Posts mit dem Label pemu werden angezeigt. Alle Posts anzeigen
Posts mit dem Label pemu werden angezeigt. Alle Posts anzeigen

Freitag, 23. Oktober 2009

DE - "ASDM" Befehlseinschränkung

Ich hab eine ganze Weile nichts mehr gepostet und komme auch im Moment nicht wirklich dazu, daher mach ich mich mal ans übersetzen von älteren Artikeln, Es ist ja nicht so das wir hier nicht eigentlich Deutsch und Englisch anbieten wollten.

Die Anfrage um die es geht kam damals via Twitter und es war einfach grundlegend nur die Frage, Kann man Nutzern im ASDM rechte beschneiden, so das sie nur Teile der Konfiguration sehen können.. Kurz um: “Ja es geht”

Anbei hab ich eine Quick und Dirty Konfiguration zusammengeschustert die zeigt wie es geht. Ich hab das ganze auf realer Hardware getestet (ASA 5505 8.0.3 ASDM 6.2.1) mit echten VPN settings. Wie gesagt es geht und die Nutzer können nur die Settings im ASDM betrachten und nicht ändern.


PIX Version 8.0(3)
!
hostname PIX
domain-name playingwithnetworks.com
enable password 123 encrypted
!
interface Ethernet0
shutdown
no nameif
no security-level
no ip address
!
interface Ethernet1
nameif inside
security-level 100
ip address 192.168.188.2 255.255.255.0
!
!
!
dns server-group DefaultDNS
domain-name playingwithnetworks.com
pager lines 24
logging enable
logging buffered debugging
logging asdm errors
mtu inside 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image flash:/asdm-621.bin
!
!
!

dynamic-access-policy-record DfltAccessPolicy

aaa authentication http console LOCAL
aaa authorization command LOCAL
! THIS IS IMPORTANT IF YOU MISS THIS COMMANDS THE THING WILL NOT WORK

http server enable
http 192.168.188.0 255.255.255.0 inside
!
!
!
username VPNSUPPORT password 123 encrypted priv 2
!
!
privilege show level 2 mode exec command running-config
privilege show level 2 mode exec command version
privilege show level 2 mode exec command interface
privilege show level 2 mode exec command logging
privilege show level 2 mode exec command aaa
privilege show level 2 mode exec command crypto
privilege show level 2 mode exec command vpn-sessiondb
privilege show level 2 mode exec command vpnclient
privilege show level 2 mode exec command vpn
privilege show level 2 mode exec command blocks
privilege show level 2 mode exec command webvpn
privilege show level 2 mode exec command compression
!
prompt hostname context


In der vorangegangene Konfiguration wird dem User VPNSUPPORT das Recht eingeräumt, VPN Informationen abzurufen, ohne sie ändern zu können.
Um andere Bereich freizugeben oder zu Sperren kann man einen Trick anwenden.


debug http enabled at level 250


Dann clickt man mit einem User auf die Bereiche die man sehen will und im Debug sieht man die URL die aufgerufen wird. Anhand dieser Information kann die CFG oben angepasst werden.


HTTP: processing GET URL '/admin/exec/show+ipv6+neighbor'


Im Beispiel kann Ipv6 für Level 2 User freigegeben werden.

HTH
Cheers NWG

Montag, 22. Juni 2009

EN - "ASDM" command restrictions

This one I just received via Twitter (Well i grabbed it from my search stream)
Can you restrict ASDM so that users can only view parts of the configuration.

Well "Yes you can"
I´ve created a quick and dirty configuration that should reflect this settings.
Update tested on real hardware with real VPN connections (ASA 5505 8.0.3 ASDM 6.2.1) Works quite well, users can´t reset or disconnect only view. Some commands added to view all VPN settings on ASDM.


PIX Version 8.0(3)
!
hostname PIX
domain-name playingwithnetworks.com
enable password 123 encrypted
!
interface Ethernet0
shutdown
no nameif
no security-level
no ip address
!
interface Ethernet1
nameif inside
security-level 100
ip address 192.168.188.2 255.255.255.0
!
!
!
dns server-group DefaultDNS
domain-name playingwithnetworks.com
pager lines 24
logging enable
logging buffered debugging
logging asdm errors
mtu inside 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image flash:/asdm-621.bin
!
!
!

dynamic-access-policy-record DfltAccessPolicy

aaa authentication http console LOCAL
aaa authorization command LOCAL
! THIS IS IMPORTANT IF YOU MISS THIS COMMANDS THE THING WILL NOT WORK

http server enable
http 192.168.188.0 255.255.255.0 inside
!
!
!
username VPNSUPPORT password 123 encrypted priv 2
!
!
privilege show level 2 mode exec command running-config
privilege show level 2 mode exec command version
privilege show level 2 mode exec command interface
privilege show level 2 mode exec command logging
privilege show level 2 mode exec command aaa
privilege show level 2 mode exec command crypto
privilege show level 2 mode exec command vpn-sessiondb
privilege show level 2 mode exec command vpnclient
privilege show level 2 mode exec command vpn
privilege show level 2 mode exec command blocks
privilege show level 2 mode exec command webvpn
privilege show level 2 mode exec command compression
!
prompt hostname context


So this should be enough to show your user VPNSUPPORT information about the status of your VPN connection. If you need further information you could use the following trick: switch on debug:


debug http enabled at level 250


and then click with you low priv user to the location of the ASDM you need. You will get the output of what URL was requested and from this you can see what commands you need to enable
for example if you click on monitor interfaces you will get along with others the debug output:


HTTP: processing GET URL '/admin/exec/show+ipv6+neighbor'


With this information you can now enable show ip6 for level 2 if you need.

Hope that helps
NWG

Donnerstag, 23. April 2009

DE - NEUES aus dem Netz- ASA 8.2 und das neue IPS für die ASA 5505

In den meisten englischen Blogs ist es seit 2 Tage ein großes Thema, die aktuellen Ankündigungen von Cisco zum Security Bereich. Zwei der wichtigsten Themen (aus meiner Sicht) sind

Die neuen Features des ASA 8.2 Releases
Eigentlich sollte die Version 8.2 bereits zum Download angeboten sein aber mein CCO Account weis noch nichts davon. Na mal sehen wann das Release kommt und ich ein wenig damit rumspielen kann. Leider ist das ASA only so das man es nicht in Pemu verwenden kann. Egal!
Das wichtigste Feature ist wohl der Botnet Filter, der die Kommunikation von bereits infizierten Geräten zu den Botnetzen unterbinden soll.
Außerdem klingt der TCP State Bypass ganz interessant, aber das muss ich dann in der echten Welt zeigen.

Das zweites Highlight ist das IPS für die ASA 5505
Vor einer weile hab ich schon einmal Gerüchte über ein IPS für die ASA 5505 gehört und nun ist offiziell für den Mai angekündigt. Persönlich finde ich die Idee großartig und hoffe das sie vom Markt angenommen wird (und das sie nicht zu teuer wird).


Cisco Q&A about the new features and the ASA 5505 IPS + more
ASA 8.2 Image Features

Thanks for the information to Jamey Heary at Networkworld

Cheers
NWG

Mittwoch, 22. April 2009

EN - NEWS from the Web - ASA 8.2 and IPS for ASA 5505

Well you may have heard from several other blogs and news sites that Cisco announced some new interesting features for the ASA Firewalls. Among some other the key things that are interesting for me (personal) are

ASA 8.2 main feature
Basing on the ASA Q+A this ASA Image should be available already but my CCO account shows nothing for the ASA to download. Hope that this image will be available soon for test deployment.
Some features that really are worth a second look.
First to mention is Botnet Filtering that by design should prevent traffic from a already infected machine to the Botnets.
Interesting sounds the TCP State bypass but this will need some hands on to check :)
Some drawback, ASA 8.2 is an ASA only image so no support in PEMU

ASA 5505 IPS
I´ve heard rumors about it and the empty slot was obvious for some add on. Well now you can have a look at the brand new Cisco ASA 5505 IPS module. I think this is a great feature for the ASA 5505, I know some customers that are looking for this feature and I hope that the market accepts the IPS.

Cisco Q&A about the new features and the ASA 5505 IPS + more
ASA 8.2 Image Features

Thanks for the information to Jamey Heary at Networkworld

Cheers
NWG

Dienstag, 24. März 2009

DE – Tools update

In den letzten Wochen hat sich mein Lab doch etwas verändert, daher hier ein kurzes Update.

Tools:
GNS3 Version 0.6

Ich musste feststellen das die 7200 Router ab einer bestimmten Anzahl dazu tendieren einfach so zu crashen. Bei meinem Arbeitsnotebook ist das zwischen 3 und 4 Router. Daher habe ich die Wahl dieser Boxen verworfen. Seit kurzem setze ich daher auf 3725, ich wollte zuerst die 3745er nehmen aber die leiden unter einem Dynamips Bug und so kann man die Konfig nicht reimportieren nachdem man sie gespeichert hat. Die 3725 laufen mit dem IOS 12.4.15T8.

Ach so ich habe eine der 5505 ASAs ausgetauscht gegen eine 5510 aber leider ist die Box im produktiven Umfeld. Daher wird es auf der keinen großen außergewöhnlichen Configs geben.

Bei VMWare bleibt alles beim alten.
Cheers NWG

ENG – Tools update

Well within the last weeks my environment slightly changed.

Just to give you a quick update
Tools:
GNS3 version 0.6

I've noticed that the 7200 routers tend to crash, if you run more than a certain amount of them. On my notebook it is often between 3 or 4 7200 routers, even if the are doing nothing. I dropped them and only use them if I need features of 12.4.22T1.
My main routers are now 3725, I tried the 3745 but due to some kind of dynamips bug the do not re import saved configs. So I keep the 3725s running IOS 12.4.15T8.

I changed one of the ASA 5505 to an ASA 5510 but this equipment is now in productive environment so their is no big chance of using them in tricky configs. Both ASAs are still running v8.0.3

VMWare stays the same
Cheers NWG

Montag, 16. März 2009

DE – Tool für PEMU unter Windows

In der letzten Zeit habe ich viel mit Dynamips und PEMU gemacht und habe festgestellt das es oft anstrengend ist mehr als 2 PIX laufen zu lassen. Meistens ist nach 4 PIX Schluss da mein CPU bei 100% ist und selbst schreiben unmöglich wird. Am Freitag hat mir ein Kollege „Battle Encoder Shiraze“ als zusätzliches Tool empfohlen. Damit lassen sich einzelne CPU Prozesse limitieren. Ich war danach in der Lage 9 PIX und einen Router gleichzeitig laufen zu lassen.
Es ist auf jeden Fall einen blick Wert

BES 1.3.8

Hoffentlich hilft es noch mehr Leuten als nur mir
Cheers NWG

ENG - Tool for PEMU under Windows

Playing around with dynamips and pemu is sometime quite hard since running two or more PIX Firewalls costs a lot of resources. Usually running 4 PIX is the maximum I can run on my laptop before I hit 100% CPU Load.
But on Friday a co-worker showed me „Battle Encoder Shiraze“ with this tool you are able to limit the CPU load of PEMU. Quite nice!! I was able to run about 9 PIX and 1 Router without problems.

BES 1.3.8

Hope that helps
Cheers NWG

Donnerstag, 26. Februar 2009

ENG - Tools and Hardware

To build my labs I use several tools here are some of them including some links

Tools
GNS3 – graphical interface for the router simulator Dynamips
* mainly I use the 7200 routers with 12.4.22T IOS

Pemu – PIX and ASA simulator
* my PIX are running v7.2.4 or v8.0.4
* the ASA is running v8.0.3

VMWare – nothing more to say I guess


Hardware

2x ASA 5505
* both ASAs are running 8.0.4

DE - Tools und Hardware

Um die Labs zu bauen werde verschiedene Tools benutzt hier eine kleine Auflistung mit Links.

Tools
GNS3 – grafische Oberfläche zum Router Simulator Dynamips
* Hauptsächlich arbeite ich mit den 7200 Router und IOS 12.4.22T

Pemu – PIX und ASA Simulator
* die PIXen laufen mit v7.2.4 oder v8.0.4
* die ASA mit v8.0.3

VMWare – Was soll ich hierzu noch sagen

Hardware
2x ASA 5505
* beide ASAs laufen mit 8.0.4