog box.
|
Access Rules Page
Use the Access Rules page to configure access control rules for device interfaces. Access rules policies define the rules that allow or deny traffic to transit an interface. Typically, you create access rules for traffic entering an interface, because if you are going to deny specific types of packets, it is better to do it before the device spends a lot of time processing them. Access rules are processed before other types of firewall rules.
Read the following topics before you configure access rules:
•
Understanding Access Rules, page 11-17
•
Understanding Device Specific Access Rule Behavior, page 11-19
•
Understanding Access Rule Address Requirements and How Rules Are Deployed, page 11-19
•
Configuring Access Rules, page 11-21
Tip
Disabled rules are shown with hash marks covering the table row. If the device supports the configuration of disabled rules, these are included in the configuration as disabled. Otherwise, they are not part of the configuration. For more information, see Enabling and Disabling Rules, page 11-8.
Navigation Path
To open the Access Rules page, do one of the following:
•
(Device view) Select a device, then select Firewall > Access Rules from the Device selector.
•
(Policy view) Select Firewall > Access Rules from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Policies > Access Rules.
Related Topics
•
Configuring Expiration Dates for Access Rules, page 11-22
•
Configuring Settings for Access Control, page 11-23
•
Importing Rules, page 11-28
•
Adding and Removing Rules, page 11-4
•
Editing Rules, page 11-5
•
Enabling and Disabling Rules, page 11-8
•
Moving Rules and the Importance of Rule Order, page 11-7
•
Using Sections to Organize Rules Tables, page 11-8
•
Using Rules Tables, page 11-3
•
Filtering Tables, page 2-16
Field Reference
Table I-6 Access Rules Page
Element
|
Description
|
No.
|
The ordered rule number.
|
Permit
|
Whether a rule permits or denies traffic based on the conditions set:
• Permit—Shown as a green check mark.
• Deny—Shown as a red circle with slash.
|
Source
Destination
|
The source and destination addresses for the rule. The "any" address does not restrict the rule to specific hosts, networks, or interfaces. These addresses are IP addresses for hosts or networks, network/host objects, interfaces, or interface roles. Multiple entries are displayed as separate subfields within the table cell. See:
• Understanding Network/Host Objects, page 8-65
• Understanding Interface Role Objects, page 8-33
|
Service
|
The services or service objects that specify the protocol and port of the traffic to which the rule applies. Multiple entries are displayed as separate subfields within the table cell. See Understanding and Specifying Services and Service and Port List Objects, page 8-75.
|
Interface
|
The interfaces or interface roles to which the rule is assigned. Interface role objects are replaced with the actual interface names when the configuration is generated for each device. Multiple entries are displayed as separate subfields within the table cell. See Understanding Interface Role Objects, page 8-33.
|
Dir.
|
The direction of the traffic to which this rule applies:
• In—Packets entering the interface.
• Out—Packets exiting the interface.
|
Options
|
The additional options configured for the rule. These include logging, time range, and some additional IOS rule options. See Advanced and Edit Options Dialog Boxes.
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Description
|
The description of the rule, if any.
|
Expiration Date
|
The date that the rule expires. Expired rules show Expired in bold text. Expired rules are not automatically deleted.
|
Tools button
|
Click this button to select tools that you can use with this type of policy. You can select from the following tools:
• Analysis—To identify rules that overlap or conflict with other rules. See Generating Analysis Reports, page 11-24.
• Combine Rules—To improve performance and memory usage by combining similar rules. This reduces the number of rules in the policy. See Combining Rules, page 11-9.
• Hit Count—To identify the number of times that traffic for a device is permitted or denied based on an access rule. This information is useful in debugging the deployed policies. See Generating Hit Count Reports, page 11-26.
• Import Rules—To import rules from an ACL defined using device commands. See Importing Rules, page 11-28.
• Query—To run policy queries, which can help you evaluate your rules and identify ineffective rules that you can delete. See Generating Policy Query Reports, page 11-12
|
Find and Replace button (binoculars icon)
|
Click this button to search for various types of items within the table and to optionally replace them. See Finding and Replacing Items in Rules Tables, page 11-6.
|
Up Row and Down Row buttons (arrow icons)
|
Click these buttons to move the selected rules up or down within a scope or section. For more information, see Moving Rules and the Importance of Rule Order, page 11-7.
|
Add Row button
|
Click this button to add a rule to the table after the selected row using the Add and Edit Access Rule Dialog Boxes. If you do not select a row, the rule is added at the end of the local scope. For more information about adding rules, see Adding and Removing Rules, page 11-4.
|
Edit Row button
|
Click this button to edit the selected rule. You can also edit individual cells. For more information, see Editing Rules, page 11-5.
|
Delete Row button
|
Click this button to delete the selected rule.
|
Add and Edit Access Rule Dialog Boxes
Use the Add and Edit Firewall Rule dialog boxes to add and edit firewall access rules. Read the following topics before you configure access rules:
•
Understanding Access Rules, page 11-17
•
Understanding Device Specific Access Rule Behavior, page 11-19
•
Understanding Access Rule Address Requirements and How Rules Are Deployed, page 11-19
•
Configuring Access Rules, page 11-21
Navigation Path
From the Access Rules Page, click the Add Row button or select a row and click the Edit Row button.
Related Topics
•
Configuring Expiration Dates for Access Rules, page 11-22
•
Editing Rules, page 11-5
•
Adding and Removing Rules, page 11-4
•
Importing Rules, page 11-28
•
Understanding Network/Host Objects, page 8-65
•
Understanding and Specifying Services and Service and Port List Objects, page 8-75
Field Reference
Table I-7 Add and Edit Access Rule Dialog Boxes
Element
|
Description
|
Enable Rule
|
Whether to enable the rule, which means the rule becomes active when you deploy the configuration to the device. Disabled rules are shown overlain with hash marks in the rule table. For more information, see Enabling and Disabling Rules, page 11-8.
|
Action
|
Permit or deny traffic based on the conditions defined.
|
Sources
Destinations
|
The source or destination of the traffic. You can enter more than one value by separating the items with commas.
You can enter any combination of the following address types to define the source or destination of the traffic. For more information, see Specifying IP Addresses During Policy Definition, page 8-68.
• Network/host object. Enter the name of the object or click Select to select it from a list. You can also create new network/host objects from the selection list.
• Host IP address, for example, 10.10.10.100.
• Network address, including subnet mask, in either the format 10.10.10.0/24 or 10.10.10.0/255.255.255.0.
• A range of IP addresses, for example, 10.10.10.100-10.10.10.200.
• An IP address pattern in the format 10.10.0.10/255.255.0.255, where the mask is a discontiguous bit mask (see Contiguous and Discontiguous Network Masks, page 8-65).
• Interface role object. Enter the name of the object or click Select to select it from a list (you must select Interface Role as the object type). When you use an interface role, the rule behaves as if you supplied the IP address of the selected interface. This is useful for interfaces that get their address through DHCP, because you do not know what IP address will be assigned to the device. For more information, see Understanding Interface Role Objects, page 8-33.
If you select an interface role as a source, the dialog box displays tabs to differentiate between hosts or networks and interface roles.
|
Service
|
The services that define the type of traffic to act on. You can enter more than one value by separating the items with commas.
You can enter any combination of service objects and service types (which are typically a protocol and port combination). If you type in a service, you are prompted as you type with valid values. You can select a value from the list and press Enter or Tab.
For complete information on how to specify services, see Understanding and Specifying Services and Service and Port List Objects, page 8-75.
|
Interfaces
|
The interfaces or interface roles to which the rule is assigned. Enter the name of the interface or the interface role, or click Select to select the interface or role from a list, or to create a new role. An interface must already be defined to appear on the list.
Interface role objects are replaced with the actual interface names when the configuration is generated for each device. See Understanding Interface Role Objects, page 8-33.
|
Description
|
An optional description of the rule (up to 1024 characters).
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Advanced button
|
Click this button to configure other settings for the rule, including logging configuration, traffic direction, time ranges, and rule expiration dates. For more information, see Advanced and Edit Options Dialog Boxes.
|
Advanced and Edit Options Dialog Boxes
Use the Advanced and Edit Options dialog boxes to configure additional settings for an access rule. When you are in the Advanced dialog box, you have more fields available for configuration than when you edit options, which is a cell-level editing dialog box. The settings in the Advanced dialog box show up in three different cells in an access rule; direction, options, and rule expiration.
Navigation Path
To access the Advanced dialog box, do one of the following:
•
Go to the Add and Edit Access Rule Dialog Boxes and click Advanced Options.
•
Right-click the Options cell in an access rule (on the Access Rules Page) and select Edit Options. If you select multiple rows, your changes replace the options defined for all selected rules.
Related Topics
•
Configuring Access Rules, page 11-21
•
Editing Rules, page 11-5
•
Understanding Access Rules, page 11-17
•
Working with Access Rules, page 11-17
•
Creating Time Range Objects, page 8-92
Field Reference
Table I-8 Advanced Dialog Box
Element
|
Description
|
Enable Logging (PIX, ASA, FWSM)
|
Whether to generate syslog messages for the rule entries, or ACEs, for PIX, ASA, and FWSM devices. You can select these additional options:
• Default Logging—Use the default logging behavior. If a packet is denied, message 106023 is generated. If a packet is permitted, no syslog message is generated. The default logging interval is 300 seconds.
• Per ACE Logging—Configure logging specific to this entry. Select the logging level you want to use to log events for the ACE, and the logging interval, which can be from 1-600 seconds. Syslog message 106100 is generated for the ACE.
Following are the possible logging levels:
– Emergency—(0) System is unstable
– Alert—(1) Immediate action is needed
– Critical—(2) Critical conditions
– Error—(3) Error conditions
– Warning—(4) Warning conditions
– Notification—(5) Normal but significant condition
– Informational—(6) Informational messages only
– Debugging—(7) Debugging messages
|
Enable Logging (IOS)
Log Input
|
Whether to generate an informational logging message about the packet that matches the entry to be sent to the console for IOS devices.
Select Log Input to include the input interface and source MAC address or virtual circuit in the logging output.
|
Traffic Direction
(Advanced dialog box only)
|
The direction of the traffic to which this rule applies:
• In—Packets entering an interface.
• Out—Packets exiting an interface.
|
Time Range
|
The name of a time range policy object that defines the times when access to the device will be allowed by this rule. The time is based on the system clock of the device. The feature works best if you use NTP to configure the system clock.
Enter the name or click Select to select the object. If the object that you want is not listed, click the Create button to create it.
Note Time range is not supported on FWSM 2.x or PIX 6.3 devices.
|
Options (IOS)
|
Additional options for IOS devices:
• Fragment—Allow fragmentation, which provides additional management of packet fragmentation and improves compatibility with NFS.
By default, a maximum of 24 fragments is accepted to reconstruct a full IP packet; however, based on your network security policy, you might want to consider configuring the device to prevent fragmented packets from traversing the firewall.
• Established—Allow outbound TCP connections to return access through the device. This option works with two connections: an original connection outbound from a network protected by the device, and a return connection inbound between the same two devices on an external host.
|
Rule Expiration
(Advanced dialog box only)
|
Whether to configure an expiration date for the rule. Click the calendar icon to select a date. For more information, see Configuring Expiration Dates for Access Rules, page 11-22.
If you configure an expiration date, you can also configure the number of days before which the rule expires to send out a notification of the pending expiration, and e-mail addresses to which to send the notifications. These fields are initially filled with the information configured on the Rule Expiration administrative settings page (select Tools > Security Manager Administration > Rule Expiration).
Expired rules are not automatically deleted. You must delete them yourself and redeploy the configuration to the device.
|
Edit Firewall Rule Expiration Settings Dialog Box
Use the Edit Firewall Rule Expiration Settings dialog box to edit the expiration settings for an access rule.
To set an expiration date for the rule, click the calendar icon to select a date.
If you configure an expiration date, you can also configure the number of days before which the rule expires to send out a notification of the pending expiration, and e-mail addresses to which to send the notifications. These fields are initially filled with the information configured on the Rule Expiration administrative settings page (select Tools > Security Manager Administration > Rule Expiration).
Expired rules are not automatically deleted. You must delete them yourself and redeploy the configuration to the device.
For more information, see Configuring Expiration Dates for Access Rules, page 11-22.
Navigation Path
Right-click the Expiration Date cell in an access rule (on the Access Rules Page) and select Edit Rule Expiration. If you select multiple rows, your changes replace the options defined for all selected rules.
Related Topics
•
Editing Rules, page 11-5
•
Working with Access Rules, page 11-17
Inspection Rules Page
Use the Inspection Rules page to identify inspection rules managed by Security Manager. For more information, see Understanding Inspection Rules, page 11-33.
From the Inspection Rules page, you can add, edit, and delete rules, reorder rules, and enable or disable rules in the table. You perform these tasks using either the shortcut menu, which is accessed by right-clicking a table cell, or by selecting the appropriate buttons located below the table.
From the Inspection Rules page, you can generate reports to discover object groups that are being used and identify policies associated with a particular device.
Navigation Path
To access the Inspection Rules page, do one of the following:
•
(Device view) Select a device, then select Firewall >Inspection Rules from the Device selector.
•
(Policy view) Select Firewall >Inspection Rules from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Policies > Inspection Rules.
Related Topics
•
Understanding Inspection Rules, page 11-33
•
Filtering Tables, page 2-16
Field Reference
Table I-9 Inspection Rules Page
Element
|
Description
|
No.
|
Identifies the ordered rule number in the table.
|
Permit
|
Whether a rule permits or denies traffic based on the conditions set.
• Permit—Shown as a green check mark.
• Deny—Shown as a red circle with slash.
|
Source
|
Identifies the source network object names or addresses of hosts and networks, for example, 10.1.1.1, 10.1.1.1/32, 10.1.1.1/255.255.255.255 and net10. Interface roles can also be used to identify a source. Multiple entries are displayed as separate subfields within the table cell. For more information, see the following:
• Understanding Network/Host Objects, page 8-65
• Understanding Interface Role Objects, page 8-33
Note If you manually enter 0.0.0.0/0 for the source, it automatically matches the "any" predefined object.
|
Destination
|
Identifies the destination network object names or addresses of hosts and networks, for example, 10.1.1.1, 10.1.1.1/32, 10.1.1.1/255.255.255.255 and net10. Interface roles can also be used to identify a destination. Multiple entries are displayed as separate subfields within the table cell. For more information, see the following:
• Understanding Network/Host Objects, page 8-65
• Understanding Interface Role Objects, page 8-33
Note If you manually enter 0.0.0.0/0 for the destination, it automatically matches the "any" predefined object.
|
Service
|
Identifies service objects that specify protocol and port information. Multiple entries are displayed as separate subfields within the table cell. See Understanding and Specifying Services and Service and Port List Objects, page 8-75.
Note If you manually enter a service, such as TCP / 80, and that data translates directly to a predefined service object, such as HTTP, the rule takes the predefined object as its value.
|
Interface
|
Identifies the logical name of the interface (interface role) or physical interface to which a rule is assigned. See Understanding Interface Role Objects, page 8-33.
For example:
• All DMZs
• All Fast Ethernets
• All Interfaces
• FastEthernet0
Note Interface roles are objects that are used to help you configure firewall rules. The objects are replaced with the actual interface names when the configuration is generated for each device.
|
Dir.
|
(Direction) Identifies traffic direction within a network. Direction is always associated with an interface:
• In—Packets entering a network.
• Out—Packets exiting a network.
Note The Direction parameter is supported on IOS devices only.
|
Inspected Protocol
|
Identifies the protocol to be inspected.
|
Time Range
|
Defines access to a firewall device or security appliance based on specific times of the day and weekly access. Time range relies on the system clock of the device or appliance; however, the feature works best with NTP synchronization. See Creating Time Range Objects, page 8-92.
Note Time range is not supported on FWSM 2.x or PIX 6.3 devices.
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Description
|
Shows a user-defined description to help you identify a rule when viewing the rules table. A maximum of 1024 characters is allowed.
|
Tools button
|
Click this button to select tools that you can use with this type of policy. You can select from the following tools:
• Query—To run policy queries, which can help you evaluate your rules and identify ineffective rules that you can delete. See Generating Policy Query Reports, page 11-12
|
Find and Replace button (binoculars icon)
|
Searches for values in rules tables, such as IP addresses and policy object names, to facilitate locating and making changes to rules in tables. See Finding and Replacing Items in Rules Tables, page 11-6.
|
Up Row and Down Row buttons (arrow icons)
|
Click these buttons to move the selected rules up or down within a scope or section. For more information, see Moving Rules and the Importance of Rule Order, page 11-7.
|
Add button
|
Adds a rule to the table.
|
Edit button
|
Edits an existing rule in the table.
|
Delete button
|
Deletes a rule from the table.
|
Add and Edit Inspection Rule Dialog Boxes
Use the Add and Edit Inspection Rule dialog boxes to add and edit inspection rules.
Navigation Path
To access the Add and Edit Inspection Rule dialog boxes, do one of the following:
•
(Device view) Select a device, then select Firewall >Inspection Rules from the Device selector. Right-click inside the table, then select Add Rule, or right-click a rule, then select Edit Rule.
•
(Policy view) Select Firewall >Inspection Rules from the Policy selector. Right-click inside the table, then select Add Rule, or right-click a rule, then select Edit Rule.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-10 Add and Edit Inspect/Application FW Rule Dialog Boxes
Element
|
Description
|
Apply the Rule to
|
Enable Rule
|
When selected, indicates that the rule becomes active on a device after the configuration is generated and deployed.
When viewing the main rules tables:
• An enabled rule is shown without hash marks.
• A disabled rule is shown with hash marks.
Note A disabled rule is not generated and deployed to devices; however, it is retained in the rules table for debugging purposes.
|
All Interfaces
|
Enables you to add an inspection rule that will be associated with all interfaces.
Note Global inspection is supported for PIX and ASA devices only; however, although IOS doesn't support global inspection, it is simulated when you create an IOS inspection rule and apply it globally. Such a rule is applied to all interfaces in the direction "in".
|
Interface (PIX 7.x, ASA, FWSM 3.x, IOS)
|
Enables you to add an inspection rule based on an interface.
|
Traffic Direction
|
Enables you to further define deep packet inspection by identifying traffic direction within a network:
• In—Packets entering a network.
• Out—Packets exiting a network.
Note Traffic direction is active only when inspection is based on an interface.
|
Interfaces
|
Identifies the logical name of the interface (interface role) or physical interface to which a rule is assigned. For example:
• All DMZs
• All Fast Ethernets
• All Interfaces
• FastEthernet0
This is a required field if you apply the rule to ASA or IOS device interfaces.
Enter the interface information or click Select, which opens the Interface Selector dialog box from which to make your selection. You can also create an interface role by clicking the Create button in the Interface Selector dialog box.
Note Interface roles are objects that are used to help you configure firewall rules. The objects are replaced with the actual interface names when the configuration is generated for each device. See Understanding Interface Role Objects, page 8-33.
|
Match Traffic By
|
Default Protocol Ports
|
Enables you to inspect traffic based on a default protocol setting. Select this option if you want to inspect a protocol without applying any constraints to the inspected traffic. For a description of the GUI elements, see Table I-11.
Note You must click Next to open the appropriate wizard page.
|
Limit inspection between source and destination IP addresses (ASA, FWSM 3.x)
|
When selected, enables you to limit inspection between source and destination IP addresses. This setting applies to PIX 7.0, ASA, and FWSM 3.x devices only. For a description of the GUI elements, see Table I-13.
Note You must click Next to open the appropriate wizard page.
|
Custom Destination Ports
|
Enables you to inspect traffic based on TCP or UDP destination ports.
Select this option if you want to associate additional TCP or UDP traffic with a given protocol, for example, treating TCP traffic on destination port 8080 as HTTP traffic. For a description of the GUI elements, see Table I-14.
Note You must click Next to open the appropriate wizard page.
|
Destination Address and Port (IOS)
|
Enables you to inspect traffic on IOS devices based on destination IP addresses.
Select this option if you want to associate additional traffic with a given protocol only when the traffic is going to certain destinations, for example, if you want to treat TCP traffic on destination port 8080 as HTTP only when the traffic is going to server 192.168.1.1. For a description of the GUI elements, see Table I-15.
Note You must click Next to open the appropriate wizard page.
|
Source and Destination Address and Port (PIX 7.x, ASA, FWSM 3.x)
|
Enables you to inspect traffic on ASA and FWSM 3.x devices based on source and destination IP addresses and ports. For a description of the GUI elements, see Table I-16.
Note You must click Next to open the appropriate wizard page.
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Description
|
Shows a user-defined description to help you identify a rule when viewing the rules table. A maximum of 1024 characters is allowed.
|
Add Inspect/Application FW Rule Wizard Inspected Protocol Page and Edit Inspected Protocol Dialog Boxes
Use the Inspected Protocol page of the Add Inspect/Application FW Rule wizard, or the Edit Inspected Protocol dialog box, to configure the protocol inspected by an inspection rule.
Navigation Path
Do one of the following:
•
To access the Inspected Protocol page, go to the Inspection Rules Page and click Add Row to add a new rule, or select a rule and click Edit Row. Advance the wizard to this page.
•
To access the Edit Inspected Protocols dialog box, right-click the Inspected Protocol cell in an inspection rule and select Edit Inspected Protocol. If you select multiple rows, your changes replace the inspected protocol defined for all selected rules.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Configuring Default Protocol Ports, page 11-36
•
Understanding Inspection Rules, page 11-33
•
Filtering Tables, page 2-16
Field Reference
Table I-11 Inspected Protocols Dialog Box
Element
|
Description
|
Protocols table
|
Lists the protocols that you can inspect. You can select one protocol per rule. The list includes information on the device operating systems that allow inspection of the protocol: do not select protocols that are not supported by the device type on which you will use the inspection rule policy.
The group column provides additional information on the use of some of the protocols.
|
Selected Protocol
Configure button
|
Displays the protocol you selected. If the protocol allows additional configuration, the Configure button becomes active; click it to see your options, and click the Help button in the dialog box that is opened for information about the options. For more information about protocols that allow configuration, see Protocols Supporting Configuration Options.
|
Rule Settings (IOS)
|
Additional settings for the rule if it is used on devices running Cisco IOS software. If you select Use Default Inspection settings, the IOS defaults, or the settings defined in the inspection settings policy (see Inspection Settings Page), are used. These are the settings you can enable or disable:
• Alert—Whether to generate stateful packet inspection alert messages on the console.
• Audit—Whether audit trail messages are logged to the syslog server or router.
• Timeout—Whether to configure the length of time, in seconds, for which a session is managed while there is no activity. If you select Specify Timeout, enter the timeout value; the range is 5 to 43200 seconds.
• Inspect Router Generated Traffic—Whether to inspect traffic that is generated by the device itself. This option is available for a limited number of the protocols.
|
Protocols Supporting Configuration Options
Table I-12 is a partial list of protocols that allow you to configure additional settings options.
Table I-12 Protocols Supporting Configuration Options
Element
|
Description
|
DNS
|
Sets maximum DNS packet length (PIX/ASA/FWSM/IOS). Values are 512-65535. Also, you can configure DNS policy maps and dynamic snooping. For more information, see Configure DNS Dialog Box.
|
FTP Strict
|
Enables you to select or create an FTP Map object to configure application firewall (PIX/ASA 7.x/FWSM/IOS). To configure FTP strict inspection, no map is required.
|
GTP
|
Enables you to select or create a GTP Map object to configure application firewall (PIX/ASA 7.x/FWSM 3.x). To configure GTP inspection, no map is required.
|
HTTP
|
Enables you to select or create an HTTP Map object to configure application firewall (PIX/ASA 7.x/FWSM/IOS). To configure HTTP inspection, no map is required.
|
RPC
|
Requires a program number and wait time (IOS/FWSM 2.x).
• Program number values are 1-4294967295.
• Wait time values are 0-35791.
For more information, see Configure RPC Dialog Box.
|
SMTP
|
Sets maximum data length (PIX/FWSM/IOS). Values are 0-4294967295. For more information, see Configure SMTP Dialog Box.
|
Custom protocol
|
Requires a custom protocol name. Custom protocols allow you to associate protocols with destination ports and inspect them, for example, TCP with destination ports 12000, UDP with destination ports 8000-9000. For more information, see Custom Protocol Dialog Box.
|
ESMTP
|
Sets maximum data length (PIX/ASA/FWSM 3.x/IOS). Values are 0-4294967295. For more information, see Configure ESMTP Dialog Box.
|
Fragment
|
Sets maximum fragments and timeout values (IOS).
• Fragment values are 0-10000.
• Timeout values are 1-1000.
For more information, see Configure Fragments Dialog Box.
|
IMAP
|
Includes optional settings for retrieving email (IOS). For more information, see Configure IMAP Dialog Box.
|
POP3
|
Includes optional settings for retrieving email (IOS). For more information, see Configure POP3 Dialog Box.
|
Limit Inspection Between Source and Destination IP Addresses
(ASA, FWSM 3.x) Page
Use this wizard page (Step 2) to inspect traffic for specific sources and destinations for ASA devices.
Navigation Path
To access the Limit Inspection Between Source and Destination Addresses (ASA, FWSM 3.x) wizard page, do one of the following:
•
(Device view) Select a device, then select Firewall >Inspection Rules from the Device selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
•
(Policy view) Select Firewall >Inspection Rules from the Policy selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
For more information, see:
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
Related Topics
•
Configuring Default Protocol Ports, page 11-36
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
•
Understanding Network/Host Objects, page 8-65
•
Understanding Interface Role Objects, page 8-33
•
Creating Time Range Objects, page 8-92
Field Reference
Table I-13 Limit Inspection Between Source and Destination Addresses (ASA, FWSM 3.x) Page
Element
|
Description
|
Action
|
Describes what should occur based on the conditions set.
• Permit—Allows traffic
• Deny—Denies traffic
|
Sources
Destinations
|
The source or destination of the traffic. You can enter more than one value by separating the items with commas.
You can enter any combination of the following address types to define the source or destination of the traffic. For more information, see Specifying IP Addresses During Policy Definition, page 8-68.
• Network/host object. Enter the name of the object or click Select to select it from a list. You can also create new network/host objects from the selection list.
• Host IP address, for example, 10.10.10.100.
• Network address, including subnet mask, in either the format 10.10.10.0/24 or 10.10.10.0/255.255.255.0.
• A range of IP addresses, for example, 10.10.10.100-10.10.10.200.
• An IP address pattern in the format 10.10.0.10/255.255.0.255, where the mask is a discontiguous bit mask (see Contiguous and Discontiguous Network Masks, page 8-65).
• Interface role object. Enter the name of the object or click Select to select it from a list (you must select Interface Role as the object type). When you use an interface role, the rule behaves as if you supplied the IP address of the selected interface. This is useful for interfaces that get their address through DHCP, because you do not know what IP address will be assigned to the device. For more information, see Understanding Interface Role Objects, page 8-33.
If you select an interface role as a source, the dialog box displays tabs to differentiate between hosts or networks and interface roles.
|
Time Range
|
Defines access to a firewall device or security appliance based on specific times of the day and weekly access. Time range relies on the system clock of the device or appliance; however, the feature works best with NTP synchronization.
Enter the time range value in the field provided or click Select, which opens the Object Selector dialog box from which to make your selection. You can also create a Time Range object by clicking the Create button in the Object Selector dialog box.
Note Time range is not supported on FWSM 2.x or PIX 6.3 devices.
|
Match Traffic by Custom Destination Ports Page
Use this wizard page (Step 2) to select protocol and port values for TCP or UDP destination ports.
Navigation Path
To access the Match Traffic By Custom Destination Ports wizard page, do one of the following:
•
(Device view) Select a device, then select Firewall >Inspection Rules from the Device selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
•
(Policy view) Select Firewall >Inspection Rules from the Policy selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
For more information, see:
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
Related Topics
•
Configuring Custom Destination Ports, page 11-36
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-14 Match Traffic By Custom Destination Ports Page
Element
|
Description
|
Protocol
|
• TCP
• UDP
• TCP/UDP
|
Ports
|
Specifies port information. Values are 1-65535.
• Single—Identifies a single port value. When selected, requires a port value.
• Range—Identifies a range of port values. When selected, requires a range of port values.
Note Port range values might not be supported on all platforms or OS versions. In such cases, a validation error results.
|
Match Traffic by Destination Address and Port (IOS) Page
Use this wizard page (Step 2) to select protocol and port values for specific destinations for IOS devices.
To treat this matched traffic type as a supported inspect protocol only when destined to certain hosts, you should create a network policy object and include the list of hosts in it. Alternatively, you can also enter a list of host IP addresses as Destinations.
Navigation Path
To access the Match Traffic By Destination Address and Port (IOS) wizard page, do one of the following:
•
(Device view) Select a device, then select Firewall >Inspection Rules from the Device selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
•
(Policy view) Select Firewall >Inspection Rules from the Policy selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
For more information, see:
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
Related Topics
•
Configuring Destination Address and Port (IOS), page 11-37
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
•
Understanding Network/Host Objects, page 8-65
Field Reference
Table I-15 Match Traffic By Destination Address and Port (IOS)
Element
|
Description
|
Destinations
|
The destination of the traffic. You can enter more than one value by separating the items with commas.
You can enter any combination of the following address types to define the destination of the traffic. For more information, see Specifying IP Addresses During Policy Definition, page 8-68.
• Network/host object. Enter the name of the object or click Select to select it from a list. You can also create new network/host objects from the selection list.
• Host IP address, for example, 10.10.10.100.
• Network address, including subnet mask, in either the format 10.10.10.0/24 or 10.10.10.0/255.255.255.0.
• A range of IP addresses, for example, 10.10.10.100-10.10.10.200.
• An IP address pattern in the format 10.10.0.10/255.255.0.255, where the mask is a discontiguous bit mask (see Contiguous and Discontiguous Network Masks, page 8-65).
|
Protocol
|
The protocol for the traffic, either TCP, UDP, or both (TCP/UDP).
|
Ports
|
• Single—Identifies a single port value. Values are 1-65535.
• Range—Identifies a range of port values. Values are 1-65535.
|
Match Traffic by Source and Destination Address and Port
(ASA, FWSM 3.x) Page
Use this wizard page (Step 2) to inspect traffic for specific sources and destinations for ASA and FWSM 3.x devices.
Select this matched traffic type if you want to limit inspection of traffic flowing between a set of source and destination addresses, for example, if you want to inspect FTP traffic flowing between 192.168.1.0/24 and 192.168.2.0/24.
You can use policy objects for sources, destinations and services. A time range can also be specified, which will activate the traffic criteria only during that period of time.
Navigation Path
To access the Match Traffic By Source and Destination Address and Port (ASA, FWSM 3.x) wizard page, do one of the following:
•
(Device view) Select a device, then select Firewall >Inspection Rules from the Device selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
•
(Policy view) Select Firewall >Inspection Rules from the Policy selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
Related Topics
•
Configuring Source and Destination Address and Port (ASA, FWSM 3.x), page 11-38
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
•
Understanding Network/Host Objects, page 8-65
•
Understanding Interface Role Objects, page 8-33
•
Understanding and Specifying Services and Service and Port List Objects, page 8-75
•
Creating Time Range Objects, page 8-92
Field Reference
Table I-16 Match Traffic By Source and Destination Address and Port (ASA, FWSM 3.x) Page
Element
|
Description
|
Action
|
Describes what should occur based on the conditions set.
• Permit—Allows traffic.
• Deny—Denies traffic.
|
Sources
Destinations
|
The source or destination of the traffic. You can enter more than one value by separating the items with commas.
You can enter any combination of the following address types to define the source or destination of the traffic. For more information, see Specifying IP Addresses During Policy Definition, page 8-68.
• Network/host object. Enter the name of the object or click Select to select it from a list. You can also create new network/host objects from the selection list.
• Host IP address, for example, 10.10.10.100.
• Network address, including subnet mask, in either the format 10.10.10.0/24 or 10.10.10.0/255.255.255.0.
• A range of IP addresses, for example, 10.10.10.100-10.10.10.200.
• An IP address pattern in the format 10.10.0.10/255.255.0.255, where the mask is a discontiguous bit mask (see Contiguous and Discontiguous Network Masks, page 8-65).
• Interface role object. Enter the name of the object or click Select to select it from a list (you must select Interface Role as the object type). When you use an interface role, the rule behaves as if you supplied the IP address of the selected interface. This is useful for interfaces that get their address through DHCP, because you do not know what IP address will be assigned to the device. For more information, see Understanding Interface Role Objects, page 8-33.
If you select an interface role as a source, the dialog box displays tabs to differentiate between hosts or networks and interface roles.
|
Services
|
The services that define the type of traffic to act on. You can enter more than one value by separating the items with commas.
You can enter any combination of service objects and service types (which are typically a protocol and port combination). If you type in a service, you are prompted as you type with valid values. You can select a value from the list and press Enter or Tab.
For complete information on how to specify services, see Understanding and Specifying Services and Service and Port List Objects, page 8-75.
|
Time Range
|
Defines access to a firewall device or security appliance based on specific times of the day and weekly access. Time range relies on the system clock of the device or appliance; however, the feature works best with NTP synchronization.
Enter the time range value in the field provided or click Select, which opens the Object Selector dialog box from which to make your selection. You can also create a Time Range object by clicking the Create button in the Object Selector dialog box.
Note Time range is not supported on FWSM 2.x or PIX 6.3 devices.
|
Configure DNS Dialog Box
Use the Configure DNS dialog box to configure settings for DNS inspection on PIX 7.0+, ASA, FWSM, and IOS devices.
Navigation Path
Go to the Add Inspect/Application FW Rule Wizard Inspected Protocol Page and Edit Inspected Protocol Dialog Boxes, select DNS in the protocols table, and click Configure.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
•
Botnet Traffic Filter Rules Page
Field Reference
Table I-17 Configure DNS Dialog Box
Element
|
Description
|
Maximum DNS Packet Length
|
The maximum DNS packet length. Values are 512 to 65535.
|
DNS Map
|
The DNS policy map object that defines traffic match conditions and actions, protocol conformance policies, and filter settings. Enter the object name, or click Select to select it. If the object that you want is not listed, click the Create button to create it.
|
Enable Dynamic Filter Snooping
|
Whether to allow the security appliance to snoop DNS packets in order to build a database of DNS lookup information. This information is used by botnet traffic filtering to match DNS names to IP addresses.
If you configure a botnet traffic filtering rules policy, select this option. Otherwise, do not select the option.
|
Configure SMTP Dialog Box
Use the SMTP dialog box to edit settings for Simple Mail Transfer Protocol (SMTP) inspection (PIX/FWSM/IOS). SMTP is used to transfer email between servers and clients on the Internet. email clients and mail servers that use protocols other than Message Application Programming Interface (MAPI) can use the SMTP protocol to transfer a message from a client to the server, and then forward it to a message recipient's server.
SMTP inspection causes Simple Mail Transfer Protocol (SMTP) commands to be inspected for illegal commands. Any packets with illegal commands are dropped, and the SMTP session will hang and eventually time out.
Navigation Path
You can access the Configure SMTP dialog box from the Inspection Rules table. Select SMTP as the protocol for inspection, then click Configure.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-18 Configure SMTP Dialog Box
Element
|
Description
|
Maximum Data
|
Values are 0 to 4294967295.
|
Custom Protocol Dialog Box
Use the Custom Protocol dialog box to edit settings for custom protocol inspection (IOS). Custom protocols allow you to associate protocols with destination ports and inspect them, for example, TCP with destination ports 12000, UDP with destination ports 8000-9000.
Navigation Path
You can access the Custom Protocol dialog box from the Inspection Rules table. Select, Custom Protocol as the protocol for inspection, then click Configure.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-19 Configure Custom Protocol Dialog Box
Element
|
Description
|
Custom Protocol Name
|
Identifies the name associated with the custom protocol.
|
Configure ESMTP Dialog Box
Use the Configure ESMTP dialog box to edit settings for Extended Simple Mail Transport Protocol (ESMTP) inspection (PIX/ASA/FWSM 3.x/IOS). ESMTP enables users who install mail servers behind Cisco IOS firewalls to install their servers on the basis of ESMTP (instead of Simple Mail Transport Protocol [SMTP]).
Navigation Path
You can access the Configure ESMTP dialog box from the Inspection Rules table. Select ESMTP as the protocol for inspection, then click Configure.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-20 Configure ESMTP Dialog Box
Element
|
Description
|
Maximum Data
|
Values are 0 to 4294967295.
|
Configure Fragments Dialog Box
Use the Configure Fragments dialog box to edit settings for fragment inspection.
Navigation Path
You can access the Configure Fragments dialog box from the Inspection Rules table. Select Fragments as the protocol for inspection, then click Configure.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-21 Configure Fragments Dialog Box
Element
|
Description
|
Maximum Fragments
|
Specifies the maximum number of unassembled packets for which state information (structures) is allocated by Cisco IOS software. Unassembled packets are packets that arrive at the router interface before the initial packet for a session. Values are 0-10000 state entries. Default is 256.
Note Memory is allocated for the state structures, and setting this value to a larger number may cause memory resources to be exhausted.
|
Timeout (sec)
|
Configures the number of seconds that a packet state structure remains active. When the timeout value expires, the router drops the unassembled packet, freeing that structure for use by another packet. Values are 1 to 1000. Default timeout value is one second.
If this number is set to a value greater that one second, it is automatically adjusted by the Cisco IOS software when the number of free state structures goes below certain thresholds:
• When the number of free states is less than 32, the timeout is divided by two.
• When the number of free states is less than 16, the timeout is set to one second.
|
Configure IMAP Dialog Box
Use the Configure IMAP dialog box to edit settings for Internet Message Access Protocol (IMAP) inspection (IOS). IMAP is a method for accessing electronic mail or bulletin board messages that are kept on a mail server that may be shared. It permits a client email program to access remote messages as though they were local.
Navigation Path
You can access the Configure IMAP dialog box from the Inspection Rules table. Select IMAP as the protocol for inspection, then click Configure.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-22 Configure IMAP Dialog Box
Element
|
Description
|
Reset Connection on Invalid IMAP packet
|
When selected, requires that the client/server communication repeat the validation process from the time the TCP connection is initialized until the client is authenticated.
|
Enforce Secure Authentication
|
When selected, allows you to download external IMAP email only if authentication methods are secure, which generates the secure-login command.
|
Configure POP3 Dialog Box
Use the Configure POP3 dialog box to edit settings for Post Office Protocol, Version 3 (POP3) inspection (IOS). POP3 is used to receive email that is stored on a mail server. Unlike IMAP, POP retrieves mail only from a remote host.
Navigation Path
You can access the Configure POP3 dialog box from the Inspection Rules table. Select POP3 as the protocol for inspection, then click Configure.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-23 Configure POP3 Dialog Box
Element
|
Description
|
Reset Connection on Invalid POP3 packet
|
When selected, requires that the client/server communication repeat the validation process from the time the TCP connection is initialized until the client is authenticated.
|
Enforce Secure Authentication
|
When selected, allows you to download external POP3 email only if authentication methods are secure, which generates the secure-login command.
|
Configure RPC Dialog Box
Use the RPC dialog box to edit settings for RPC inspection (IOS). RPC inspection allows the specification of various program numbers. You can define multiple program numbers by creating multiple entries for RPC inspection, each with a different program number. If a program number is specified, all traffic for that program number will be permitted. If a program number is not specified, all traffic for that program number is blocked. For example, if you create an RPC entry with the NFS program number, all NFS traffic will be allowed through the firewall.
Navigation Path
You can access the Configure RPC dialog box from the Inspection Rules table. Select RPC as the protocol for inspection, then click Configure.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-24 Configure RPC Dialog Box
Element
|
Description
|
Program Number
|
Specifies the program number to permit. Values are 1 to 4294967295.
|
Wait Time
|
Specifies the number of minutes to keep a small hole in the firewall to allow subsequent connections from the same source address and to the same destination address and port. Values are 0 to 35791 minutes. Default is zero.
|
Configuring Protocol Platform Dialog Box
Use the Configure (Protocol Platform) dialog box to choose a policy object based on device type.
Navigation Path
You can access the Configure (Protocol Platform) dialog box from the Inspection Rules table. Select HTTP or IM as the protocol for inspection, then click Configure.
Related Topics
•
Adding Inspection Rules, page 11-34
•
Editing Rules, page 11-5
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-25 Configuring Protocol Platform Dialog Box
Element
|
Description
|
Platform radio buttons
|
Enables you to select the device type, which then enables you to enter the information in the field provided or click Select, which opens the appropriate Selector dialog box from which to make your selection.
|
Botnet Traffic Filter Rules Page
You can use the Botnet Traffic Filter Rules page to define rules for identifying malicious traffic passing through your ASA security device.
The Botnet Traffic Filter Rules page is divided into three sections:
•
Dynamic Blacklist Configuration Tab
•
Traffic Classification Tab
•
Whitelist/Blacklist Tab
Navigation Path
To access the Botnet Traffic Filter Rules page, do one of the following:
•
(Device view) Select a device, then select Firewall > Botnet Traffic Filter Rules from the Policy selector.
•
(Policy view) Select Firewall > Botnet Traffic Filter Rules from the Policy Type selector. Select an existing policy or create a new one.
•
(Map view) Right-click a device and select Edit Firewall Policies > Botnet Traffic Filter Rules.
Related Topics
•
Understanding Botnet Traffic Filtering, page 11-47
•
Task Flow for Configuring the Botnet Traffic Filter, page 11-48
•
Dynamic Blacklist Configuration Tab
•
Traffic Classification Tab
•
Traffic Classification Dialog Box
•
Whitelist/Blacklist Tab
•
Device Whitelist or Device Blacklist Dialog Box
•
Configure DNS Dialog Box
Dynamic Blacklist Configuration Tab
Use the Dynamic Blacklist Configuration tab to enable database updates from the Cisco update server and to enable use of the downloaded dynamic database by the security appliance.
Navigation Path
From the Botnet Traffic Filter Rules Page, click the Dynamic Blacklist Configuration tab.
Related Topics
•
Configuring the Dynamic Database, page 11-49
•
Understanding Botnet Traffic Filtering, page 11-47
•
Task Flow for Configuring the Botnet Traffic Filter, page 11-48
•
Botnet Traffic Filter Rules Page
•
Traffic Classification Tab
•
Traffic Classification Dialog Box
•
Whitelist/Blacklist Tab
•
Device Whitelist or Device Blacklist Dialog Box
•
Configure DNS Dialog Box
Field Reference
Table I-26 Dynamic Blacklist Configuration Tab
Element
|
Description
|
Enable Dynamic Blacklist From Server
|
Enables downloading of the dynamic database from the Cisco update server. If you do not have a database already installed on the security appliance, it downloads the database after approximately 2 minutes. The update server determines how often the security appliance polls the server for future updates, typically every hour.
Note If the device is in multiple context mode, configure this option on the System context for that device.
|
Use Dynamic Blacklist
|
Enables use of the dynamic database for the Botnet Traffic Filter.
Note In multiple context mode, you configure use of the database on a per-context basis.
|
Traffic Classification Tab
Use the Traffic Classification tab to view or to configure the traffic classification definitions for a device or shared policy. Traffic classification definitions consist of an interface or interface role with an associated ACL that identifies the traffic that is monitored by the Botnet Traffic Filter. You can configure settings for specific interfaces or for interface roles. You can use the All Interfaces role object to enable botnet filtering globally (selected by default). If you configure an interface-specific classification, the settings for that interface override any settings defined for an interface role.
The columns in the table summarize the settings for an entry and are explained in Traffic Classification Dialog Box.
Tip
You can use the "Click here to go to Inspect Rules..." link at the bottom of the Traffic Classification tab to navigate directly to the Inspection Rules page so that you can enable DNS snooping. For more information, see Enabling DNS Snooping, page 11-51.
To configure traffic classification:
•
Click the Add Row button to add an interface or interface role to the table, and fill in the Traffic Classification Dialog Box.
•
Select an entry and click the Edit Row button to edit an existing entry.
•
Select an entry and click the Delete Row button to delete it.
Navigation Path
From the Botnet Traffic Filter Rules Page, click the Traffic Classification tab.
Related Topics
•
Traffic Classification Dialog Box
•
Enabling Traffic Classification for Botnet Traffic Filter Logging, page 11-52
•
Understanding Botnet Traffic Filtering, page 11-47
•
Task Flow for Configuring the Botnet Traffic Filter, page 11-48
•
Botnet Traffic Filter Rules Page
•
Dynamic Blacklist Configuration Tab
•
Whitelist/Blacklist Tab
•
Device Whitelist or Device Blacklist Dialog Box
•
Configure DNS Dialog Box
Traffic Classification Dialog Box
Use the Traffic Classification dialog box to specify the interfaces on which you want to enable the Botnet Traffic Filter and to identify the traffic that you want to monitor.
Navigation Path
To access the Traffic Classification dialog box, right-click inside the work area of the Traffic Classification tab and then select Add Row, or right-click an existing entry and select Edit Row.
Related Topics
•
Enabling Traffic Classification for Botnet Traffic Filter Logging, page 11-52
•
Understanding Botnet Traffic Filtering, page 11-47
•
Task Flow for Configuring the Botnet Traffic Filter, page 11-48
•
Botnet Traffic Filter Rules Page
•
Dynamic Blacklist Configuration Tab
•
Traffic Classification Tab
•
Whitelist/Blacklist Tab
•
Device Whitelist or Device Blacklist Dialog Box
•
Configure DNS Dialog Box
Field Reference
Table I-27 Traffic Classification Dialog Box
Element
|
Description
|
Interfaces
|
The interfaces or interface roles on which you want to enable the Botnet Traffic Filter. Enter the name of the interface or the interface role, or click Select to select the interface or role from a list, or to create a new role. An interface must already be defined to appear on the list.
You can use the All Interfaces role object to enable botnet filtering globally (selected by default). If you configure an interface-specific classification, the settings for that interface override the global settings.
Interface role objects are replaced with the actual interface names when the configuration is generated for each device. See Understanding Interface Role Objects, page 8-33.
|
ACL
|
Specifies the access-list to use for identifying the traffic that you want to monitor. If you do not specify an access list, by default you monitor all traffic.
To specify the traffic that you want to monitor, click Select to the right of the ACL field to select an Access Control List object that identifies the traffic that you want to monitor. For example, you might want to monitor all port 80 traffic on the outside interface. For more information about Access Control List objects, see Creating Access Control List Objects, page 8-23.
|
Whitelist/Blacklist Tab
Use the Whitelist/Blacklist tab to view or to configure the static database entries for a device or shared policy. The Device Blacklist contains domain names or IP addresses of malicious or undesirable sites. You can use the static blacklist to supplement the Cisco dynamic database or you can use the static blacklist alone if you can identify all the malware sites that you want to target.
The Device Whitelist contains domain names or IP addresses of sites that are deemed to be acceptable. If the dynamic database includes blacklisted addresses that you think should not be blacklisted, you can manually enter them into a static whitelist. Static whitelist entries take precedence over entries in the static blacklist and the Cisco dynamic database. Whitelisted addresses still generate syslog messages, but because you are only targeting blacklist syslog messages, they are informational.
To configure the static database:
•
Click the Add Row button to define static database entries using the Device Whitelist or Device Blacklist Dialog Box.
•
Select an entry and click the Edit Row button to edit an existing entry.
Timesaver
Select an entry and press F2 or double-click on an entry in the Device Whitelist or Device Blacklist to edit that entry in place.
•
Select an entry and click the Delete Row button to delete it.
Navigation Path
From the Botnet Traffic Filter Rules Page, click the Whitelist/Blacklist tab.
Related Topics
•
Adding Entries to the Static Database, page 11-50
•
Understanding Botnet Traffic Filtering, page 11-47
•
Task Flow for Configuring the Botnet Traffic Filter, page 11-48
•
Device Whitelist or Device Blacklist Dialog Box
•
Botnet Traffic Filter Rules Page
•
Dynamic Blacklist Configuration Tab
•
Traffic Classification Tab
Device Whitelist or Device Blacklist Dialog Box
Use the Device Whitelist or Device Blacklist dialog box to manually define domain names or IP addresses that you want to add to the whitelisted (safe) or blacklisted (malicious) lists. You can use the static blacklist to supplement the Cisco dynamic database or you can use the static blacklist alone if you can identify all the malware sites that you want to target. Names or addresses that appear on both the whitelist and the dynamic blacklist are identified only as whitelist addresses in syslog messages and reports.
Domain names can be complete (including the host name, such as www.cisco.com), or partial (such as cisco.com). For partial names, all web site hosts on that domain are either whitelisted or blacklisted. You can also enter host IP addresses. Use a comma or new line to separate multiple entries.
Navigation Path
From the Whitelist/Blacklist Tab, click the Add Rows button beneath the Device Whitelist or Device Blacklist tables, or select an entry and click the Edit Row button.
Related Topics
•
Adding Entries to the Static Database, page 11-50
•
Understanding Botnet Traffic Filtering, page 11-47
•
Task Flow for Configuring the Botnet Traffic Filter, page 11-48
•
Botnet Traffic Filter Rules Page
•
Dynamic Blacklist Configuration Tab
•
Traffic Classification Tab
•
Traffic Classification Dialog Box
•
Whitelist/Blacklist Tab
•
Configure DNS Dialog Box
Transparent Rules Page
Use the Transparent Rules page to identify EtherType rules defined in Security Manager. Before you can configure transparent rules on ASA/PIX 7.x+ security appliances or FWSM firewall devices, they must be configured in transparent mode.
To configure transparent rules on IOS devices, you must configure a bridge group with two or more layer 3 interfaces (see Bridging on Cisco IOS Routers, page 13-50 and Defining Bridge Groups, page 13-51) and create a bridge group virtual interface (BVI) (see Bridge-Group Virtual Interfaces, page 13-50).
From the Transparent Rules page, you can add, edit, and delete rules, reorder rules, and enable or disable rules in the table. You perform these tasks using either the shortcut menu, which is accessed by right-clicking a table cell, or by selecting the appropriate buttons located below the table.
Only EtherType rules are configured as firewall policies. To configure other types of transparent firewall features, select Platform > Bridging.
Note
Transparent rules are not supported on PIX 6.x devices or IOS devices with an image lower than 12.3(7)T.
Navigation Path
To access Transparent Rules, do one of the following:
•
(Device view) Select a device, then select Firewall >Transparent Rules from the Device selector.
•
(Policy view) Select Firewall > Transparent Rules from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Policies > Transparent Rules.
Related Topics
•
Working with Transparent Firewall Rules, page 11-58
•
Filtering Tables, page 2-16
Field Reference
Table I-28 Transparent Rules Page
Element
|
Description
|
No.
|
Identifies the ordered rule number in the table.
|
Permit
|
Whether a rule permits or denies traffic based on the conditions set.
• Permit—Shown as a green check mark.
• Deny—Shown as a red circle with slash.
|
EtherType
|
Specifies Ethernet packet type.
• Supports PIX/FWSM/ASA EtherType access-lists:
– IPX
– BPDU—Spanning Tree Bridge Protocol Data Units
– MPLS-UNICAST
– MPLS-MULTICAST
– Other—Any valid hex value from 0x600-0xFFFF.
• Supports IOS devices:
– Other—Any valid hex value from 0x0-0xFFFF.
|
Mask
|
Identifies a 16-bit hexadecimal number whose ones bits correspond to bits in the type-code argument that should be ignored when making a comparison. (A mask for a DSAP/SSAP pair should always be at least 0x0101. This is because these two bits are used for purposes other than identifying the SAP codes.)
|
Interface
|
Identifies the logical name of the interface (interface role) or physical interface to which a rule is assigned. Multiple entries are displayed as separate subfields within the table cell. See Understanding Interface Role Objects, page 8-33.
For example:
• All DMZs
• All FastEthernets
• All Interfaces
• FastEthernet0
Enter interface information, or click Select, which opens the Interface Selector dialog box from which to make your selection. You can also create an interface role by clicking the Create button in the Interface Selector dialog box.
Note Interface roles are objects that are used to help you configure firewall rules. The objects are replaced with the actual interface names when the configuration is generated for each device. The access-group command is generated for the interface role selected for PIX/FWSM/ASA. The bridge-group command is generated as a subcommand of the interface role.
|
Dir.
|
(Direction) Identifies traffic direction within a network. Direction is always associated with an interface:
• In—Packets entering a network.
• Out—Packets exiting a network.
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Description
|
Shows a user-defined description to help you identify a rule when viewing the rules table. A maximum of 1024 characters is allowed.
Note For PIX/FWSM/ASA, the description is mapped to access-list remark.
|
Up Row and Down Row buttons (arrow icons)
|
Click these buttons to move the selected rules up or down within a scope or section. For more information, see Moving Rules and the Importance of Rule Order, page 11-7.
|
Add button
|
Adds a rule to the table.
|
Edit button
|
Edits an existing rule in the table.
|
Delete button
|
Deletes a rule from the table.
|
Add and Edit Transparent Firewall Rule Dialog Boxes
Use the Add and Edit Transparent Firewall Rule dialog boxes to add and edit EtherType rules.
Navigation Path
To access Transparent Rules, do one of the following:
•
(Device view) Select a device, then select Firewall >Transparent Rules from the Device selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
•
(Policy view) Select Firewall > Transparent Rules from the Policy selector. Right-click inside the table, then click Add Row, or right-click a rule, then click Edit Row.
Related Topics
•
Adding Transparent Rules, page 11-59
•
Working with Transparent Firewall Rules, page 11-58
Field Reference
Table I-29 Add and Edit Transparent Firewall Rule Dialog Boxes
Element
|
Description
|
Enable Rule
|
When selected, indicates that the rule becomes active on a device after the configuration is generated and deployed.
When viewing the main rules tables:
• An enabled rule is shown without hash marks.
• A disabled rule is shown with hash marks.
Note A disabled rule is not generated and deployed to devices; however, it is retained in the rules table for debugging purposes.
|
Action
|
Describes what should occur based on the conditions set.
• Permit—Allows traffic.
• Deny—Denies traffic.
|
Interfaces
|
Identifies the logical name of the interface (interface role) or physical interface to which a rule is assigned. See Understanding Interface Role Objects, page 8-33.
For example:
• All DMZs
• All Fast Ethernets
• All Interfaces
• FastEthernet0
Click Edit, which opens the Interface Selector dialog box from which to make your selection. You can also create an interface role by clicking the Create button in the Interface Selector dialog box.
Note Interface roles are objects that are used to help you configure firewall rules. The objects are replaced with the actual interface names when the configuration is generated for each device. The access-group command is generated for the interface role selected for PIX/FWSM/ASA. The bridge-group command is generated as a subcommand of the interface role.
|
Traffic Direction
|
Identifies traffic direction within a network. Direction is always associated with an interface.
• In—Packets entering a network.
• Out—Packets exiting a network.
|
EtherType
|
Specifies Ethernet packet type.
• Supports PIX/FWSM/ASA EtherType access-lists:
– IPX
– BPDU—Spanning Tree Bridge Protocol Data Units
– MPLS-UNICAST
– MPLS-MULTICAST
– Other—Any valid hex value from 0x600-0xFFFF.
• Supports IOS devices:
– Other—Any valid hex value from 0x0-0xFFFF.
|
Wildcard Mask (IOS)
|
Identifies a 16-bit hexadecimal number whose ones bits correspond to bits in the type-code argument that should be ignored when making a comparison. (A mask for a DSAP/SSAP pair should always be at least 0x0101. This is because these two bits are used for purposes other than identifying the SAP codes.)
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Description
|
Shows a user-defined description to help you identify a rule when viewing the rules table. A maximum of 1024 characters is allowed.
Note For PIX/FWSM/ASA, the description is mapped to access-list remark.
|
Edit Transparent EtherType Dialog Box
Use the Edit Transparent EtherType dialog box to edit EtherType settings in a table.
Navigation Path
To access the Edit Transparent EtherType dialog box, right-click the entry in the EtherType column of the Transparent Rules table, then click Edit EtherType.
Related Topics
•
Adding Transparent Rules, page 11-59
•
Editing Rules, page 11-5
•
Working with Transparent Firewall Rules, page 11-58
Field Reference
Table I-30 Edit Transparent EtherType Dialog Box
Element
|
Description
|
EtherType
|
Specifies Ethernet packet type.
• Supports PIX/FWSM/ASA EtherType access-lists:
– IPX
– BPDU—Spanning Tree Bridge Protocol Data Units
– MPLS-UNICAST
– MPLS-MULTICAST
– Other—Any valid hex value from 0x600-0xFFFF.
• Supports IOS devices:
– Other—Any valid hex value from 0x0-0xFFFF.
|
Edit Transparent Mask Dialog Box
Use the Edit Transparent Mask dialog box to edit mask settings in a table.
Navigation Path
To access the Edit Transparent Mask dialog box, right-click the entry in the Mask column of the Transparent Rules table, then click Edit Mask.
Related Topics
•
Adding Transparent Rules, page 11-59
•
Editing Rules, page 11-5
•
Working with Transparent Firewall Rules, page 11-58
Field Reference
Table I-31 Edit Transparent Mask Dialog Box
Element
|
Description
|
Wildcard Mask (IOS)
|
Identifies a 16-bit hexadecimal number whose ones bits correspond to bits in the type-code argument that should be ignored when making a comparison. (A mask for a DSAP/SSAP pair should always be at least 0x0101. This is because these two bits are used for purposes other than identifying the SAP codes.)
|
Web Filter Rules Page (PIX/ASA)
Use the Web Filter Rules page to identify web filter rules defined in Security Manager for PIX and ASA devices.
From the Web Filter Rules page, you can add, edit, and delete rules, reorder rules, and enable or disable rules in the table. You perform these tasks using either the shortcut menu, which is accessed by right-clicking a table cell, or by selecting the appropriate buttons located below the table.
Navigation Path
To access the Web Filter Rules page for PIX/ASA devices, do one of the following:
•
(Device view) Select a device, then select Firewall >Web Filter Rules from the Device selector.
•
(Policy view) Select Firewall >Web Filter Rules from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Policies > Web Filter Rules.
Related Topics
•
Understanding Web Filter Rules, page 11-54
•
Filtering Tables, page 2-16
Field Reference
Table I-32 Web Filter Rules Page (PIX/ASA)
Element
|
Description
|
No.
|
Identifies the ordered rule number in the table.
|
Source
|
Identifies the source network object names or addresses of hosts and networks, for example, 10.1.1.1, 10.1.1.1/32, 10.1.1.1/255.255.255.255 and net10. Interface roles can also be used to identify a source. Multiple entries are displayed as separate subfields within the table cell. See:
• Understanding Network/Host Objects, page 8-65.
• Understanding Interface Role Objects, page 8-33.
Note If you manually enter 0.0.0.0/0 for the source, it automatically matches the "any" predefined object.
|
Destination
|
Identifies the destination network object names or addresses of hosts and networks, for example, 10.1.1.1, 10.1.1.1/32, 10.1.1.1/255.255.255.255 and net10. Interface roles can also be used to identify a destination. Multiple entries are displayed as separate subfields within the table cell. See:
• Understanding Network/Host Objects, page 8-65.
• Understanding Interface Role Objects, page 8-33.
Note If you manually enter 0.0.0.0/0 for the destination, it automatically matches the "any" predefined object.
|
Service
|
Identifies service objects that specify protocol and port information. Multiple entries are displayed as separate subfields within the table cell. See Understanding and Specifying Services and Service and Port List Objects, page 8-75.
Note If you manually enter a service, such as TCP / 80, and that data translates directly to a predefined service object, such as HTTP, the rule takes the predefined object as its value.
|
Type
|
Displays filtering parameters.
|
Options
|
Displays additional configuration options for the selected protocol.
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Description
|
Shows a user-defined description to help you identify a rule when viewing the rules table. A maximum of 1024 characters is allowed.
|
Tools button
|
Click this button to select tools that you can use with this type of policy. You can select from the following tools:
• Query—To run policy queries, which can help you evaluate your rules and identify ineffective rules that you can delete. See Generating Policy Query Reports, page 11-12
|
Find and Replace button (binoculars icon)
|
Searches for values in rules tables, such as IP addresses and policy object names, to facilitate locating and making changes to rules in tables. See Finding and Replacing Items in Rules Tables, page 11-6.
|
Up Row and Down Row buttons (arrow icons)
|
Click these buttons to move the selected rules up or down within a scope or section. For more information, see Moving Rules and the Importance of Rule Order, page 11-7.
|
Add button
|
Adds a rule to the table.
|
Edit button
|
Edits an existing rule in the table.
|
Delete button
|
Deletes a rule from the table.
|
Add and Edit PIX/FWSM/ASA Rules Dialog Boxes
Use the Add and Edit PIX/FWSM/ASA Rules dialog boxes to set values for Web Filter Rules for those platforms.
Navigation Path
To access the PIX/FWSM/ASA Rules dialog box, do one of the following:
•
(Device view) Select a device, then select Firewall >Web Filter Rules from the Device selector. Right-click inside the work area, then click Add Row or right-click a rule, then click Edit Row.
•
(Policy view) Select Firewall >Web Filter Rules from the Policy selector. Right-click inside the work area, then click Add Row or right-click a rule, then click Edit Row.
Related Topics
•
Adding Web Filter Rules (PIX/ASA), page 11-54
•
Understanding Web Filter Rules, page 11-54
•
Working with Web Filter Rules, page 11-53
Field Reference
Table I-33 Add and Edit PIX/FWSM/ASA Web Filter Rule Dialog Boxes
Element
|
Description
|
Enable Rule
|
When selected, indicates that the rule becomes active on a device after the configuration is generated and deployed.
When viewing the main rules tables:
• An enabled rule is shown without hash marks.
• A disabled rule is shown with hash marks.
Note A disabled rule is not generated and deployed to devices; however, it is retained in the rules table for debugging purposes.
|
Filtering
|
Lists options for handling filtering:
• Filter—Limits traffic to particular sites and limits traffic between two entities.
• Filter Except—Exempts specific traffic from filtering.
Note Filter except rules are recognized before filter rules.
|
Type
|
Describes what should be filtered.
• URL—HTTP filtering using an external filtering server, such as Websense or N2H2.
• HTTPS—Supported on Websense filtering servers only.
• Java—Supported on Websense and N2H2 servers.
• ActiveX—Supported on Websense and N2H2 servers.
• FTP—Supported on Websense filtering servers only.
|
Sources
Destinations
|
The source or destination of the traffic. You can enter more than one value by separating the items with commas.
You can enter any combination of the following address types to define the source or destination of the traffic. For more information, see Specifying IP Addresses During Policy Definition, page 8-68.
• Network/host object. Enter the name of the object or click Select to select it from a list. You can also create new network/host objects from the selection list.
• Host IP address, for example, 10.10.10.100.
• Network address, including subnet mask, in either the format 10.10.10.0/24 or 10.10.10.0/255.255.255.0.
• A range of IP addresses, for example, 10.10.10.100-10.10.10.200.
• An IP address pattern in the format 10.10.0.10/255.255.0.255, where the mask is a discontiguous bit mask (see Contiguous and Discontiguous Network Masks, page 8-65).
• Interface role object. Enter the name of the object or click Select to select it from a list (you must select Interface Role as the object type). When you use an interface role, the rule behaves as if you supplied the IP address of the selected interface. This is useful for interfaces that get their address through DHCP, because you do not know what IP address will be assigned to the device. For more information, see Understanding Interface Role Objects, page 8-33.
If you select an interface role as a source, the dialog box displays tabs to differentiate between hosts or networks and interface roles.
|
Services
|
The services that define the type of traffic to act on. You can enter more than one value by separating the items with commas.
You can enter any combination of service objects and service types (which are typically a protocol and port combination). If you type in a service, you are prompted as you type with valid values. You can select a value from the list and press Enter or Tab.
For complete information on how to specify services, see Understanding and Specifying Services and Service and Port List Objects, page 8-75.
Note The Services field is not applicable when Filter Except is selected.
|
Allow traffic if URL Filter Server unavailable
|
When selected, permits outbound connections to pass through the security appliance without filtering if the server is unavailable.
If you omit this option and if the N2H2 or Websense server goes offline, the security appliance stops outbound port 80 (Web) traffic until the N2H2 or Websense server is back online.
|
Block connection to HTTP Proxy Server.
|
When selected, prevents users from connecting to an HTTP proxy server.
|
Truncate CGI request by removing CGI parameters.
|
When selected, truncates CGI URLs to include only the CGI script location and the script name without any parameters.When a URL has a parameter list starting with a question mark (?), the URL sent to the filtering server is truncated by removing all characters after and including the question mark.
|
Long URL
|
Lists options for handling long URLs:
• Drop—Drops the packet if a URL exceeds the maximum permitted size. (Default). To avoid this, you can set the security appliance to truncate a long URL
• Truncate—Sends only the originating hostname or IP address to the Websense server if the URL is over the URL buffer limit.
• Deny—Denies the URL request if the URL is over the URL buffer size limit or the URL buffer is not available.
Note Filtering URLs up to 4 KB is supported for the Websense filtering server, and up to 1159 bytes for the N2H2 filtering server.
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Description
|
Shows a user-defined description to help you identify a rule when viewing the rules table. A maximum of 1024 characters is allowed.
|
Edit Web Filter Type Dialog Box
Use the Edit Web Filter Type dialog box to edit filtering and service entries.
Navigation Path
To access the Edit Web Filter Type dialog box, right-click the entry in the Type column of the Web Filter Rules table, then click Edit Web Filter Type.
Related Topics
•
Adding Web Filter Rules (PIX/ASA), page 11-54
•
Editing Rules, page 11-5
•
Understanding Web Filter Rules, page 11-54
•
Working with Web Filter Rules, page 11-53
Field Reference
Table I-34 Edit Web Filter Type Dialog Box
Element
|
Description
|
Filtering
|
Lists options for handling filtering:
• Filter—Limit traffic to particular sites, and limits traffic between two entities.
• Filter Except—Exempts specific traffic from filtering.
Note Filter Except rules are recognized before filter rules.
|
Action
|
Describes what should occur based on the conditions set.
• Permit—Allows traffic.
• Deny—Denies traffic.
|
Edit Web Filter Options Dialog Box
Use the Edit Web Filter Options dialog box to edit additional options entries based on the service selected.
Navigation Path
Right-click the entry in the Options column of the Web Filter Rules table, then click Edit Web Filter Rule Options.
Related Topics
•
Adding Web Filter Rules (PIX/ASA), page 11-54
•
Editing Rules, page 11-5
•
Understanding Web Filter Rules, page 11-54
•
Working with Web Filter Rules, page 11-53
Field Reference
Table I-35 Edit Web Filter Options Dialog Box
Element
|
Description
|
Allow traffic if URL Filter Server unavailable
|
When selected, permits outbound connections to pass through the security appliance without filtering if the server is unavailable.
Note If you omit this option and if the N2H2 or Websense server goes offline, the security appliance stops outbound port 80 (Web) traffic until the N2H2 or Websense server is back online.
|
Block connection to HTTP Proxy Server
|
When selected, prevents users from connecting to an HTTP proxy server.
|
Truncate CGI request by removing CGI parameters
|
When selected, truncates CGI URLs to include only the CGI script location and the script name without any parameters.When a URL has a parameter list starting with a question mark (?), the URL sent to the filtering server is truncated by removing all characters after and including the question mark.
|
Block outbound traffic if absolute FTP path is not provided
|
When selected, blocks traffic if an exact path to a particular directory is not specified.
|
Long URL
|
Lists options for handling long URLs:
• Drop—Drops the packet if a URL exceeds the maximum permitted size. (Default). To avoid this, you can set the security appliance to truncate a long URL
• Truncate—Sends only the originating hostname or IP address to the Websense server if the URL is over the URL buffer limit.
• Deny—Denies the URL request if the URL is over the URL buffer size limit or the URL buffer is not available.
Note Filtering URLs up to 4 KB is supported for the Websense filtering server, and up to 1159 bytes for the N2H2 filtering server.
|
Web Filter Rules Page (IOS)
Use the Web Filter Rules page for IOS devices to configure web, or URL, filtering rules. Web filtering is a type of HTTP inspection. If your access rules allow HTTP traffic on an interface, you can configure rules to apply local and server-based web filtering to prevent users from accessing undesirable web servers.
When you configure web filter rules, also configure web filter settings in the Firewall > Settings > Web Filter policy. The settings identify the web filtering server and contain other settings that control the overall functioning of the policy. For example, you can use the settings policy to allow all web traffic if the filtering server becomes unavailable. For more information, see Web Filter Settings Page.
Tip
You can also configure web filtering as a zone based firewall rule. For more information, see Zone-based Firewall Rules Page.
Navigation Path
To access the Web Filter Rules page for IOS devices, do one of the following:
•
(Device view) Select an IOS device and select Firewall > Web Filter Rules from the policy selector.
•
(Policy view) Select Firewall > Web Filter Rules (IOS) from the policy selector.
•
(Map view) Right-click an IOS device and select Edit Firewall Policies > Web Filter Rules.
Related Topics
•
Understanding Web Filter Rules, page 11-54
•
Configuring Web Filter Rules for IOS devices, page 11-56
•
Working with Web Filter Rules, page 11-53
Field Reference
Table I-36 Web Filter Rules Page (IOS)
Element
|
Description
|
Web Filter Rules tab
|
The URL filtering rules defined for the policy. Each rule shows the interface on which it is defined, whether the rule is applied to incoming or outgoing traffic, and the permitted or denied Java applet sources if Java applet scanning is enabled. You might have more than one rule for an interface if you configure both a permit and deny list for Java applet scanning.
• To add a rule, click the Add Row button and fill in the IOS Web Filter Rule and Applet Scanner Dialog Box.
• To edit a rule, select it and click the Edit Row button.
• To delete a rule, select it and click the Delete Row button.
|
Exclusive Domains tab
|
The local web filter list. This list is checked before web requests are sent to the filtering server and applies to all interfaces on which you configure web filtering.
If you know there are specific domains that you will always allow (such as your organization's own domain name), or disallow, you can list them here. By configuring a local filter list, you can improve performance because the device does not need to wait for a response from the filtering server.
• To add a domain, click the Add Row button and fill in the IOS Web Filter Exclusive Domain Name Dialog Box.
• To edit a domain, select it and click the Edit Row button.
• To delete a domain, select it and click the Delete Row button.
|
IOS Web Filter Rule and Applet Scanner Dialog Box
Use the IOS Web Filter Rule and Applet Scanner dialog box to create web filtering rules for IOS devices.
Navigation Path
To open this dialog box, select the Web Filter Rules tab on the Web Filter Rules Page (IOS), click Add Row to create a new rule, or select a row and click Edit Row to edit an existing rule.
Related Topics
•
Configuring Web Filter Rules for IOS devices, page 11-56
•
Understanding Web Filter Rules, page 11-54
•
Working with Web Filter Rules, page 11-53
•
Configuring Settings for Web Filter Servers, page 11-57
Field Reference
Table I-37 IOS Web Filter Rule and Applet Scanner Dialog Box
Element
|
Description
|
Enable Web Filtering
|
Whether to enable the web filtering rule.
|
Interface
|
The interface or interface role to which the rule is assigned. Enter the name of the interface or the interface role, or click Select to select the interface or role from a list, or to create a new role. An interface must already be defined to appear on the list.
Interface role objects are replaced with the actual interface names when the configuration is generated for each device. See Understanding Interface Role Objects, page 8-33.
|
Traffic Direction
|
The direction of the traffic to which this rule applies:
• In—Packets entering an interface.
• Out—Packets exiting an interface.
|
Java Applet Scanning
Enable Java Applet Scanner
|
If you select Enable Java Applet Scanning, the device checks for the presence of Java applets in HTTP traffic coming from web servers to internal hosts. If a Java applet is present and the web server (applet source) is in the list of permitted sources, the Java applet is left unmodified in the HTTP traffic. Otherwise, the Java applets are removed from HTTP pages.
Tip  When you enable web filtering, Java applets are inspected, which can affect performance. By enabling the Java applet scanner, you can identify a list of permitted or denied sources and avoid inspection for those applets. Even if you do not want to deny any sources, enable scanning and permit the any source.
|
Permit Traffic
Applet Sources
|
The list of permitted or denied source addresses for Java applets. To configure a list of permitted or denied sources:
• Select either Permit from Specified Sources or Deny from Specified Sources. If you want to create both a permit and deny list, create two separate web filter rules. If you do not configure a permit list, all sources are denied.
• Enter the list of permitted or denied addresses in the Applet Sources field. The list can include host IP addresses, network addresses, address ranges, or network/host objects, but cannot include domain names. Separate multiple addresses with commas. For more information on entering addresses, see Specifying IP Addresses During Policy Definition, page 8-68.
|
IOS Web Filter Exclusive Domain Name Dialog Box
Use the IOS Web Filter Exclusive Domain Name dialog box configure local web filtering rules for IOS devices. You can create a list of permitted or denied domain names or IP addresses. The device checks this list before forwarding web requests to your web filtering server.
Using local filtering saves the wait time for getting a response from the server when a user requests a web site that you know you will either always permit or always deny.
Navigation Path
To open this dialog box, select the Exclusive Domains tab on the Web Filter Rules Page (IOS), click Add Row to create a new rule, or select a row and click Edit Row to edit an existing rule.
Related Topics
•
Configuring Web Filter Rules for IOS devices, page 11-56
•
Understanding Web Filter Rules, page 11-54
•
Working with Web Filter Rules, page 11-53
Field Reference
Table I-38 IOS Web Filter Exclusive Domain Name Dialog Box
Element
|
Description
|
Traffic
|
Whether you want to permit access to the listed web sites or deny access to them.
|
Domain Name
|
The domain names or host IP addresses of web sites that you are permitting or denying. Separate multiple entries with commas.
For domain names, you can enter a full or partial name. For example, cisco.com covers all web servers on the cisco.com domain, whereas www.cisco.com specifies only the www web server.
|
Zone-based Firewall Rules Page
Zone-based firewall rules provide unidirectional application of firewall policies between groups of interfaces known as "zones." That is, interfaces are assigned to zones, and specific inspection policies are applied to traffic moving between zones in one direction or the other.
A zone defines a boundary where traffic is subjected to specific restrictions as it crosses into another region of your network. The default zone-based firewall policy between zones is deny all. Thus, if no policy is explicitly configured, all traffic between zones is blocked.
Note
Zone-based firewall policies can be configured only on Cisco IOS and ASR devices.
The Zone Based Firewall Rules page displays a list of currently configured zone-based firewall rules, and lets you add, edit and delete rules.
Navigation Path
To access the Zone Based Firewall Rules page, do one of the following:
•
(Device view) Select a device, then select Firewall > Zone Based Firewall Rules from the Device selector.
•
(Policy view) Select Firewall > Zone Based Firewall Rules from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Policies > Zone Based Firewall Rules.
Related Topics
•
Understanding the Zone-based Firewall Rules, page 11-62
•
Zone Restrictions, page 11-63
•
Adding Zone-Based Firewall Rules, page 11-67
•
Filtering Tables, page 2-16
Field Reference
Table I-39 Zone Based Firewall Rules Page
Element
|
Description
|
Note Hatching (a series of slanted lines) across an entry in the table indicates that rule is currently disabled. (See Adding and Editing Zone-based Firewall Rules for information about enabling and disabling these rules.)
|
No.
|
This number indicates the rule's position in the ordering of the list. You can use the Up Row and Down Row buttons to change the position of the selected rule.
|
Permit
|
Indicates whether the rule permits or denies traffic.
• Permit—Shown as a green check mark.
• Deny—Shown as a red circle with a slash.
|
Source
|
Identifies source networks and hosts for this rule. Networks/hosts can be provided as named objects, or as IP addresses. See Understanding Network/Host Objects, page 8-65 for more information.
|
Destination
|
Identifies destination networks and hosts for this rule. Networks and hosts can be provided as named objects, or as IP addresses. See Understanding Network/Host Objects, page 8-65 for more information.
|
Service
|
The services that define the types of traffic matched by this rule. Services are defined by objects that specify protocol and port information. See Understanding and Specifying Services and Service and Port List Objects, page 8-75 for more information.
|
From Zone
|
This rule applies only to traffic originating from this zone.
|
To Zone
|
This rule applies only to traffic destined for this zone.
|
Inspected Protocol
|
The protocol(s) on which the rule performs the chosen Action.
|
Action
|
Identifies how matched protocols are processed:
• Drop - Matched traffic is silently dropped. The default action for all traffic.
• Drop and Log - Matched traffic is logged and dropped.
• Pass - The router forwards matched traffic from the source zone to the destination zone.
• Pass and Log - Traffic is logged and forwarded.
• Inspect - State-based traffic control; Inspect can provide application inspection and control for certain protocols, based on Port to Application Mapping (PAM).
• Content Filter - HTTP content inspection based on a WebFilter parameter map, or a WebFilter policy map.
Note The Log options generate system-log messages; you must ensure that syslog logging is configured to capture these messages.
|
Options
|
The Inspect Parameter map assigned to this rule; available only with Inspect and Content Filter actions.
|
Category
|
The category assigned to the rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Description
|
The description of this rule, if provided. A maximum of 1024 characters is allowed.
|
Tools button
|
Click this button to select tools that you can use with this type of policy. You can select from the following tools:
• Query—To run policy queries, which can help you evaluate your rules and identify ineffective rules that you can delete. See Generating Policy Query Reports, page 11-12
|
Find and Replace button (binoculars icon)
|
Searches for values in rules tables, such as IP addresses and policy object names, to facilitate locating and making changes to rules in tables. See Finding and Replacing Items in Rules Tables, page 11-6.
|
Up button
|
Moves the selected rule up one row in the table.
|
Down button
|
Moves the selected rule down one row in the table.
|
Add button
|
Opens the Add Zone-based Firewall Rule dialog box, where you can create a new rule.
|
Edit button
|
Used to edit the selected rule in the table; opens the Edit Zone-based Firewall Rule dialog box.
|
Delete button
|
Deletes the selected rule from the table.
|
Adding and Editing Zone-based Firewall Rules
Use the Add and Edit Zone based Firewall Rule dialog boxes to add and edit zone-based firewall rules on Cisco IOS and ASR devices.
Navigation Path
From the Zone-based Firewall Rules Page, click the Add Row button, or select a row and click the Edit Row button.
Related Topics
•
Understanding the Zone-based Firewall Rules, page 11-62
•
Configuring Settings for Zone Based Firewall Rules, page 11-70
•
Adding Zone-Based Firewall Rules, page 11-67
Field Reference
Table I-40 Add and Edit Zone based Firewall Rule Dialog Boxes
Element
|
Description
|
Enable Rule
|
When selected, the rule is enabled on the device after the configuration is generated and deployed. Deselect this option to disable the rule without deleting it.
|
Traffic
|
Define the traffic flow to which this rule is applied.
|
Match
|
Choose whether to Permit or Deny matched traffic.
|
Sources
Destinations
|
Provide the source networks/hosts and destination networks/hosts for matching traffic. Each field allows multiple values separated by commas.
You can enter any combination of the following address types to define the source or destination of the traffic. For more information, see Specifying IP Addresses During Policy Definition, page 8-68.
• Network/host object. Enter the name of the object or click Select to select it from a list. You can also create new network/host objects in the selection dialog box.
• Host IP address; for example, 10.10.10.100.
• Network address, including subnet mask, in either 10.10.10.0/24 or 10.10.10.0/255.255.255.0 formats.
• A range of IP addresses; for example, 10.10.10.100-10.10.10.200.
• An IP address pattern in the format 10.10.0.10/255.255.0.255, where the mask is a discontiguous bit mask (see Contiguous and Discontiguous Network Masks, page 8-65).
|
Services
|
Specify the services that define the type of traffic to matched by this rule. You can enter any combination of service objects and service types (which are typically a protocol and port combination), separated by commas.
If you type in a service, you are prompted as you type with valid values. You also can click Select to select services from a list.
For complete information on how to specify services, see Understanding and Specifying Services and Service and Port List Objects, page 8-75.
|
From Zone
To Zone
|
Basic zone-based firewall rules are unidirectional; that is, they define a traffic flow that moves in only one direction between two zones.
Enter or Select the zone from which traffic flows can originate for this rule, and enter or Select the zone to which traffic can flow.
|
Advanced button
|
Opens the Advanced Options dialog box where you can select time-range options. See Zone-based Firewall Rule: Advanced Options Dialog Box.
|
Action
|
The action applied to traffic that matches this rule. Choose the desired Action:
|
Action: Drop, Drop and Log, Pass, Pass and Log
|
• Drop - Silently drops all packets for the specified Services. The default action for all traffic.
• Drop and Log - Matched traffic is logged and dropped.
• Pass - The router forwards matched packets from the source zone to the destination zone. Return traffic is not recognized, so you have to specify additional rules for return traffic. This option is useful only for protocols such as IPsec-encrypted traffic.
• Pass and Log - Traffic is logged and forwarded.
For any of these Actions, you can select one or more protocols to be matched by clicking the Select button next to the Protocol table to open the Protocol Selector Dialog Box. However, this is not necessary; you can leave the Protocol table empty and pass or drop traffic based on the Sources, Destinations, and Services parameters.
The Protocol Selector dialog box also provides access to the Configure Protocol Dialog Box, where you can edit the Port Application Mapping (PAM) parameters for the selected protocol.
Note The Log options generate system-log messages; you must ensure that syslog logging is configured to capture these messages.
|
Action: Inspect
|
Inspect provides state-based traffic control—the device maintains connection or session information for TCP and UDP traffic, meaning return traffic in reply to connection requests is permitted.
Choose this option to apply packet inspection based on your selected Layer 4 (TCP, UDP) and Layer 7 (HTTP, IMAP, instant messaging, and peer-to-peer) protocols. You also can edit PAM settings for the selected protocols, and you can set up deep packet inspection (DPI) and provide additional protocol-related information for the Layer 7 protocols. See Configuring Maps for Inspection in Zone-Based Firewall Rules Policies, page 8-57 for more information.
1. You can select one or more protocols for inspection by clicking the Select button next to the Protocol table to open the Protocol Selector Dialog Box.
2. The Protocol Selector dialog box also provides access to the Configure Protocol Dialog Box, where you can create custom protocols, and edit the PAM and DPI parameters for the selected protocol.
3. Inspect Parameters - You can apply a customized set of connection, timeout, and other settings by entering the name of an Inspect Parameter map in this field, or you can click Select to select one from a list. You also can create new Inspect Parameter maps from the selection-list dialog box; see Add or Edit Inspect Parameter Map Dialog Boxes, page F-74 for more information.
If you do not specify an Inspect Parameters map, the default settings are used.
|
Action: Content Filter
|
Content Filter provides URL filtering based on a supplied parameter or policy map. The router intercepts HTTP requests, performs protocol-related inspection, and optionally contacts a third-party server to determine whether the requests should be allowed or blocked. You can provide a WebFilter parameter map, which defines filtering based on local URL lists, as well as information from an external SmartFilter (previously N2H2) or Websense server. Alternately, you can provide a WebFilter policy map that accesses Local, N2H2, Websense, or Trend Micro filtering data.
1. When Content Filter is the chosen Action, HTTP is the specified Protocol. You can click Configure to open the Configure Protocol Dialog Box, where you can edit the HTTP PAM settings, and apply an HTTP DPI map.
2. Select WebFilter Parameter Map, or WebFilter Policy Map, and supply the name of an appropriate map. You can click the appropriate Select button to select the map from a list; you also can create new maps from the selection-list dialog box. See Configuring Maps for Content Filtering in Zone-Based Firewall Rules Policies, page 8-59 for information about configuring these maps.
3. Inspect Parameters - You can apply a customized set of connection, timeout, and other settings by entering the name of an Inspect Parameter map in this field, or you can click Select to select one from a list. You also can create new Inspect Parameter maps from the selection-list dialog box; see Add or Edit Inspect Parameter Map Dialog Boxes, page F-74 for more information.
If you do not specify an Inspect Parameters map, the default settings are used.
|
Description
|
(Optional) You can enter a description of up to 1024 characters to help you identify the rule when viewing the rules table.
|
Category
|
(Optional) You can assign a category to the rule, to help you organize and identify rules and objects. See Using Category Objects, page 8-6.
|
Zone-based Firewall Rule: Advanced Options Dialog Box
Use the Zone-Based Firewall Rule Advanced Options dialog box to apply specific time-range information to a zone-based firewall rule.
Navigation Path
In the Traffic section of the Add or Edit Zone based Firewall Rule dialog box, click the Advanced button.
Related Topics
•
Adding and Editing Zone-based Firewall Rules
•
Understanding the Zone-based Firewall Rules, page 11-62
Field Reference
Table I-41 Advanced Options Dialog Box
Element
|
Description
|
Time Range
|
This feature lets you define time periods during which this zone-based firewall rule is active. If you do not specify a time range, the rule is immediately and always active.
Enter the name of a time-range object, or click Select to choose one from a list in the Time Ranges Selector dialog box. You can create and edit time-range objects from this dialog box. See Creating Time Range Objects, page 8-92 for more information.
|
Options
|
This feature lets you apply a packet-fragment or an established-connection restriction to this zone-based firewall rule. Choose one of the following options:
• None - No packet-fragment or established-connection restrictions are applied.
• Fragment - If chosen, non-initial packet fragments are blocked.
• Established - Permits return traffic only for connections already established.
|
Protocol Selector Dialog Box
Use the Protocol Selector dialog box to specify one or more communication protocols as part of the definition of traffic for a zone-based firewall rule.
The Protocol Selector dialog box also provides access to the Configure Protocol dialog box, which you can use to create custom protocols and edit Port Application Mapping (PAM) parameters for existing protocols. The Configure Protocol dialog box is also where you select Deep Inspection policy maps, and Protocol Info parameter maps, for certain protocols. See Configure Protocol Dialog Box for more information.
Navigation Path
The Protocol Selector dialog box can be accessed from the Add and Edit Zone based Firewall Rule dialog boxes (described in Adding and Editing Zone-based Firewall Rules). In either dialog box, choose any Action except Content Filter and then click the Select button next to the Protocol table.
You can also open the Protocol Selector dialog box by right-clicking the Inspected Protocol column for any entry in the Zone Based Firewall Rules table, and then choosing Edit Protocols.
Related Topics
•
Understanding the Zone-based Firewall Rules, page 11-62
•
Adding and Editing Zone-based Firewall Rules
•
Selecting Objects for Policies, page 8-2
•
Configure Protocol Dialog Box
Table I-42 Protocol Selector Dialog Box
Element
|
Description
|
Available Protocols
|
A list of protocols that can be selected for a zone-based firewall rule.
Tip  You can create a custom protocol by clicking the Create button below the Selected Protocols column.
|
Selected Protocols
|
The list of protocols you have selected for this zone-based firewall rule.
Tip  You can edit Port Application Mapping (PAM) settings for the protocol highlighted in the Selected Protocols column: click the Edit button below the Selected Protocols column to open the Configure Protocol Dialog Box.
|
>> button
|
Moves the highlighted protocols from the Available Protocols column to the Selected Protocols column. You can select multiple protocols using the standard Shift-click and Ctrl+click functions.
|
<< button
|
Moves the highlighted protocols from the Selected Protocols column back to the Available Protocols column. You can select multiple protocols using the standard Shift-click and Ctrl+click functions.
|
Configure Protocol Dialog Box
Packet inspection can be configured in zone-based firewall rules by the selection of specific protocol objects, which define Port Application Mapping (PAM) parameters (Layer 4 protocols and ports, and optionally specific networks and hosts). A Layer 7 (HTTP, IMAP, instant messaging, and peer-to-peer) protocol can also include a deep-packet inspection policy specific to that protocol. Refer to Adding and Editing Zone-based Firewall Rules for information about selecting protocols during zone-based firewall rule definition.
The Configure Protocol dialog box is used to edit existing protocol definitions, and to create custom definitions, for use with zone-based firewall rules. For example, if a protocol does not use its default ports for some or all networks, you can configure different port mappings.
Navigation Path
The Configure Protocol dialog box is accessed from the Protocol Selector Dialog Box, as follows:
•
Click the Create (+) button below the Selected Protocols list to create a new protocol.
•
Select a protocol in the Selected Protocols list, and click the Edit (pencil) button to edit that protocol.
Related Topics
•
Understanding the Zone-based Firewall Rules, page 11-62
•
Adding Zone-Based Firewall Rules, page 11-67
•
Protocol Selector Dialog Box
Table I-43 Configure Protocol Dialog Box
Element
|
Description
|
Protocol Name
|
The name of the selected protocol. If you are creating a custom protocol, you can enter a name of up to 19 characters. Custom protocol names must begin with user-.
|
Enable Signature
|
This option is available only when editing the peer-to-peer (eDonkey, FastTrack, Gnutella, Kazaa2) protocols.
Select this option to enable signature-based classification of peer-to-peer (P2P) packets.
|
Deep Inspection
|
This option is available only when editing the H.323, HTTP, IM (AOL, ICQ, MSN Messenger, Windows Messenger, and Yahoo Messenger), IMAP, P2P (eDonkey, FastTrack, Gnutella, Kazaa2), POP3, SIP, SMTP, Sun RPC protocols, and Inspect is the chosen Action for the zone-based firewall rule.
Enter or Select the name of the Inspect policy map to be used with the selected protocol. See Configuring Maps for Inspection in Zone-Based Firewall Rules Policies, page 8-57 for more information about these policy maps.
|
Protocol Info
|
This option is available only when editing the Instant Messaging (AOL, ICQ, MSN Messenger, Windows Messenger, and Yahoo Messenger) and the Stun-ice protocols.
Enter or Select the name of the Protocol Info parameter map to be used with the selected protocol. These parameter maps define the DNS servers that interact with these applications, which helps the Instant Messaging (IM) application engine recognize the IM traffic and enforce the configured policy for that IM application.
See Add or Edit Protocol Info Parameter Map Dialog Boxes, page F-76 for more information about these parameter maps.
|
Port Application Mapping
|
These options let you customize the Port Application Mapping (PAM) parameters for the selected protocol.
|
Protocol
|
Select the transport protocol(s) for this mapping:
• TCP/UDP
• TCP
• UDP
|
Ports
|
Enter any combination of a single port number, multiple port numbers, or a range of ports (for example, 60000-60005). Separate multiple entries with commas. Do not specify a range that overlaps already mapped ports.
|
Networks
|
If this protocol/port mapping is only for specific networks or hosts, enter the names or IP addresses of the networks or hosts, or the names of the network/host objects. You can click Select to open the Networks/Hosts Selector. Separate multiple entries with commas.
|
Common Firewall Services Dialog Boxes
There are several dialog boxes that are used by many of the firewall services rules policies. These dialog boxes are used when editing or viewing the contents of rules cells, as opposed to editing the entire rule. For detailed information about editing or viewing cell contents, see Editing Rules, page 11-5.
Add or Edit Sources or Destinations Dialog Boxes
Use the Add or Edit Sources or Destinations dialog boxes to edit the source or destination entry in a firewall rules table that includes sources or destinations. For detailed information on editing firewall rules cells, see Editing Rules, page 11-5.
You can enter any combination of the following address types to define the source or destination of the traffic. You can enter more than one value by separating the items with commas. For more information, see Specifying IP Addresses During Policy Definition, page 8-68.
•
Network/host object. Enter the name of the object or click Select to select it from a list. You can also create new network/host objects from the selection list.
•
Host IP address, for example, 10.10.10.100.
•
Network address, including subnet mask, in either the format 10.10.10.0/24 or 10.10.10.0/255.255.255.0.
•
A range of IP addresses, for example, 10.10.10.100-10.10.10.200.
•
An IP address pattern in the format 10.10.0.10/255.255.0.255, where the mask is a discontiguous bit mask (see Contiguous and Discontiguous Network Masks, page 8-65).
•
Interface roles object. Enter the name of the object or click Select to select it from a list (you must select Interface Role as the object type). When you use an interface role, the rule behaves as if you supplied the IP address of the selected interface. This is useful for interfaces that get their address through DHCP, because you do not know what IP address will be assigned to the device. For more information, see Understanding Interface Role Objects, page 8-33.
If you select an interface role as a source, the dialog box displays tabs to differentiate between hosts or networks and interface roles.
Navigation Path
Do any of the following in a rules policy that includes sources or destinations:
•
Right-click a Sources or Destinations cell in a rules table and select Edit Sources or Edit Destinations or a similar command. The data replaces the content of the selected cells.
•
Select an entry in a Sources or Destinations cell and select Edit <Entry>. The data replaces the selected entry.
•
Select multiple rules, right-click a Sources or Destination cell, and select Add Sources or Add Destinations. The data is appended to the data already in the cell.
Add or Edit Services Dialog Boxes
Use the Edit Services dialog box to edit the services that define the type of traffic to act on. You can enter more than one value by separating the items with commas.
You can enter any combination of service objects and service types (which are typically a protocol and port combination). If you type in a service, you are prompted as you type with valid values. You can select a value from the list and press Enter or Tab. You can also click Select to select the service from a list, or to create a new service.
For complete information on how to specify services, see Understanding and Specifying Services and Service and Port List Objects, page 8-75.
For detailed information on editing firewall rules cells, see Editing Rules, page 11-5.
Navigation Path
Do any of the following in a rules policy that includes services:
•
Right-click a Services cell in a rules table and select Edit Services. The data replaces the content of the selected cells.
•
Select an entry in a Services cell and select Edit <Entry>. The data replaces the selected entry.
•
Select multiple rules, right-click a Services cell, and select Add Services. The data is appended to the data already in the cell.
Tip
For inspection rules, services appear in the Traffic Match column and only for rules where the traffic matches source, destination, and port.
Add or Edit Interfaces or Zones Dialog Boxes
Use the Add or Edit Interfaces (or Zones) dialog box to edit the interfaces or zones for which the rule is defined. For detailed information on editing firewall rules cells, see Editing Rules, page 11-5.
•
When editing interfaces, you can enter any combination of specific interface names or interface roles. You can enter more than one value by separating the items with commas. Enter the names or click Select to select the interfaces and roles from a list, or to create new roles. An interface must already be defined to appear on the list.
When you deploy the policy to the device, interface roles are replaced by actual interface names, and only to interfaces that are actually configured on the device. To see which interfaces will actually be selected by a rule, right-click the Interfaces cell and select Show Interfaces.
•
When editing zones, you can select only one interface role, and you cannot select individual interfaces. The interface roles are used to create zones for zone based firewall rules. To see the interfaces that will belong to the zone, right-click the Zones cell and select Show Zone Contents.
For more information about interface roles and selecting interfaces, see the following topics:
•
Understanding Interface Role Objects, page 8-33
•
Specifying Interfaces During Policy Definition, page 8-35
Navigation Path
Do any of the following in a rules policy that includes interfaces or zones:
•
Right-click an Interfaces or Zones cell in a rules table and select Edit Interfaces, Edit Zones, or similar command. The data replaces the content of the selected cells.
•
Select an entry in an Interfaces cell and select Edit <Entry>. The data replaces the selected entry. You cannot edit an entry in a zone.
•
Select multiple rules, right-click an Interfaces cell, and select Add Interfaces. The data is appended to the data already in the cell. You cannot add entries to a zone.
Edit Category Dialog Box
Use the Edit Category dialog box to change the category assigned to a rule. Categories help you organize and identify rules and objects. See Using Category Objects, page 8-6. For detailed information on editing firewall rules cells, see Editing Rules, page 11-5.
Navigation Path
Right-click a Category cell in a rules policy that includes categories and select Edit Category.
Edit Description Dialog Box
Use the Edit Description dialog box to edit the description of the rule. The description helps you identify the purpose of a rule and can be up to 1024 characters. For detailed information on editing firewall rules cells, see Editing Rules, page 11-5.
Navigation Path
Right-click a Description cell in a rules policy that includes descriptions and select Edit Description.
Show Contents Dialog Boxes
Use the Show Contents dialog boxes to display the actual, translated data defined in a source, destination, services, interfaces, zones, or other cell in a rules table that includes addresses, interfaces, services, or policy objects that define those things. The title of the dialog box indicates which cell or entry you are examining. Use this information to determine to which addresses, services, or interfaces the rule will actually apply when deployed to the device. For detailed information about editing or viewing cell contents, see Editing Rules, page 11-5.
What you see in the dialog box depends on the view you are in:
•
Device View, Map View—You are shown the actual IP addresses, services, or interfaces to which the rule will apply for the specific device. For example, if the rule uses network/host objects, you will see the specific IP addresses defined by the objects. If the rule uses interface objects, you will see the specific interfaces defined on the device that the object identifies, if any.
–
The IP addresses for network/host objects are sorted in ascending order on the IP address, and then descending order on the subnet mask.
–
Service objects are sorted on protocol, source port, and destination port.
–
Interface objects are listed in alphabetical order. If the interface is selected because it matches a pattern in an interface object, the pattern is listed first, and the matching interface is shown in parentheses. For example, "* (Ethernet1)" indicates that the Ethernet1 interface on the device is selected because it matches the * pattern (which matches all interfaces).
•
Policy View—You are shown the patterns defined in the policy objects and entries defined for the policy. Entries are sorted alphabetically, with numbers and special characters coming first.
Navigation Path
Do any of the following in a rules policy that includes sources, destinations, services, interfaces, zones, or other fields that specify networks, interfaces, or services. You can also show contents when using tools that work with rules, such as importing rules.
•
Right-click one of those cells and select Show <Attribute Type> Contents, where the attribute type is the name of the cell. The data includes all entries defined in the cell.
•
Right-click an entry in one of those cells and select Show <Entry> Contents, where the name of the selected entry is included in the command name. The data displayed is only for the selected entry.
Tip
For inspection rules, services appear in the Traffic Match column and only for rules where the traffic matches source, destination, and port.
Firewall Settings
The firewall settings policy relate directly to the similarly-named rules policy, and provide additional options for configuring the behavior of the rules policies.
This section contains the following topics:
•
Access Control Settings Page
•
Inspection Settings Page
•
AAA Firewall Page, Advanced Setting Tab
•
AAA Firewall Page, MAC-Exempt List Tab
•
AuthProxy Page
•
Web Filter Settings Page
•
Zone Based Firewall Page
Access Control Settings Page
Use the Access Control Settings page to configure settings to use in conjunction with your access rules policy. You can control some performance and logging features, and configure ACL names for individual interfaces.
Tip
Many of these settings apply only to specific device types or software versions. If you configure an option and apply the policy to unsupported device types, the option is ignored for those unsupported devices.
Navigation Path
To access the Access Control Page, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > Access Control from the Device selector.
•
(Policy view) Select Firewall > Settings > Access Control from the Policy selector. Create a new policy or select an existing policy.
•
(Map view) Right-click a device and select Edit Firewall Settings > Access Control.
Related Topics
•
Configuring Settings for Access Control, page 11-23
•
Understanding Access Rules, page 11-17
•
Understanding Device Specific Access Rule Behavior, page 11-19
•
Understanding Access Rule Address Requirements and How Rules Are Deployed, page 11-19
•
Understanding Access Rules, page 11-17
•
Understanding Interface Role Objects, page 8-33
Field Reference
Table I-44 Access Control Settings Page
Element
|
Description
|
Maximum number of concurrent flows (PIX, ASA, FWSM)
|
The maximum number of concurrent deny flows that the device is allowed to create. Syslog message 106101 is generated when the device reaches the number. The range you should use depends on the amount of flash memory available in the device:
• More than 64 MB—Values are 1-4096. The default is 4096.
• More than 16 MB—Values are 1-1024. The default is 1024.
• Less than or equal to 16 MB—Values are 1-256. The default is 256.
|
Syslog interval (PIX, ASA, FWSM)
|
The interval of time for generating syslog message 106101, which alerts you that the security appliance has reached a deny flow maximum. When the deny flow maximum is reached, another 106101 message is generated if the specified number of seconds has passed since the last 106101 message. Values are 1 to 3600 milliseconds. The default is 300.
|
Enable Access List Compilation (Global)
|
Whether to compile access lists, which speeds up the processing of large rules tables. Compilation optimizes your policy rules and performance for all ACLs, but is supported on a limited number of older platforms:
• Routers (global configuration only): 7120, 7140, 7200, 7304, and 7500.
• PIX 6.3 firewalls, in global mode or per interface.
ACL compilation speeds up the processing of large rules tables and optimizes your policy rules and performance. An ACL is compiled only if the number of access list elements is greater than or equal to 19. The maximum recommended number of entries is 16,000.
To compile access lists, the device must have a minimum of 2.1 MB of memory for the device. Access list compilation is also known as Turbo ACL.
|
Interfaces table
|
The table lists the interfaces for which you want to configure special processing. The interface name can be a specific interface or an interface role (which can apply settings to more than one interface at a time).
The main use of this table is to configure names for ACLs if you do not want Security Manager to configure system-generated names. The name applies to the ACL generated for an interface in a specific direction.
You can also configure interface-level settings for object group search, per user downloadable ACLs, and ACL compilation.
• To add an interface setting, click the Add button and fill in the Firewall ACL Setting Dialog Box.
• To edit an interface setting, select it and click the Edit button.
• To delete an interface setting, select it and click the Delete button.
|
Firewall ACL Setting Dialog Box
Use the Firewall ACL Setting dialog box to configure settings for specific interfaces or interface roles for use with access rules policies.
Navigation Path
Go to the Access Control Settings Page and click the Add Row button below the interface table, or select a row in the table and click the Edit Row button.
Related Topics
•
Configuring Settings for Access Control, page 11-23
•
Understanding Access Rules, page 11-17
•
Understanding Device Specific Access Rule Behavior, page 11-19
•
Understanding Access Rule Address Requirements and How Rules Are Deployed, page 11-19
•
Understanding Interface Role Objects, page 8-33
Field Reference
Table I-45 Firewall ACL Setting Dialog Box
Element
|
Description
|
Interface
|
A name of the interface or interface role for which you are configuring settings. Enter the name or click Select to select the interface or interface role. If the object that you want is not listed, click the Create button to create it.
|
Traffic Direction
|
The direction of the traffic through the interface, in or out. The settings you configure apply only to this direction, if direction matters.
|
User Defined ACL Name
|
Whether you want to supply the name for the ACL. If you select this option, enter the name you want to use, which is applied to the ACL generated for the interface and direction combination. The name must be unique on the device.
If you do not provide a name, Security Manager generates a name for you.
|
Enable Per User Downloadable ACLs (PIX, ASA, FWSM)
|
Whether to enable the download of per-user ACLs to override the ACLs on the interface. Typically, user ACLs are configured in a AAA server; they are not configured in Security Manager. If there are no per-user ACLs, the access rules configured for the interface are applied to the traffic.
|
Enable Object Group Search (PIX 6.x)
|
Whether to enable object group search, which reduces the memory requirement on the device to hold large ACLs. However, object group search impacts performance by making ACL processing slower for each packet.
Object group search is recommended when you have large object groups.
|
Enable Access List Compilation (PIX 6.x)
|
Whether to compile access lists on this interface for PIX 6.x devices. This setting overrides the equivalent global setting that you configure on the Access Control Settings page.
ACL compilation speeds up the processing of large rules tables and optimizes your policy rules and performance for the interface. An ACL is compiled only if the number of access list elements is greater than or equal to 19. The maximum recommended number of entries is 16,000.
To compile access lists, the device must have a minimum of 2.1 MB of memory for the device.
|
Inspection Settings Page
Use the Inspection settings page to configure options that work with inspection rules on IOS devices. Many of these settings are used for helping to prevent or mitigate Denial of Service (DoS) attacks. The default settings for most of these options are appropriate for most networks, so configure this policy only if you need to adjust one or more settings.
Navigation Path
To open the Inspection settings page, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > Inspection from the Device selector.
•
(Policy view) Select Firewall > Settings > Inspection from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Settings > Inspection.
Related Topics
•
Understanding Inspection Rules, page 11-33
•
Working with Inspection Rules, page 11-32
Field Reference
Table I-46 Inspection Page
Element
|
Description
|
Global Timeout Values
|
TCP Establish Timeout (seconds)
|
How long to wait for a TCP session to reach the established state before dropping the session, in seconds, from 1 to 2147483. The default is 30.
|
FIN Wait Time (seconds)
|
How long to maintain TCP session state information after the firewall detects a FIN-exchange, in seconds, from 1 to 2147483. The FIN-exchange occurs when the TCP session is ready to close. The default is 5.
|
TCP Idle Time (seconds)
|
How long to maintain a TCP session while there is no activity in the session, in seconds, from 1 to 2147483. The default is 3600 (one hour).
|
UDP Idle Time (seconds)
|
How long to maintain a UDP session while there is no activity in the session, in seconds, from 1 to 2147483. The default is 30.
When the software detects a valid UDP packet, the software establishes state information for a new UDP session. Because UDP is a connectionless service, there are no actual sessions, so the software approximates sessions by examining the information in the packet and determining if the packet is similar to other UDP packets (for example, it has similar source or destination addresses) and if the packet was detected soon after another similar UDP packet.
If the software detects no UDP packets for the UDP session for the period of time defined by the UDP idle timeout, the software will not continue to manage state information for the session.
|
DNS Timeout (seconds)
|
The length of time for which a DNS lookup session is managed while there is no activity, in seconds, from 1 to 2147483. The default is 5.
|
SYN Flooding DoS Attack Thresholds
|
Maximum 1 Minute Connection Rate - low
Maximum 1 Minute Connection Rate - high
|
The number of new unestablished sessions that causes the system to start and stop deleting half-open sessions. Ensure that you enter a lower number in the Low field than you enter in the High field. Possible values are from 1 to 2147483647 per minute. The default is 400 for low and 500 for high.
|
Maximum Incomplete Sessions Stop Threshold
Maximum Incomplete Sessions Start Threshold
|
The number of existing half-open sessions that will cause the software to start and stop deleting half-open sessions. Ensure that you enter a lower number in the stop field than you enter in the start field. Possible values are from 1 to 2147483647. The default is 400 for low and 500 for high.
|
Thresholds per Host
|
Max Sessions Per Host
|
The number of half-open TCP sessions with the same host destination address that can exist at a time before the software starts deleting half-open sessions to the host. Possible values are 1 to 4294967295. The default is 50.
A large number of half-open sessions can indicate there is a Denial of Service attack against the host.
|
Max Sessions Blocking Interval (min)
|
If the maximum sessions per host threshold is reached, the blocking time to apply to help mitigate the potential TCP host-specific denial-of-service (DoS) attack. Possible values are 0 to 35791 minutes. The default is 0.
• If the blocking timeout value is 0, the software deletes the oldest existing half-open session for the host for every new connection request to the host above the maximum session limit. This ensures that the number of half-open sessions to a given host will never exceed the threshold.
• If the blocking timeout value is greater than 0, the software deletes all existing half-open sessions for the host, then blocks all new connection requests to the host. The software will continue to block all new connection requests until the block-time expires.
|
Other
|
Session Hash Table Size (buckets)
|
The size of the hash table in terms of buckets. Possible values for the hash table are 1024, 2048, 4096, and 8192. The default is 1024.
You should increase the hash table size when the total number of sessions running through the device is approximately twice the current hash size; decrease the hash table size when the total number of sessions is reduced to approximately half the current hash size. Essentially, try to maintain a 1:1 ratio between the number of sessions and the size of the hash table.
|
Enable Alert Messages
|
Whether to generate stateful packet inspection alert messages on the console.
|
Enable Audit Trail Messages
|
Whether audit trail messages are logged to the syslog server or router.
|
Permit DHCP Passthrough (Transparent Firewall)
|
Whether to permit a transparent firewall to forward DHCP packets across the bridge without inspection.
Permitting DHCP passthrough overrides an ACL for DHCP packets, so DHCP packets are forwarded even if the ACL is configured to deny all IP packets. Thus, clients on one side of the bridge can get an IP address from a DHCP server on the opposite side of the bridge.
|
Block Non-SYN Packets
|
Whether to drop TCP packets that do not belong to an established session. These are TCP packets that do not initiate sessions, that is, the SYN bit is not set in them.
|
Log Dropped Packets
|
Whether to create log messages for dropped packets to specify the reason for dropping them.
|
AAA Firewall Page, Advanced Setting Tab
Use the Settings for AAA Firewalls to define HTTPS, proxy, and MAC settings for PIX 6.3, ASA/PIX 7.x and FWSM 3.2 devices.
Navigation Path
To access the AAA Firewall settings page, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > AAA Firewall from the Device selector, then select the Advanced Setting tab.
•
(Policy view) Select Firewall > Settings > AAA Firewall from the Policy selector. Create a new policy or select and existing one, then select the Advanced Setting tab.
•
(Map view) Right-click a device and select Edit Firewall Settings > AAA Firewall, then select the Advanced Setting tab.
Related Topics
•
Configuring Settings for AAA Firewall (PIX/ASA/FWSM), page 11-43
•
Working with AAA Rules, page 11-40
Field Reference
Table I-47 Advanced Setting Tab, AAA Firewall Settings Page
Element
|
Description
|
Use Secure HTTP Authentication
|
When selected, requires additional user authentication during the session establishment.
|
Enable Proxy Limit
|
When enabled, allows proxies based on proxy limit settings.
|
Maximum Concurrent Proxy Limit per User
|
Specifies the number of concurrent proxy connections allowed per user. Values are 1 to 128. Default is 16.
|
Interactive Authentication (ASA/PIX 7.2.2+
|
Table used to configure listening ports to authenticate network users. When you enable a listening port, the security appliance serves an authentication page for direct connections and/or for through traffic.
|
Disable FTP Authentication Challenge (FWSM 3.x)
|
When selected, enables you to disable the authentication challenge for FTP traffic.
You can configure whether the FWSM challenges you for a username and password. By default, the FWSM prompts you when a AAA rule enforces authentication for traffic in a new session and the protocol is FTP.
|
Disable HTTP Authentication Challenge (FWSM 3.x)
|
When selected, enables you to disable the authentication challenge for HTTP traffic.
You can configure whether the FWSM challenges you for a username and password. By default, the FWSM prompts you when a AAA rule enforces authentication for traffic in a new session and the protocol is HTTP.
|
Disable HTTPS Authentication Challenge (FWSM 3.x)
|
When selected, enables you to disable the authentication challenge for HTTPS traffic.
You can configure whether the FWSM challenges you for a username and password. By default, the FWSM prompts you when a AAA rule enforces authentication for traffic in a new session and the protocol is HTTPS.
|
Disable TELNET Authentication Challenge (FWSM 3.x)
|
When selected, enables you to disable the authentication challenge for TELNET traffic.
You can configure whether the FWSM challenges you for a username and password. By default, the FWSM prompts you when a AAA rule enforces authentication for traffic in a new session and the protocol is TELNET.
|
Clear Connections When Uauth Timer Expires (FWSM 3.2)
|
Table used to define when the connection from a certain interface and source will be cleared when the uauth timer expires.
|
Interactive Authentication Configuration Dialog Box
Use the Interactive Authentication Configuration dialog box to configure listening ports to authenticate network users. When you enable a listening port, the security appliance serves an authentication page for direct connections and/or for through traffic.
Navigation Path
Go to the AAA Firewall Page, Advanced Setting Tab and click the Add Row button beneath the Interactive Authentication table, or select an item in the table and click the Edit Row button.
Related Topics
•
Working with AAA Rules, page 11-40
Field Reference
Table I-48 Interactive Authentication Configuration Dialog Box
Element
|
Description
|
Protocol
|
Specifies the protocol that you want to listen for. Options are HTTP or HTTPS.
|
Interface
|
Specifies the interface on which you enable listeners.
Click Select, which opens the Interface Selector dialog box from which to make your selection. You can also create an interface role by clicking the Create button in the Interface Selector dialog box.
Note Interface roles are objects that are used to help you configure firewall rules. The objects are replaced with the actual interface names when the configuration is generated for each device. The access-group command is generated for the interface role selected.
|
Port
|
Specifies the port number that the security appliance listens on; the defaults are 80 (HTTP) and 443 (HTTPS).
|
Redirect network users for authentication request
|
When selected, redirects through traffic to an authentication web page served by the security appliance. Without the redirect keyword, only traffic directed to the security appliance interface can access the authentication web pages.
|
Clear Connection Configuration Dialog Box
Use the Clear Connection Configuration dialog box to define when the connection from the certain interface and source will be cleared when the uauth timer expires.
Navigation Path
Go to the AAA Firewall Page, Advanced Setting Tab and click the Add Row button beneath the Clear Connections When Uauth Timer Expires table, or select an item in the table and click the Edit Row button.
Related Topics
•
Working with AAA Rules, page 11-40
Field Reference
Table I-49 Clear Connection Configuration Dialog Box
Element
|
Description
|
Interface
|
Identifies the logical name of the interface (interface role) or physical interface to which a rule is assigned. See Understanding Interface Role Objects, page 8-33
For example:
• All DMZs
• All FastEthernets
• All Interfaces
• FastEthernet0
Enter the information in the field provided or click Select, which opens the Interface Selector dialog box from which to make your selection. You can also create an interface role by clicking the Create button in the Interface Selector dialog box.
Note Interface roles are objects that are used to help you configure firewall rules. The objects are replaced with the actual interface names when the configuration is generated for each device.
|
Source IP Address/Netmask
|
Identifies the network object names or addresses of hosts and networks. Multiple entries are separated by commas. Accepted formats are:
• a.b.c.d where a,b,c,d = 0-255 (host)
• a.b.c.d/e where a,b,c,d = 0-255 and e = 1-32 (subnet)
• a.b.c.d-e.f.g.h where a,b,c,d,e,f,g,h = 0-255 (range)*
• a.b.c.d/e where e = subnet in x.x.x.x format**
• Freeform text that is the name of a network object
*IP address ranges can span more than one subnet.
**For information on how network masks are handled, see Contiguous and Discontiguous Network Masks, page 8-65.
Enter the addresses or names in the field provided, or click Select, which opens the Object Selector dialog box from which to make your selections. You can also create an object by clicking the Create button in the Object Selector dialog box.
Note If you manually enter 0.0.0.0/0 for the source, it automatically matches the "any" predefined object.
|
AAA Firewall Page, MAC-Exempt List Tab
Use the MAC Exempt List tab of the AAA Firewall settings policy to identify hosts that should be exempt from authentication and authorization for ASA, PIX, and FWSM 3.x devices. For example, if the security appliance authenticates TCP traffic originating on a particular network but you want to allow unauthenticated TCP connections from a specific server, create a rule permitting traffic from the MAC address of the server.
You can use masks to create rules for groups of MAC addresses. For example, if you want to exempt all Cisco IP phones whose MAC addresses start with 0003.e3, create a permit rule for 0003.e300.0000 with the mask ffff.ff00.0000. (An f in a mask exactly matches the corresponding number in the address, whereas a 0 matches anything.)
Deny rules are necessary only if you are permitting a group of MAC addresses but there are some addresses within the permitted group that you want to require to use authentication and authorization. Deny rules do not prohibit traffic; they simply require the host to go through normal authentication and authorization. For example, if you want to allow all hosts with MAC addresses that start with 00a0.c95d, but you want to force 00a0.c95d.0282 to use authentication and authorization, enter these rules in order:
1.
Deny 00a0.c95d.0282 ffff.ffff.ffff
2.
Permit 00a0.c95d.0000 ffff.ffff.0000
When you deploy the policy to the device, these entries are configured using the mac-list and aaa mac-exempt commands.
Tip
The MAC exempt list is processed on a first match basis. Thus, the order of entries matters. If you want to permit a group of MAC addresses, but deny a subset of them, the deny rule must come before the permit rule. However, Security Manager does not allow you to order MAC exempt rules: they are implemented in the order shown. If you sort the table, your policy changes. If your entries do not depend on each other, this does not matter. Otherwise, ensure that you enter rows in the proper order.
Navigation Path
To access the MAC Exempt List tab, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > AAA Firewall. Select the MAC-Exempt List tab.
•
(Policy view) Select Firewall > Settings > AAA Firewall from the Policy selector. Select the MAC-Exempt List tab.
•
(Map view) Right-click a device and select Edit Firewall Settings > AAA Firewall, then select the MAC-Exempt List tab.
Related Topics
•
Configuring Settings for AAA Firewall (PIX/ASA/FWSM), page 11-43
•
Filtering Tables, page 2-16
Field Reference
Table I-50 MAC-Exempt List Tab, AAA Firewall Settings Page
Element
|
Description
|
MAC-Exempt List Name
|
The name of the MAC exempt list.
|
MAC Exempt List table
|
The MAC exempt rules that you want to implement. The table shows the MAC addresses and masks (in hexadecimal) and whether you are permitting them (exempting them from authentication and authorization) or denying them (making them go through standard authentication and authorization). The device processes the entries in order and uses the first match (not the best match).
• To add an exemption rule, click the Add Row button and fill in the Firewall AAA MAC Exempt Setting Dialog Box.
• To edit an exemption rule, select it and click the Edit Row button.
• To delete an exemption rule, select it and click the Delete Row button.
|
Firewall AAA MAC Exempt Setting Dialog Box
Use the Firewall AAA MAC Exempt Setting dialog box to add and edit exemption entries in the MAC Exempt List table. The security appliance skips authentication and authorization for hosts associated with permitted MAC addresses.
Navigation Path
Go to the AAA Firewall Page, MAC-Exempt List Tab and click the Add Row button beneath the MAC Exempt List table, or select an item in the table and click the Edit Row button.
Related Topics
•
Configuring Settings for AAA Firewall (PIX/ASA/FWSM), page 11-43
Field Reference
Table I-51 Firewall AAA MAC Exempt Setting Dialog Box
Element
|
Description
|
Action
|
The action you want to take for the hosts that use the specified MAC addresses:
• Permit—Exempts the host from authentication and authorization.
• Deny—Forces the host to go through authentication and authorization.
|
MAC Address
|
The MAC address of the hosts in standard 12-digit hexadecimal format, such as 00a0.cp5d.0282. You can enter complete MAC addresses or partial addresses.
For partial addresses, you can enter 0 for digits you are not matching.
|
MAC Mask
|
The mask to apply to the MAC address. Use f to match a digit exactly, 0 to match any digit at that place:
• To specify an exact match of the address, enter ffff.ffff.ffff.
• To match an address pattern, enter 0 for any digit for which you want to match any character. For example, ffff.ffff.0000 matches all addresses that have the same first 8 digits.
|
AuthProxy Page
The AuthProxy page for IOS devices is divided into two sections:
•
AuthProxy General Tab (IOS)
•
AuthProxy Timeout Tab (IOS)
Navigation Path
To access the AuthProxy page, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > AuthProxy from the Device selector.
•
(Policy view) Select Firewall > Settings > AuthProxy from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Settings > AuthProxy.
Related Topics
•
Configuring Settings for AAA (IOS), page 11-44
AuthProxy General Tab (IOS)
Navigation Path
To access the AuthProxy General page, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > AuthProxy from the Device selector.
•
(Policy view) Select Firewall > Settings > AuthProxy from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Settings > AuthProxy.
Related Topics
•
Configuring Settings for AAA (IOS), page 11-44
Field Reference
Table I-52 AuthProxy General Tab
Element
|
Description
|
Authorization Server Groups
|
Selects different authorization methods by selecting different AAA Server Groups, for example, RADIUS and TACACS+ servers.
Enter the information in the field provided or click Select, which opens the AAA Server Groups Selector dialog box from which to make your selection.
|
Accounting Server Groups
|
Selects different accounting methods by selecting different AAA Server Groups, for example, RADIUS and TACACS+ servers.
Enter the information in the field provided or click Select, which opens the AAA Server Groups Selector dialog box from which to make your selection.
|
Use Broadcast for Accounting
|
When selected, enables sending accounting records to multiple AAA servers. Accounting records are simultaneously sent to the first server in each group. If the first server is unavailable, failover occurs using the backup servers defined within that group.
|
Authentication Server Groups
|
To configure authentication server groups, go to Platform > Device Admin > AAA.
|
Accounting Notice
|
Lists options for handling an accounting notice.
• Start-stop—Sends a start accounting notice at the beginning of a process and a stop accounting notice at the end of a process. The start accounting record is sent in the background. The requested user process begins regardless of whether the start accounting notice was received by the accounting server.
• Stop-only—Sends a stop accounting notice at the end of the requested user process.
• None—Disables accounting services on this line or interface.
|
HTTP Banner
|
Enables you to select an HTTP banner.
• Disable Banner Text—No banner is displayed for the authentication proxy login page for HTTP.
• Use Default Banner—Displays the default banner "Cisco Systems, <router hostname > Authentication" for the authentication proxy login page for HTTP.
• Use Custom Banner—Enables you to enter a custom message that appears for the authentication proxy login page for HTTP (for example, "Welcome <Username>."
Note If HTTP banner text and URL location are selected at the same time, the URL banner take precedence; however, the configuration for the banner text remains on the device.
|
Use HTTP banner from File
|
When selected, enables you to enter the URL for the HTTP banner file.
|
URL
|
Enables you to identify the location of the HTTP banner file.
|
HTTPS Server
|
To configure HTTPS Server, go to Platform > Device Admin > Device Access > HTTP.
|
FTP Banner
|
Enables you to select an FTP banner.
• Disable Banner Text—No banner is displayed for the authentication proxy login page for FTP.
• Use Default Banner—Displays the default banner "Cisco Systems, <router hostname > Authentication" for the authentication proxy login page for FTP.
• Use Custom Banner—Enables you to enter a custom message that appears for the authentication proxy login page for FTP (for example, "Welcome <Username >."
|
Telnet Banner
|
Enables you to select a Telnet banner.
• Disable Banner Text—No banner is displayed for the authentication proxy login page for Telnet.
• Use Default Banner—Displays the default banner "Cisco Systems, <router hostname > Authentication" for the authentication proxy login page for Telnet.
• Use Custom Banner—Enables you to enter a custom message that appears for the authentication proxy login page for Telnet (for example, "Welcome <Username >."
|
AuthProxy Timeout Tab (IOS)
Navigation Path
To access the AuthProxy Timeout page for IOS devices, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > AuthProxy from the Device selector.
•
(Policy view) Select Firewall > Settings > AuthProxy from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Settings > AuthProxy.
Related Topics
•
Configuring Settings for AAA (IOS), page 11-44
Field Reference
Table I-53 AuthProxy Timeout Tab
Element
|
Description
|
Global Inactivity Time
|
Specifies the length of time in minutes that an authentication cache entry, along with its associated dynamic user access control list (ACL), is managed after a period of inactivity. Values are 1 to 2,147,483,647 minutes.
|
Global Absolute Time
|
Specifies a window in which the authentication proxy on the enabled interface is active. Values are 1 to 65,535 minutes (45 and a half days).
|
Interface
|
Identifies the logical name of the interface (interface role) or physical interface to which a rule is assigned. For example:
• All DMZs
• All FastEthernets
• All Interfaces
• FastEthernet0
Note Interface roles are objects that are used to help you configure firewall rules. The objects are replaced with the actual interface names when the configuration is generated for each device.
|
Traffic Types
|
Identifies the protocols.
|
Inactivity Time
|
Specifies the length of time in minutes that an authentication cache entry, along with its associated dynamic user access control list (ACL), is managed after a period of inactivity. Values are 1 to 2,147,483,647 minutes.
|
Absolute Time
|
Specifies a window in which the authentication proxy on the enabled interface is active. Values are 1 to 65,535 minutes (45 and a half days).
|
Add button
|
Adds a rule to the table.
|
Edit button
|
Edits an existing rule in the table.
|
Delete button
|
Deletes a rule from the table.
|
Firewall AAA IOS Timeout Value Setting Dialog Box
Use the Firewall AAA IOS Timeout Value Setting dialog box to set inactivity and cache time, absolute time, and authentication proxy methods for interfaces on IOS devices.
Navigation Path
To access the Firewall AAA IOS Timeout Value Setting dialog box for IOS devices, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > AuthProxy from the Device selector. Click the Timeout tab. Right-click inside the table, then click Add Row or Edit Row.
•
(Policy view) Select Firewall > Settings > AuthProxy from the Policy selector. Click the Timeout tab. Right-click inside the table, then click Add Row or Edit Row.
Related Topics
•
Configuring Settings for AAA (IOS), page 11-44
Field Reference
Table I-54 Firewall AAA IOS Timeout Value Setting Dialog Box
Element
|
Description
|
Interfaces
|
Identifies the logical name of the interface (interface role) or physical interface to which a rule is assigned. For example:
• All DMZs
• All FastEthernets
• All Interfaces
• FastEthernet0
Enter the interface information, or click Select, which opens the Interface Selector dialog box from which to make your selection. You can also create an interface role by clicking the Create button in the Interface Selector dialog box.
Note Interface roles are objects that are used to help you configure firewall rules. The objects are replaced with the actual interface names when the configuration is generated for each device.
|
Inactivity/Cache Time
|
Specifies the length of time in minutes that an authentication cache entry, along with its associated dynamic user access control list (ACL), is managed after a period of inactivity. Values are 1 to 2,147,483,647 minutes.
|
Absolute Time
|
Specifies a window in which the authentication proxy on the enabled interface is active. Values are 1 to 65,535 minutes (45 and a half days).
|
Authentication Proxy Method (IOS)
|
Options are:
• HTTP—Specifies HTTP to trigger the authentication proxy.
• FTP—Specifies FTP to trigger the authentication proxy.
• Telnet—Specifies Telnet to trigger the authentication proxy.
|
Web Filter Settings Page
Use the Web Filter settings page to configure the web filter servers and other settings to use with your web filter rules policy.
You must install and configure the web filter servers as directed by the documentation for the server before configuring and deploying this policy. Security Manager cannot confirm that the servers exist or that are configured correctly.
Tip
These settings work only with the web filter rules policy. The web servers you configure here are not used with zone based firewall rules policies that configure web content filtering.
Navigation Path
To access the Web Filter settings page, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > Web Filter from the Device selector.
•
(Policy view) Select Firewall > Settings > Web Filter from the Policy selector.
•
(Map view) Right-click a device and select Edit Firewall Settings > Web Filter.
Related Topics
•
Configuring Settings for Web Filter Servers, page 11-57
•
Adding Web Filter Rules (PIX/ASA), page 11-54
•
Configuring Web Filter Rules for IOS devices, page 11-56
Field Reference
Table I-55 Web Filter Page
Element
|
Description
|
Web Filter Server Type
|
The type of web filter server you are using:
• None—You are not using web filter servers.
• Websense—You use Websense servers.
• Secure Computing SmartFilter/N2H2—You use Smartfilter servers. If you select this option, you can specify the server port to use for communication in the Port field.
Tip  If you change this setting, you are prompted to remove the existing list of servers from the table. Clicking Yes does not clear the table. The prompt is to remind you that the list might contain the wrong type of servers.
|
Web Filter Servers table
|
The servers that the device should use for web filtering. Enter the servers in priority order; the device uses the first one in the list until it fails to respond, and moves to the next server in the list until it receives a response.
If you select None for filter type, this list is ignored.
• To add a server, click the Add Row button and fill in the Web Filter Server Configuration Dialog Box.
• To edit a server, select it and click the Edit Row button.
• To delete a server, select it and click the Delete Row button.
|
IOS Specific Settings
|
Allow Traffic when Servers Unreachable
|
Whether the device should allow web traffic if the web filter servers are not responding. If you do not select this option, all web access is prevented until the servers come back online.
If you allow web traffic when the servers are down, the web requests are not filtered and access to all web servers is allowed.
|
Enable Alerts
|
Whether to generate stateful packet inspection alert messages on the console.
|
Enable Audit Trail
|
Whether audit trail messages are logged to the syslog server or router.
|
Enable Web Filter Server Logging
|
Whether to send system messages to the URL filtering server for logging. The device sends a log request immediately after the URL lookup request. The log request contains the URL, hostname, source IP address, and the destination IP address. The server records the log request into its own log server so your can view this information as necessary.
|
Cache Size
|
The maximum number of destination IP addresses (and their authorization status) that can be cached in the device. The default value is 5000.
When the cache reaches 80% full, the device starts removing older inactive entries.
|
Maximum Requests
|
The maximum number of outstanding requests that can exist at any given time. If the specified number is exceeded, new requests are dropped. The default is 1000.
|
Packet Buffer
|
The maximum number of HTTP responses that can be stored in the packet buffer of the device while it waits for the web filter server to allow or deny the request. The device drops responses when the maximum is reached. The default (and maximum) value is 200.
When users make web requests, the device simultaneously sends the request to the web site and to the web filtering server. If the response from the web site is received before the server provides a permit or deny response, the device keeps the request in the packet buffer until it gets a response from the server.
The response is removed from the buffer when the server responds or if the device determines that the server is unavailable and you also selected Allow Traffic when Servers Unreachable.
|
PIX/ASA/FWSM Specific Settings
|
Cache Match Criteria
|
How to cache web requests:
• Source and Destination—Cache entries are based on both the address initiating the request and the destination web address. Select this mode if users do not share the same filtering policy on the filtering server.
• Destination—Cache entries are based on the destination web address. Select this mode if all users share the same filtering policy on the filtering server.
|
URL Buffer Memory
(ASA 7.2+, PIX 7.2+ only.)
|
The size of the URL buffer memory pool in KB. Values are 2 to 10240.
|
Maximum Allowed URL Size
(ASA 7.2+, PIX 7.2+ only.)
|
The maximum allowed URL size in KB for each URL being buffered. The possible values differ depending on server type:
• Websense—From 2 to 4.
• Smartfilter (N2H2)—2 or 3.
|
Cache Size
|
The size of the cache, in KB, for storing responses from the filtering server. Values are 1 to 128.
Caching stores URL access privileges in memory on the security appliance. When a host requests a connection, the security appliance first looks in the URL cache for matching access privileges instead of forwarding the request to the Websense server.
|
URL Block Buffer Limit
|
The size of the buffer for storing web server responses while waiting for a filtering decision from the filtering server. The values are 1 to 128, which specifies the number of 1550-byte blocks.
|
Web Filter Server Configuration Dialog Box
Use the Web Filter Server Configuration dialog box to configure the external web filter servers you want to use with your Web Filter Rules policies. You can configure Websense or Smartfilter (N2H2) servers.
Navigation Path
From the Web Filter Settings Page, click Add Row beneath the Web Filter Servers table, or select a row and click Edit Row.
Related Topics
•
Configuring Settings for Web Filter Servers, page 11-57
•
Understanding Web Filter Rules, page 11-54
•
Working with Web Filter Rules, page 11-53
Field Reference
Table I-56 Web Filter Server Configuration Dialog Box
Element
|
Description
|
Common
|
IP Address
|
The IP address of the web filter server.
|
Timeout
|
The length of time, in seconds, that the device will wait for a response from the web filter server. The default is 5 seconds.
If the request times out, the device tries the next server, if you configure more than one.
|
PIX/ASA/FWSM Specific Settings
|
Interface
|
The network interface where the authentication server resides, for example, FastEthernet0. If not specified, the default is inside.
Enter the name of the interface or the interface role that identifies it, or click Select to select the interface or role from a list, or to create a new role. An interface must already be defined to appear on the list.
|
Protocol
|
The protocol to use when communicating with the web filtering server. Select the option for which the server is configured:
• TCP (version 1)
• TCP version 4
• UDP version 4
|
Connection Number
|
(Optional) The maximum number of TCP connections allowed between the device and the server.
|
IOS Specific Settings
|
Retransmit
|
The number of times the device will retransmit a request when the server does not respond. The default value is two times.
|
Port
|
The port number that the server listens on. The default port is 15868.
|
Zone Based Firewall Page
Use the Zone Based Firewall page to configure and identify unreferenced zones, specify a VPN zone, enable or disable WAAS support, maintain Trend Micro server and certificate information, and specify global Log settings on supported ASR devices.
The following tabs are described in the table on this page:
•
Zones
•
VPN
•
WAAS
•
Global Parameters (ASR)
The Content Filtering tab is detailed in Zone Based Firewall Page - Content Filter Tab.
Navigation Path
To access the Zone Based Firewall page, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > Zone Based Firewall from the Device selector.
•
(Policy view) Select Firewall > Settings > Zone Based Firewall from the Policy selector.
•
(Map view) Right-click a device and choose Edit Firewall Settings > Zone Based Firewall.
Related Topics
•
Configuring Settings for Zone Based Firewall Rules, page 11-70
•
Understanding the Zone-based Firewall Rules, page 11-62
•
Adding Zone-Based Firewall Rules, page 11-67
Field Reference
Table I-57 Zone Based Firewall Page
Element
|
Description
|
Zones tab
|
This tab displays the Zones table, which lists unreferenced zones; that is zones without any associated interfaces, rules or policies. Unreferenced zones are usually found and listed during device discovery, but you also can create named, "empty" zones here.
The Zones table lists the following information for each unreferenced zone:
• Zone - The name of the Zone/Interface Role.
• Content - Any interfaces assigned to the zone.
• Description - Any user-provided comments about the zone.
To add a zone to this table, click the Add Row button and provide a Zone name in the Zone dialog box.
|
VPN tab
|
This tab presents the VPN Zone field; a zone entry in this field ensures that dynamic VPN traffic can be processed by the zone-based firewall rules on this router. See Using VPNs with Zone-based Firewall Policies, page 11-65 for more information about this zone.
Enter or Select the zone through which VPN traffic will pass.
|
WAAS tab
|
This tab presents the Enable WAAS check box. Select this option to enable Wide Area Application Services interoperability.
If this option is not enabled, packets being optimized by a WAAS device may be dropped because WAAS increases the TCP packet sequence number during the TCP handshake. This behavior may be viewed as a possible attack by the IOS device.
|
Content Filtering tab
|
This tab displays server settings and certificate links for Trend Micro-based content filtering. For more information, see Zone Based Firewall Page - Content Filter Tab.
|
Global Parameters (ASR) tab
|
This tab displays global, logging-related settings specific to ASR devices. Configure these settings as follows:
• Log Dropped Packets - Select this option to log all packets dropped by the device; syslog logging must be enabled to view the information.
• Log Flow export timeout rate - NetFlow logs are created after a flow either expires or is timed out, and it is important to put a time limit on how long a flow can be active before expiring. This value is maximum number of minutes a flow can remain active before it is expired. The value can be any integer from 1 to 3600; the default is 30.
• Log Flow export destination IP - The IP address or host name of the NetFlow collector to which flow data is to be sent.
• Log Flow export destination port - The UDP port monitored by the NetFlow collector for flow data.
|
Zone Based Firewall Page - Content Filter Tab
To use Trend Micro-based content filtering, you must configure contact information for the Trend Micro server on this tab of the Zone Based Firewall page. This tab also provides links to Trend Micro registration and certificate download. You must have an active subscription with Trend Micro to utilize this form of content filtering, and you must download and install a valid subscription certificate on this IOS device.
Navigation Path
To access the Zone Based Firewall page, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > Zone Based Firewall from the Device selector.
•
(Policy view) Select Firewall > Settings > Zone Based Firewall from the Policy selector.
•
(Map view) Right-click a device and choose Edit Firewall Settings > Zone Based Firewall.
Related Topics
•
Zone-based Firewall Rules Page
•
Configuring Maps for Content Filtering in Zone-Based Firewall Rules Policies, page 8-59
•
Understanding the Zone-based Firewall Rules, page 11-62
•
Adding Zone-Based Firewall Rules, page 11-67
Field Reference
Table I-58 Zone Based Firewall Page - Content Filter Tab
Element
|
Description
|
Trend Micro Server Settings
|
Cache-entry-lifetime (hrs)
|
How long, in hours, a look-up request to the Trend Micro server remains in the router's local URL cache table. The allowed range is 0 to 120; the default value is 24.
|
Cache-size (KBytes)
|
The maximum amount of memory to be used by the router's local URL cache. The allowed range is 0 to 120,000 KB; the default value is 250.
|
Server
|
The fully-qualified domain name or IP address of the Trend Micro URL filtering server.
|
HTTP Port
|
The port the Trend Micro server is listening to for HTTP requests. The default is 80.
|
HTTPS Port
|
The port the Trend Micro server is listening to for HTTPS requests. The default is 443.
|
Retransmission Count
|
The number of times the router retransmits a look-up request when a response is not received from the server. The range is 1 to 10.
|
Retransmission Timeout
|
The number of seconds that the router waits for a response from the server. The range is 1 to 300.
|
Alert
|
Whether stateful packet inspection messages are copied to the syslog.
|
Trend Micro Server Certificate Download Links
|
Link to download certificates
|
Opens the page for installing Trusted Authority Certificates on Cisco IOS Routers for Trend URL Filtering Support.
|
Link for product registration
|
Opens the page for Product License Registration. You must enter the Product Authorization Key and register the router.
|
Zone Dialog Box
Use the Add and Edit Zone dialog boxes to add and edit unreferenced zones.
Navigation Path
To access the Add and Edit Zone dialog boxes, do one of the following:
•
(Device view) Select a device, then select Firewall > Settings > Zone Based Firewall from the Device selector. Right-click inside the Zones table, then select Add Row, or right-click a line item, then select Edit Row.
•
(Policy view) Select Firewall > Settings > Zone Based Firewall from the Policy selector. Right-click inside the table, then select Add Row, or right-click a line item, then select Edit Row.
•
(Map view) Right-click a device and select Edit Firewall Policies > Settings > Zone Based Firewall Rules.
Enter a zone name in the Zone field, or click Select to choose one from the Interfaces Selector dialog box.
Related Topics
•
Understanding the Zone-based Firewall Rules, page 11-62
•
Configuring Settings for Zone Based Firewall Rules, page 11-70
Add and Edit Rule Section Dialog Boxes
Use the Add and Edit Rule Section dialog boxes to add or edit a user-defined section heading in a rules table.
Navigation Path
Do one of the following:
•
Select one or more rules in a rules table, right-click and select Include in New Section.
•
Right-click a section heading and select Edit Section.
Related Topics
•
Using Sections to Organize Rules Tables, page 11-8
•
Using Rules Tables, page 11-3
Field Reference