Websense and N2H2

Websense and N2H2

The PIX can collaborate with two types of clarification servers:Websense (www

.websense.com) and N2H2 (www.n2h2.com).Websense is accurate in PIX

version 5.3 and later, and N2H2 abutment was added in adaptation 6.2. PIX URL

filtering is activated alone to HTTP requests; for example, it does not accomplish any

inspections of FTP links. (Although a URL of blazon ftp://ftp.somedomain.com

can be entered in a Web browser, it uses the FTP protocol, not HTTP.) The PIX

also does not audit HTTPS connections.

The accomplish to configure URL clarification are:

1. Specify the server to use for URL processing.

2. Tell the firewall the cartage to inspect—ports and IP addresses.

3. Optionally configure some server-specific parameters.

4. Configure clarification rules on the clarification server.

The command for allegorical a clarification server for Websense is:

url-server () host [timeout ] [protocol

| [version 1|4]]

www.syngress.com

Figure 4.9 Interaction Among a Client, a Web Server, PIX, and a

Filtering Server

"GET /goodpage.html HTTP/1.1

Client Host: www.company.com"

FIltering Server www.mycompany.com

"Permit?"

"Yes"

"GET /goodpage.html HTTP/1.1

Host: www.company.com"

168 Chapter 4 • Advanced PIX Configurations

For example, the afterward cipher specifies that the PIX should use a server

with IP abode 10.0.0.1, which is amid on the interface “inside,” and connect

to it appliance TCP Websense agreement adaptation 4:

PIX1(config)# url-server (inside) host 10.0.0.1 agreement tcp adaptation 4

Particularly, if_name is an interface on which the server is located, the default

here is the central interface. local_ip is the IP abode of the clarification server.The

PIX uses abeyance (default is 5 seconds) to adjudge how continued it has to delay for a

reply from the server until it gives up and switches to the abutting configured server

or takes a absence activity if there are no added servers available. It is accessible to

configure up to 16 servers, but they all charge be of the aforementioned type; it is not possible

to use both Websense and N2H2 clarification servers in the aforementioned configuration.

The aboriginal server configured is a primary clarification server and is contacted first.

Protocol blazon and adaptation ambit specify the Websense agreement that should

be acclimated for advice with the server. It can be either TCP protocol

version 1 (default) or 4 or UDP agreement adaptation 4.

The N2H2 server is defined by the command:

url-server (if_name) bell-ringer n2h2 host [timeout ]

[port ] [protocol tcp | udp]

The acceptation of ambit is the same.The constant bell-ringer n2h2 states that

the server is an N2H2 clarification server. It is accessible to add the constant vendor

websense to the Websense server configuration, but it is affected by default. N2H2

servers accept alone a advice agreement adaptation available, so it is not specified.

It is accessible to configure the anchorage to use for advice with the

N2H2 server appliance the port_number parameter.

NOTE

If you about-face the appliance blazon (that is, change from N2H2 server to

Websense or carnality versa), all agreement of URL clarification is absent and will

need to be re-entered.

The abutting assignment is to configure the clarification action itself.The accordant command

is:

filter url [-]

[allow] [proxy-block]

www.syngress.com

Advanced PIX Configurations • Chapter 4 169

This command specifies anchorage numbers on which HTTP access should

be inspected (with the absence of anchorage 80). local_ip and local_mask specify which

local audience are accountable to ecology (that is, the requests by the machines from

this arrangement will be arrested with URL clarification server).The foreign_ip and

foreign_mask ambit specify that alone requests to a specific set of servers be

checked.The acquiesce constant defines that the PIX should admittance cartage through

if it is clumsy to acquaintance the primary URL clarification server. Finally, the proxy-block

parameter specifies that all requests from any audience to proxy servers will be

denied. For example, the afterward command defines that all HTTP requests to

port 80 will be inspected:

PIX1(config)# clarify url http 0 0 0 0

The afterward command configures analysis of all HTTP requests to port

8080 from audience on arrangement 10.100.1.0/24 to any server and allows the request

to canyon through in case a clarification server is unavailable:

PIX1(config)# clarify url 8080 10.100.1.0 255.255.255.0 0 0 allow

Another alternative of the clarify command allows allegorical that some traffic

should be absolved from filtering.The architecture in this case is:

filter url except

When entered afterwards the clarify command, this command excludes specified

traffic from the policy. For example, the afterward arrangement of commands means

that all HTTP cartage to anchorage 8080 will be inspected, excluding cartage from network

10.100.1.0/24:

PIX1(config)# clarify url 8080 0 0 0 0

PIX1(config)# clarify url except 10.100.1.0 255.255.255.0 0 0 allow

Filtering URLs cisco

Filtering URLs

It is accessible to use admission lists to admittance or abjure admission to specific Web sites, but

if the account of sites grows long, this band-aid will affect firewall performance. In

addition, admission lists do not accommodate a adjustable way of authoritative admission in this

case; it is not possible, for example, to admittance or abjure admission to specific pages on a

Web site, alone to the accomplished armpit articular by its IP address. Admission lists will also

not assignment for Web sites that are around hosted; in this case, there are abounding Web

sites amid on the aforementioned server and all of them accept the aforementioned IP address, so it is

only accessible to abjure or admittance admission to all of them at the aforementioned time.

As stated, one accepted band-aid moves best of the assignment to a committed URL

filtering server, offloading the PIX’s CPU and acceptance for fine-tuning of Web

access controls.The arrangement of contest is as follows:

1. A applicant establishes a TCP affiliation to a Web server.

2. The applicant sends an HTTP appeal for a folio on this server.

3. The PIX intercepts this appeal and easily it over to the clarification server.

4. The clarification server decides if the applicant should be accustomed admission to the

requested page.

5. If the accommodation is positive, the PIX assiduously the appeal to the server and

the applicant receives the requested content.

6. If the accommodation is negative, the client’s appeal is dropped.

Figure 4.9 demonstrates this process.

Interaction Among a Client, a Web Server, PIX, and a

Filtering Server

"GET /goodpage.html HTTP/1.1

Client Host: www.company.com"

FIltering Server www.mycompany.com

"Permit?"

"Yes"

"GET /goodpage.html HTTP/1.1

Host: www.company.com"

Filtering Web Traffic

Filtering Web Traffic

Although generally the best absorption is paid to the aegis of centralized servers or

clients from alien awful attempts (the capital purpose of ACLs), it is sometimes

important to adviser and clarify outbound admission fabricated by users. One

reason for agreeable analysis is if you appetite to use your firewall to accomplish security

policies such as an adequate use policy, which could specify that internal

users may not use the company’s Internet affiliation to browse assertive categories

of Web sites.There are abounding solutions for accomplishing this goal, but the most

general one is URL filtering, in which the firewall easily anniversary appeal for HTTP

content to a clarification server, which can accept the appeal or abjure admission to it.

The firewall again acts accordingly: If the appeal is approved, it is forwarded to

www.syngress.com

166 Chapter 4 • Advanced PIX Configurations

the alfresco server and the applicant receives the asked-for content; if not, either the

request is silently alone or the user is redirected to a folio cogent him or her

that the appeal breaches aggregation policy.

Another acumen for clarification is to accord with “active content” such as ActiveX

or Java applets.This could be important in adjustment to assure centralized users from

malicious Web servers that bury these executable applets in their Web pages,

because such executable agreeable can accommodate bacilli or Trojan horses.The most

general band-aid is agreeable filtering, which scans admission applets for bacilli and

denies them back article amiss is found. Unfortunately, the PIX does not

support this accepted solution, and the alone affair you can do with it is to band all

active agreeable from admission Web pages.

Internet Locator Service and Lightweight Directory Access Protocol

Internet Locator Service and Lightweight

Directory Access Protocol

Microsoft developed the Internet Locator Service (ILS) agreement for use in products

such as NetMeeting, SiteServer, and Active Directory services. It is based on

Lightweight Directory Access Agreement (LDAP) adaptation 2.The capital purpose of

ILS appliance analysis is to let centralized users acquaint locally, alike while

www.syngress.com

Advanced PIX Configurations • Chapter 4 165

registered to alfresco LDAP servers.This is done by analytical LDAP messages

traversing the firewall and assuming NAT aback necessary.There is no PAT

support, because alone IP addresses are stored on the server.When attempting

translation of an IP address, the PIX searches its centralized XLATE table first, then

DNAT tables. If neither contains the appropriate address, it is larboard unchanged.

NOTE

If you use alone nat 0 (that is, you do not use NAT) and do not accept DNAT

communications, ILS fixup can be angry off safely. Turning it off will

also advance the firewall’s performance.

The command to configure appliance analysis for ILS is as follows:

[no] fixup agreement ils [[-]]

The absence anchorage is 389 (standard LDAP port). As with all added configurable

inspection features, you can see the accepted agreement application the appearance fixup

command.

ILS/LDAP communications action on a client/server archetypal over TCP, so

there is no charge for any acting conduits to be opened by the PIX. During

client/server communications, the PIX monitors for ADD requests and

SEARCH responses, adaptation them with BER break functions; parses the

message for IP addresses; translates them as necessary; encodes the bulletin back,

and sends the accustomed packet to its destination.

Session Initiation Protocol cisco systems

Session Initiation Protocol

Session Initiation Agreement (SIP), authentic in RFC 2543, is addition agreement used

for affair ascendancy in VoIP. It additionally uses SDP, mentioned previously, to describe

each affair actuality established. Anniversary alarm is started with an INVITE message,

which contains some of the affair parameters, including IP addresses/ports for

the abutting connections, which may use added ports. SDP letters again are acclimated to

establish RTP datastreams.The antecedent SIP affair can use UDP or TCP as a

channel.The absence anchorage for this affiliation is 5060. Application analysis of

SIP over UDP is consistently on in the PIX and cannot be reconfigured.To change

the absence anchorage for TCP SIP connections, use the afterward command:

[no] fixup agreement sip [[-]]

Application analysis for SIP includes ecology of SIP and SDP messages,

changing the IP addresses of endpoints anchored central these letters (NAT

and PAT), and aperture acting conduits for all adjourned ascendancy connections

and datastreams based on the advice obtained.The PIX maintains an

internal database indexed by addition ID, sources, and destinations of anniversary call.

Included in this database are IP addresses and ports provided central an SDP message.

For example, a SIP bulletin may attending like the afterward (embedded address

negotiation is in italics; these are the best important ones, although it includes

much added IP information):

www.syngress.com

Advanced PIX Configurations • Chapter 4 163

INVITE sip:23198@192.168.2.10:5060 SIP/2.0

Expires: 180

Content-Type: application/sdp

Via: SIP/2.0/UDP 192.168.2.10:5060;branch=1FV1xhfvxGJOK9rWcKdAKOA

Via: SIP/2.0/UDP 10.0.1.134:5060

To:

From: sip:15691@10.0.1.134

Call-ID: c2943000-50405d-6af10a-382e3031@10.0.1.134

CSeq: 100 INVITE

Contact: sip:15691@10.0.1.134:5060

Content-Length: 219

User-Agent: Cisco IP Phone/ Rev. 1/ SIP enabled

Accept: application/sdp

Record-Route:

The SDP bulletin looks like the following:

v=0

o=CiscoSystemsSIP-IPPhone-UserAgent 17045 11864 IN IP4 10.0.1.134

s=SIP Call

c=IN IP4 10.0.1.134

t=0 0

m=audio 29118 RTP/AVP 0 101

a=rtpmap:0 pcmu/8000

a=rtpmap:101 telephone-event/8000

When the affair bureaucracy starts, the SIP affair is advised in a “transient”

state until an RTP anchorage has been adjourned for the datastream. If this does not

happen aural one minute, the affair is discarded. Afterwards the RTP datastream

ports are negotiated, the affair is advised alive and the SIP affiliation will

remain accustomed until the parties absolutely accomplishment the alarm or an inactivity

timeout expires.This abeyance can be configured application the afterward command:

timeout sip

The absence accompaniment of this abeyance is 30 minutes, which is agnate to the following

setting:

PIX1(config)# abeyance sip 0:30:0

www.syngress.com

164 Chapter 4 • Advanced PIX Configurations

RTP media admission are accountable to a absence abeyance of 2 minutes,

although this ambience can be afflicted application this command:

timeout sip_media

You can appearance the cachet of SIP, RTP, and any of the admission accountable to

application analysis by PIX application the command:

show conn state

You can specify the blazon of admission you appetite to appearance (for example, sip,

h323, rpc):

show conn accompaniment sip

NOTE

The PIX firewall supports PAT of SIP letters back adaptation 6.2. NAT

support has been accessible back adaptation 5.3.

One affair that could crave added agreement with SIP occurs back a

phone on a beneath defended interface tries to abode on authority a buzz on a added secure

interface.This activity is performed by the alfresco buzz sending an extra

INVITE bulletin to the central phone. If UDP is acclimated as transport, the PIX will

drop the admission packet afterwards the accepted UDP abeyance has expired.This situation

can be affected either by configuring an admission account on the alfresco interface

that permits packets to anchorage 5060/UDP on the central aperture or by application the

following command:

PIX1(config)# accustomed udp 5060 permitto udp 5060 permitfrom udp 0

This command tells the PIX to acquiesce entering UDP packets to anchorage 5060 on

a applicant if it had approachable advice from UDP anchorage 5060.