Troubleshooting Accouterments and Cabling

Troubleshooting Accouterments and Cabling

The best important affair to bethink in troubleshooting is to accouterment your

problems logically so you don’t absence any important apparatus or steps.You

must affirm the bloom of all the apparatus that accomplish up the firewall.When

addressing PIX firewall problems, you would be best served application the OSI model

to adviser your efforts.This archetypal was created to adviser development efforts in

networking by adding functions and casework into alone layers. Per the OSI

model, associate layers acquaint with anniversary other. For example, the arrangement layer

at one host communicates with the arrangement band at addition host.

The admission advocated in this affiliate is based on the OSI archetypal credible in

Figure 10.1. Problems are tackled starting at the everyman layer, such as validating

hardware and cabling at the concrete layer. Alone back the apparatus at the

lower band accept been accurate do you about-face your absorption to apparatus at a

higher layer.

Troubleshooting and Performance Ecology • Affiliate 10 555

Figure 10.1 The OSI Model

Provides the user/application

an interface into the network.

Converts and restores abstracts in a

format that can be transported

between arrangement devices.

Example protocols include

ASCII or EBCDIC.

Manages and synchronizes the

sessions amid devices.

Segments and reassembles data

for the Session and Arrangement l

ayers. Establishes connections

and provides breeze control.

Addresses and routes abstracts on

a network. IP and IPX are

examples of arrangement protocols.

OSPF, EIGRP, and added routing

protocols accomplish at this layer.

Assembles raw abstracts into

acceptable formats for the

Physical and the Arrangement layers.

802.3 and HDLC are example

protocols.

Addresses capacity of

connecting to physical

media such as 10BaseT cable.

Application

Presentation

Session

Transport

Network

Data Link

Physical

7

6

5

4

3

2

1

Access List

Conduit

NAT/PAT/Static

Global

IPsec/VPN

Routing

Hardware

Cabling

556 Affiliate 10 • Troubleshooting and Performance Monitoring

This affiliate organizes troubleshooting efforts by the OSI model. Initial

troubleshooting starts at Band 1, the concrete layer. Once all concrete components

have been validated, the troubleshooting focus is confused to the abstracts articulation layer

components, and so on, up the OSI stack.This controlled admission ensures that

we do not absence any angle of our aegis agreement area the botheration could

be.

Our aboriginal accomplish in troubleshooting alpha with concrete band issues. In the

context of the PIX firewall, concrete apparatus accommodate the firewall hardware

and cabling.We alpha our altercation with a quick overview of the PIX firewall

hardware architectonics and cabling.

This affiliate focuses on troubleshooting PIX firewalls. Once you accept mastered

its command syntax and basal firewall operations, the PIX is a almost simple

device to configure. Its library of commands is baby compared to that of Cisco

routers and switches. In antecedent chapters, we covered the PIX firewall in detail,

from the assorted models in the artefact band to simple and avant-garde configurations.

This book contains advice on how to accommodate the PIX firewall into

your absolute network. As acceptable as your PIX agreement is, problems will still

crop up, and you charge to apperceive how to boldness them.The purpose of this chapter

is to present a alignment that you can use to advance these problems and avoid

missing analytical troubleshooting steps.

Hardware and cabling problems can be a affliction to an contrarily well-functioning

network. A accouterments botheration becomes credible if you apperceive which indicators

to monitor.The bound cardinal of cable types that the PIX supports eases

our cable troubleshooting considerably.This affiliate provides abstruse information

about these cables so you can validate them.

The PIX firewall is an IP device. Granted, it is a awful specialized accessory that

performs basic aegis functions, but it is still an IP device. As such, it needs to

know area to accelerate traffic.We highlight some accepted connectivity problems

and how you can abode them. A admired action of the PIX firewall is its

ability to conserve IP abode amplitude and adumbrate arrangement capacity via Network

Address Translation (NAT). If you accept problems with NAT, you charge be able to

isolate and annihilate them.

The PIX firewall provides several admission ascendancy mechanisms, from simple

access lists to circuitous aqueduct statements.These admission mechanisms accept simultaneous

loose/tight backdrop in that assertive cartage is accustomed while added cartage is

denied.Your troubleshooting will not alone seek to boldness admission problems but

also acquisition the appropriate antithesis amid allowing and abstinent traffic.

Entire books accept been accounting on IPsec, and for acceptable reason. IPsec can protect

your cartage from end to end after accepting to be implemented at every hop

along the way. IPsec agreement can be complex.You charge be intimately

familiar with IPsec operations in adjustment to abutment and troubleshoot it.This chapter

covers several key aspects of IKE and IPsec to aid your ecology and support.

Capturing arrangement packets on the PIX firewall can accredit you to troubleshoot

more effectively.The PIX firewall offers several appearance that you can use to

capture cartage for assay and botheration isolation.Available accoutrement accommodate built-in PIX

commands as able-bodied as third-party accoutrement for arrangement abduction and packet decode.

www.syngress.com

www.syngress.com

How do you apperceive if your PIX firewall is assuming as able-bodied as it should? How

would you apperceive if it was overloaded? You charge to adviser firewall performance

and bloom proactively.The ambition of ecology is to anticipate accessory glitches from

turning into above problems.The achievement of your ecology efforts can be quite

dense and arcane, so you charge to apperceive how to adapt what you are monitoring.

Cisco Router, Cisco System Builds, Cisco Logo Picures




Monitoring and Disconnecting Sessions

Monitoring and Disconnecting Sessions
cp10

Several CLI commands are attainable to adviser and abstract administrative

sessions.To adviser and abstract PDM sessions, use the appearance pdm sessions

command.This command displays all alive PDM sessions, including the session

IDs and the PDM clients’ IP addresses.To abstract a PDM session, use the

pdm abstract command, area the session_id refers to the identification

number listed in the appearance pdm sessions command.

You can additionally use the bright pdm command to abolish all PDM locations, disable

PDM logging, and bright the PDM centralized buffer.Although the bright pdm,

pdm history, pdm location, and pdm logging commands arise in your configuration

and are attainable through the CLI, they are advised as centralized PDM-to-PIX

firewall commands attainable through PDM.

www

Summary

As you accept apparent in this chapter, PDM is a awful able graphical interface for

managing the PIX firewall. In accession to accouterment about all CLI functionality,

PDM includes several appearance to added abridge the advancing aliment and

operations firewall administrators and aegis action makers perform. Because

PDM is Java based and runs as a alive applet over an SSL-encrypted browser

session, administrators can use it deeply from any accustomed client.This remote

management adequacy can be awful admired in large, broadcast environments.

Of the all-inclusive PDM functionality, conceivably best able are the PDM wizards,

which accommodate the Startup Astrologer and the VPN Wizard. Application these tools, administrators

are guided application alternate prompts through the often-complex process

of architecture PIX configurations and VPN adit services.

In accession to the astrologer functionality, PDM facilitates abounding agreement of

PIX firewall access,AAA, filter, NAT rules, logging, user accounts, and IDS configurations.

This functionality includes the adeptness to administer complex, grouped

services and arrangement objects, which is new functionality in the PIX firewall

software.

The PDM GUI is automatic and able-bodied organized and helps anticipate accidental

syntax and agreement errors that could account the firewall to fail. Moreover,

PDM can be acclimated as a CLI acquirements apparatus for administrators who are not completely

proficient with the PIX firewall command band by previewing all

commands beatific to the PIX.

PDM additionally includes able real-time blueprint and advertisement functionality.This

tool helps firewall administrators accept the actual and accepted performance

and functionality of the PIX. Furthermore, the IDS graphical reporting

available through PDM can accommodate important acumen into the abeyant security

risks airish to organizations.

Whether you are managing a distinct PIX firewall, bristles bombastic PIX pairs,

or 50 accumulated firewalls, PDM is a accessible and able apparatus for firewall

administrators.

www.syngress.com

PIX Device Manager • Affiliate 9 549

Solutions Fast Track

Features, Limitations, and Requirements

 PDM 2.1 is accurate on all PIX 501, PIX 506/506E, PIX 515/515E,

PIX 520, PIX 525, and PIX 535 platforms alive PIX firewall software

version 6.2 or college as able-bodied as the FWSM 1.1.

 Some CLI commands abate PDM functionality to monitor-only mode.

 PDM is a alive Java applet downloaded to the applicant apparatus through

a adjustable browser.Therefore, PDM is attainable from any compliant

and accustomed applicant workstation for firewall management.

Installing, Configuring, and Launching PDM

 You charge admission and install a Abstracts Encryption Standard (DES) or

3DES activation key on the PIX afore PDM will function.

 PDM can be installed on the PIX firewall in a action agnate to that of

a PIX software angel upgrade.

 You can accredit specific IP addresses or networks for admission via PDM

using the http command.

Configuring the PIX Firewall Application PDM

 Administrators can use the VPN Astrologer to body IPsec, L2TP, and PPTP

tunnels.

 Object groups for casework or arrangement entities can be created and

managed application PDM on the PIX firewall.

 Use the Reset PIX to the Factory Default Agreement advantage from

the File drop-down card on the PIX 501 and 506 platforms to return

the PIX firewall to its aboriginal configuration.

 Rule sets can calmly be rearranged from the Admission Rules tab application the

cut-and-paste functionality of the PDM Rules drop-down menu, the

toolbar buttons, or the right-click abrasion menu.

www.syngress.com

550 Affiliate 9 • PIX Device Manager

 To set up a syslog logging host, use the Logging class attainable from

the PDM Arrangement Properties tab.

Monitoring the PIX Firewall Application PDM

 Administrators can admittance monitor-only admission to accumulated admiral or

other VIP users so that they may appearance actual and current

performance abstracts on the PIX firewall.

 Real-time IDS contest and achievement abstracts can be displayed application the

monitoring functionality of PDM.

 Administrators can accomplish avant-garde troubleshooting techniques using

the assorted ecology graphs such as interface and arrangement graphs.

 Authoritative admission (Telnet, SSH, and PDM sessions) can be monitored

using PDM.

 SSH and PDM sessions can be concluded in absolute time through the

PDM ecology functionality.

 VPN connections, including IPsec, L2TP, and PPTP tunnels, are

available for ecology via the VPN Affiliation Graphs class from

the PDM Ecology tab.

 To appearance ecology statistics with PDM, you charge aboriginal accredit History

Metrics from the Arrangement Properties tab.

 Up to four graphs from assorted categories can be aggregate calm for

a added absolute beheld representation of PIX firewall metrics.

Monitoring and Disconnecting Sessions

 Use the appearance pdm sessions and appearance ssh sessions commands to appearance realtime

administrative admission to the firewall.

 To appearance alive PDM sessions, use the appearance pdm sessions command.

 To abolish alive PDM sessions, use the pdm abstract

command.

www.syngress.com

PIX Device Manager • Affiliate 9 551

Q: Can I adviser and administer alien PIX firewalls application PDM from a central

facility or added offsite locations?

A: Yes. Application the http command via the CLI or PDM, you can accredit an IP

range or a specific IP abode for admission to PDM.The PDM affiliation is

encrypted for security.

Q: Can I set up AAA for authoritative connectivity to the PIX firewall using

PDM?

A: Yes. PDM includes abounding AAA agreement functionality. Additionally, you can

use PDM to configure the PIX for AAA casework for PDM itself.

Q: Can I use PDM to abstract a user affiliated to the PIX firewall via

Telnet?

A: No. Currently, the abstract affection is alone attainable for PDM and SSH

sessions.

Q: Do I charge a appropriate authorization to accredit PDM on my PIX firewall?

A: Yes.You charge a DES or 3DES activation key from Cisco afore PDM will

function properly.A 56-bit DES key is attainable free.The 168-bit 3DES key is

available from Cisco at an added cost.

Q: Does PDM accommodate VPN aliment functionality?

A: Yes.VPN aliment functionality is attainable in PDM. Additionally, PDM

includes VPN functionality not present in the CLI, such as the VPN Wizard.

Q: Can I use PDM to administer assorted PIX firewalls at once?

A: Yes, but a abstracted instance of PDM charge be launched for anniversary firewall.

Interface Graphs cisco

Interface Graphs

The final class of graphs accessible from the Ecology tab in PDM is

Interface Graphs. A subcategory apery anniversary alive interface on the PIX

firewall appears in the Interface Graphs category. From anniversary specific interface

subcategory, 10 graphs are available:

 Packet Rates

 Bit Rates

 Byte Counts

 Packet Counts

www.syngress.com

Figure 9.86 IDS Graphs

PIX Device Manager • Chapter 9 545

 Absorber Resources

 Packet Errors

 Miscellaneous (Received Broadcasts)

 Blow Counts

 Ascribe Queue

 Output Queue

Each of these graphs can be badly accessible in troubleshooting performance

issues or misconfigurations such as bifold mismatches, concrete cabling

issues, or anchorage agreement problems.

For instance, if you accept you are experiencing cessation with cartage passing

through the PIX firewall, you could assemble a set of graphs such as the one

shown in Figure 9.87.

www.syngress.com

Figure 9.87 Interface Graphs

546 Chapter 9 • PIX Device Manager

With this set of graphs, you can visually characterize the absolute cardinal of collisions,

buffer ability overruns, ascribe chain blocks used, and assorted packet errors for

the accomplished bristles days. If you are seeing aerial absorber overruns and blow counts, the

interfaces on the PIX ability be saturated with traffic. Perhaps the PIX anamnesis is

at 100 percent utilization. Alternatively, aerial packet errors for assorted attributes

such as runts or ascribe errors could arresting concrete cabling issues.

To verify accessible causes, you could use this set of graphs with additional

graphs such as those depicted in Figure 9.88.

This aggregate of graphs shows interface byte counts for both interfaces

as able-bodied as CPU and anamnesis appliance over a aeon of bristles days.These graphs,

in aggregate with the ahead apparent interface graphs, can advice diagnose

various problems associated with PIX performance.

You accept baffled the ability of PIX monitoring, so now let’s attending at some

connectivity ascendancy mechanisms accessible through the Ecology tab and the

PIX CLI.

Miscellaneous Graphs cisco

Miscellaneous Graphs

The Miscellaneous Graphs class includes the IDS subcategory.This subcategory

can accommodate advice accompanying to the assorted IDS capabilities imbedded on

the PIX firewall. As apparent in Figure 9.85, 16 altered graphs are accessible from

the IDS subcategory.

Using the IDS graphs, you can adviser in absolute time abeyant threats to your

network. For instance, Figure 9.86 depicts ICMP,TCP, and UDP attacks graphically

and updates every 10 seconds.

www.syngress.com

Figure 9.85 Miscellaneous Graphs Setup

544 Chapter 9 • PIX Device Manager

In this instance, no attacks accept been detected on the PIX firewall. As you

can see, assorted advance vectors are depicted in anniversary blueprint specific to the protocol

represented.