+ All Categories
Home > Documents > Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a...

Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a...

Date post: 18-Mar-2021
Category:
Upload: others
View: 1 times
Download: 0 times
Share this document with a friend
67
1 © 2005 Cisco Systems, Inc. All rights reserved. Network Security 1 Module 3 – Security Devices
Transcript
Page 1: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

1© 2005 Cisco Systems, Inc. All rights reserved.

Network Security 1

Module 3 – Security Devices

Page 2: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

2© 2005 Cisco Systems, Inc. All rights reserved.

Learning Objectives

3.1 Device Options

3.2 Using Security Device Manager

3.3 Introduction to the Cisco Security Appliance Family

3.4 Getting Started with the PIX Security Appliance

3.5 PIX Security Appliance Translations and Connections

3.6 Manage a PIX Security Appliance with Adaptive Security Device Manager

3.7 PIX Security Appliance Routing Capabilities

3.8 Firewall Services Module Operation

Page 3: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

3© 2005 Cisco Systems, Inc. All rights reserved.

Module 3 – Security Devices

3.1 Device Options

Page 4: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

4© 2005 Cisco Systems, Inc. All rights reserved.

Sample Firewall Topology

Page 5: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

5© 2005 Cisco Systems, Inc. All rights reserved.

IOS Firewall

SecuritySecurityOfferingsOfferings

Network Integrated SolutionsNetwork Integrated Solutions

VPNVPN FirewallFirewall IntrusionIntrusionProtectionProtection VV33PNPN

IPsecIPsec CBAC Stateful InspectionCBAC Stateful Inspection IDSIDS SSHSSH SSLSSL

ACLACL AAAAAA NATNAT L2TP/EAPL2TP/EAPMSCHAPv2MSCHAPv2

PKIPKI

802.1X802.1X

BGPBGP GREGRE

MulticastMulticast Application Aware QoSApplication Aware QoS

DHCP/DNSDHCP/DNS

MPLSMPLSVoIPVoIP

EIGRPEIGRP OSPFOSPFMultiprotocolMultiprotocol

HTTPSHTTPS Secure ARPSecure ARPuRPFuRPF

Authentication Authentication per user via AAAper user via AAA

Command Command Authorization via AAAAuthorization via AAA

Device Access by Device Access by Privilege LevelPrivilege Level

Activity LoggingActivity Logging

NetflowNetflow

IP CompIP Comp

SNMPv3SNMPv3(Unicast Reverse Path Forward)(Unicast Reverse Path Forward)

IP Services

SecureOperating SystemFoundation

Page 6: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

6© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance Lineup

SMBSMB

Con

nect

ivity

Performance

Gigabit Ethernet

EnterpriseEnterpriseROBOROBO

PIX 515E

PIX 525

PIX 535

SOHOSOHO

PIX 501

PIX 506E

Service ProviderService Provider

Stateful Inspection FirewallStateful Inspection FirewallAppliance is Hardened OSAppliance is Hardened OSIPSec VPNIPSec VPNIntegrated Intrusion DetectionIntegrated Intrusion DetectionHot Standby, Stateful Failover Hot Standby, Stateful Failover Easy VPN Client/ServerEasy VPN Client/ServerVoIP SupportVoIP Support

Page 7: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

7© 2005 Cisco Systems, Inc. All rights reserved.

Adaptive Security Appliance Lineup

Page 8: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

8© 2005 Cisco Systems, Inc. All rights reserved.

Catalyst Switch Integration

FirewallIDSVirtual Private Network

Appliance Capabilities Cisco Infrastructure

© 2002, Cisco Systems, Inc. All rights reserved.

VPN SSL NAM IDSFirewall

Security Services Modules

Page 9: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

9© 2005 Cisco Systems, Inc. All rights reserved.

Module 3 – Security Devices

3.2 Using Security Device Manager

Page 10: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

10© 2005 Cisco Systems, Inc. All rights reserved.

Security Device Manager (SDM)

Page 11: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

11© 2005 Cisco Systems, Inc. All rights reserved.

Obtaining SDM

• SDM is factory loaded on supported routers manufactured as of June 2003.

• Always check www.cisco.com/go/sdm for the latest information regarding SDM support.

• SDM cannot be ordered independent of the router.

Page 12: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

12© 2005 Cisco Systems, Inc. All rights reserved.

Initial Configuration

RouterP(config)# ip http server

RouterP(config)# ip http secure-server

RouterP(config)# ip http authentication local

RouterP(config)# username sdm privilege 15 password sdm

RouterP(config)# line vty 0 4

RouterP(config-line)# privilege level 15

RouterP(config-line)# login local

RouterP(config-line)# transport input telnet ssh

Page 13: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

13© 2005 Cisco Systems, Inc. All rights reserved.

Startup Wizard: Welcome Window

Page 14: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

14© 2005 Cisco Systems, Inc. All rights reserved.

SDM Main Window Layout and Navigation

Menu bar

Toolbar

RouterInformation

ConfigurationOverview

Page 15: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

15© 2005 Cisco Systems, Inc. All rights reserved.

SDM Wizard Options

• LAN Configuration: Configure LAN interfaces and DHCP. • WAN Configuration: Configure PPP, Frame Relay, and

HDLC WAN interfaces.• Firewall: Access two types of firewall wizards:

– Simple inside/outside.– Advanced inside/outside/DMZ with multiple

interfaces.• VPN: Access three types of VPN wizards:

– Secure site-to-site VPN– Easy VPN– GRE tunnel with IPSec VPN

• Security Audit: Performs a router security audit and button for router lockdown.

• IPS:• QOS:• Routing:

Page 16: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

16© 2005 Cisco Systems, Inc. All rights reserved.

WAN Wizard: Create a New WAN Connection

Page 17: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

17© 2005 Cisco Systems, Inc. All rights reserved.

Reset to Factory Default Wizard

Page 18: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

18© 2005 Cisco Systems, Inc. All rights reserved.

Monitor Mode

Overview

InterfaceStats

FirewallStats

VPNStats

Page 19: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

19© 2005 Cisco Systems, Inc. All rights reserved.

Monitor Interface Status

Page 20: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

20© 2005 Cisco Systems, Inc. All rights reserved.

Monitor Firewall Status

Page 21: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

21© 2005 Cisco Systems, Inc. All rights reserved.

Monitor VPN Status

Page 22: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

22© 2005 Cisco Systems, Inc. All rights reserved.

Monitor Logging

Page 23: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

23© 2005 Cisco Systems, Inc. All rights reserved.

Module 3 – Security Devices

3.3 Introduction to the Cisco Security Appliance Family

Page 24: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

24© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance Family

Page 25: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

25© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 501 Front Panel LEDs

VPN tunnel

Power

100 MBPS

Link/Act

Page 26: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

26© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 501 Back Panel

Security lock slot

Power connector

10BaseT (RJ-45)

Console port (RJ-45)

4-port 10/100 switch (RJ-45)

Page 27: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

27© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 506E Front Panel LEDs

Network LED

Power LED

Active LED

Page 28: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

28© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 506E Back Panel

LINKLED

Console Port (RJ-45)

Power switch

USBport

ACT(ivity)LED

10BaseT(RJ-45)

10BaseT(RJ-45)

ACT(ivity)

LED LINKLED

Page 29: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

29© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 515E Front Panel LEDs

Network LED

Power LED

Active failover firewall

Page 30: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

30© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 515E Back Panel

Failoverconnector

FDXLED

LINKLED

100 MbpsLED

FDXLED

Consoleport (RJ-45)

10/100BaseTXEthernet 1

(RJ-45)

Power switch

LINK

LED

100 MbpsLED

10/100BaseTXEthernet 0

(RJ-45)

LINK

LED

Page 31: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

31© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 515E Quad Card

Using the quad card requires the PIX Security Appliance 515E-UR license.

Page 32: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

32© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 515E Two Single-Port Connectors

Using two single-port connectors requires the PIX Security Appliance 515E-UR license.

Page 33: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

33© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 525 Front Panel LEDs

Power LED

Active LED

Page 34: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

34© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 525 Back Panel

100MbpsLED

ACT(ivity) LED

ACT(ivity) LED

LINKLED

LINKLED

Failoverconnection

10/100BaseTXEthernet 1

(RJ-45)10/100BaseTX

Ethernet 0(RJ-45)

USBport

Consoleport (RJ-45)

Page 35: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

35© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 535 Front Panel LEDs

Power ACT

Page 36: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

36© 2005 Cisco Systems, Inc. All rights reserved.

Bus 0(64-bit/66 MHz)

Bus 1(64-bit/66 MHz)

Bus 2(32-bit/33 MHz)

• 1FE• 4FE• VAC

• 1GE-66

PIX Security Appliance 535—Board InstallDB-15

failover

ConsoleRJ-45

USB port

Slot 8

Slot 7

Slot 6

Slot 5

Slot 4

Slot 3

Slot 2 Slot 1

Slot 0

Page 37: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

37© 2005 Cisco Systems, Inc. All rights reserved.

PIX Security Appliance 535 Back Panel

DB-15failover

Slot 8

Slot 7

Slot 6

Slot 5

Slot 4

Slot 3

Slot 2 Slot 1

Slot 0ConsoleRJ-45

USB port

Page 38: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

38© 2005 Cisco Systems, Inc. All rights reserved.

ASA5510 Adaptive Security Appliance

• Up to five 10/100 Fast Ethernet interfaces

• Optional Security Services Module (SSM) slot which provides inline IPS.

• Throughput of 100 Mbps with the ability to handle up to 64,000 concurrent connections.

• Supports Active/standby failover.

• Can deliver 150 Mbps IPS throughput when an AIP SSM model 10 is added to the appliance.

Page 39: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

39© 2005 Cisco Systems, Inc. All rights reserved.

ASA5520 Adaptive Security Appliance

• Four 10/100/1000 Gigabit Ethernet interfaces

• Supports an SSM slot which provides inline IPS.

• Throughput of 200 Mbps with the ability to handle up to 130,000 concurrent connections.

• Supports active/standby and active/active failover.

• Can deliver 375 Mbps IPS throughput when an AIP SSM model 20 is added to the appliance.

Page 40: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

40© 2005 Cisco Systems, Inc. All rights reserved.

ASA5540 Adaptive Security Appliance

• Four 10/100/1000 Gigabit Ethernet interfaces

• One 10/100 Fast Ethernet management interface

• Optional Security Services Module slot which provides inline IPS.

• Throughput of 400 Mbps with the ability to handle up to 280,000 concurrent connections.

• Can deliver 450 Mbps IPS throughput when an AIP SSM model 20 is added to the appliance.

Page 41: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

41© 2005 Cisco Systems, Inc. All rights reserved.

Module 3 – Security Devices

3.4 Getting Started with the PIX Security Appliance

Page 42: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

42© 2005 Cisco Systems, Inc. All rights reserved.

User Interface

• Unprivileged mode – This mode is available when the PIX is first accessed. The > prompt is displayed. This mode provides a restricted, limited, view of PIX settings.

• Privileged mode – This mode displays the # prompt and enables users to change the current settings. Any unprivileged command also works in privileged mode.

• Configuration mode – This mode displays the (config)# prompt and enables users to change system configurations. All privileged, unprivileged, and configuration commands work in this mode.

• Monitor mode – This is a special mode that enables users to update the image over the network or to perform password recovery. While in the monitor mode, users can enter commands specifying the location of the TFTP server and the PIX software image or password recovery binary file to download.

Page 43: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

43© 2005 Cisco Systems, Inc. All rights reserved.

Security Levels

• Higher security level interface to a lower security level interface – For traffic originating from the inside interface of the PIX with a security level of 100 to the outside interface ofthe PIX with a security level of 0, all IP-based traffic is allowed unless it is restricted by ACLs, authentication, or authorization.

• Lower security level interface to a higher security level interface – For traffic originating from the outside interface of the PIX with a security level of 0 to the inside interface of the PIX with a security level of 100,all packets are dropped unless specifically allowed by an access-list command. The traffic can be restricted further if authentication and authorization isused.

• Same secure interface to a same secure interface – No traffic flows between two Interfaces with the same security level.

Page 44: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

44© 2005 Cisco Systems, Inc. All rights reserved.

Basic Commands

• hostname – assigns a hostname to the PIX.

• interface – Configures the type and capability of each perimeter interface.

• nameif – Assigns a name to each perimeter interface.

• ip address – Assigns an IP address to each interface.

• security level – Assigns the security level for the perimeter interface.

• speed – Assigns the connection speed.

• duplex – Assigns the duplex communications.

Page 45: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

45© 2005 Cisco Systems, Inc. All rights reserved.

Additional Commands

•nat-control – Enable or disable NAT configuration requirement.

•nat – Shields IP addresses on the inside network from the outside network.

•global – Creates a pool of one or more IP addresses for use in NAT and PAT.

•route – Defines a static or default route for an interface.

Page 46: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

46© 2005 Cisco Systems, Inc. All rights reserved.

Module 3 – Security Devices

3.5 PIX Security Appliance Translations and Connections

Page 47: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

47© 2005 Cisco Systems, Inc. All rights reserved.

UDP

Page 48: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

48© 2005 Cisco Systems, Inc. All rights reserved.

NAT

Page 49: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

49© 2005 Cisco Systems, Inc. All rights reserved.

Access through the PIX Security Appliance

Page 50: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

50© 2005 Cisco Systems, Inc. All rights reserved.

PAT

Page 51: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

51© 2005 Cisco Systems, Inc. All rights reserved.

Static Translation

Page 52: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

52© 2005 Cisco Systems, Inc. All rights reserved.

Identity NAT

Page 53: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

53© 2005 Cisco Systems, Inc. All rights reserved.

Multiple Interfaces

Page 54: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

54© 2005 Cisco Systems, Inc. All rights reserved.

Module 3 – Security Devices

3.6 Manage a PIX Security Appliance with Adaptive Security Device Manager

Page 55: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

55© 2005 Cisco Systems, Inc. All rights reserved.

Adaptive Security Device Manager (ASDM)

Page 56: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

56© 2005 Cisco Systems, Inc. All rights reserved.

ASDM Compatibility

Page 57: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

57© 2005 Cisco Systems, Inc. All rights reserved.

ASDM Home Window

Page 58: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

58© 2005 Cisco Systems, Inc. All rights reserved.

Module 3 – Security Devices

3.7 PIX Security Appliance Routing Capabilities

Page 59: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

59© 2005 Cisco Systems, Inc. All rights reserved.

VLANs

Page 60: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

60© 2005 Cisco Systems, Inc. All rights reserved.

Static Routes

Page 61: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

61© 2005 Cisco Systems, Inc. All rights reserved.

Routing with RIP

Page 62: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

62© 2005 Cisco Systems, Inc. All rights reserved.

Routing with OSPF

Page 63: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

63© 2005 Cisco Systems, Inc. All rights reserved.

Multicast Routing

Page 64: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

64© 2005 Cisco Systems, Inc. All rights reserved.

Module 3 – Security Devices

3.8 Firewall Services Module Operation

Page 65: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

65© 2005 Cisco Systems, Inc. All rights reserved.

Firewall Services Module (FWSM)

Designed for high end enterprise and service providers

Runs in Catalyst 6500 switches and 7600 Series routers

Based on PIX Security Appliance technology

PIX Security Appliance 6.0 feature set (some 6.2)

1 million simultaneous connections

Over 100,000 connections per second

5 Gbps throughput

Up to 4 can be stacked in a chassis, providing 20 Gbps throughput

1 GB DRAM

Supports 100 VLANs

Supports failover

Page 66: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

66© 2005 Cisco Systems, Inc. All rights reserved.

FWSM in the Catalyst 6500 Switch

Supervisor engine

Redundant supervisor engine

Slots 1-9(top to bottom) 48 Port 10/100 Ethernet

Switch fabricmoduleFan assembly

16 Port GBIC

FWSM

Powersupply 2

Powersupply 1

ESD ground strap connector

Page 67: Network Security 1askoik.kapsi.fi/koulu/NetSec1/NS1_v20_Module03-new.pdf · 2017. 2. 20. · a restricted, limited, view of PIX settings. • Privileged mode – This mode displays

67© 2005 Cisco Systems, Inc. All rights reserved.

FWSM in the Cisco 7609 Internet Router

Supervisor engine

Fan assembly

Powersupply 1

Powersupply 2

Switch fabricmodule

ESD ground strap connection

FWSM

Slots 1-9(right to left)


Recommended