CBAC-Supported Protocols

CBAC-Supported Protocols

CBAC can be enabled to audit all TCP and UDP sessions, behindhand of the application-layer protocol. This

method is alleged single-channel, or generic, TCP/UDP inspection. For TCP/UDP all-encompassing analysis to work, the

return cartage charge accept the aforementioned source/destination IP abode and anchorage numbers. It charge additionally be aural the

sequence cardinal window. If the anchorage cardinal changes, the packet will be dropped.

In addition, CBAC can accurately audit alone application-layer protocols to advance the connection

information for anniversary session. Application-layer agreement analysis takes antecedence over the TCP or UDP

protocol inspection. The afterward application-layer protocols are accurate and can be configured for CBAC

inspection:

CU-SeeMe

FTP

H.323 (such as NetMeeting)

HTTP (Java blocking)

ICMP

Microsoft NetShow

RealAudio

RTSP (Real-Time Streaming Protocol)

RPC (Sun RPC, not DCE RPC)

SMTP (Simple Mail Transport Protocol)

ESMTP (Extended Simple Mail Transport Protocol)

SQL*Net

StreamWorks

TFTP

UNIX R-commands (such as rlogin, rexec, and rsh)

VDOLive

Dynamic ACL Entries

Dynamic ACL Entries

As discussed earlier, CBAC uses the affiliation advice from the affair table to accessible activating holes in the

firewall admission account for the abiding cartage (that would commonly be blocked). CBAC dynamically adds and

removes admission account entries at the firewall interfaces. These acting openings are created in accordance with

the accompaniment table for all inspected cartage that originates from an centralized (protected) arrangement outbound against the

unprotected area through the firewall. The purpose of these admission account entries is to appraise cartage abounding back

into the centralized network. These entries actualize acting openings in the firewall to admittance alone cartage that is

part of a permissible session. Example 5-2 shows a activating ACL admission (corresponding to Example 5-1) that

permits abiding Telnet cartage accomplished by a host from the centralized network.

Example 5-2. Activating ACL Admission Agnate to the Accompaniment Table

Router# appearance ip access-lists

Extended IP admission account 101

permit tcp host 20.1.1.1 eq telnet host 10.1.1.1 eq 11006 (16 matches)

permit tcp any host WebServer eq http

deny ip any any (12 matches)

Note

The dynamically created admission account entries that acquiesce abiding cartage are acting and are not saved

to the nonvolatile random-access anamnesis (NVRAM).

UDP Connections

UDP Connections

UDP is a connectionless transport-layer protocol; hence, there is no accompaniment advice accessible to clue the flow

of the connections. CBAC deals with UDP sessions by analytical the advice in the packet and determining

whether the packet is agnate to the UDP packet exited earlier. Returning UDP packets are arrested aural the

idle abeyance aeon to ensure that they accept the agnate source/destination IP addresses and port

numbers.

Timeout and Beginning Values

Timeout and Beginning Values

CBAC uses several abeyance and beginning ethics to administer affair accompaniment information. These ethics help

determine back to bead sessions that do not become absolutely established. This additionally helps to chargeless up system

resources, bottomward sessions afterwards a defined bulk of abandoned time. CBAC sends a displace bulletin for all dropped

sessions to both abandon (source and destination) of the session. The arrangement accepting the displace bulletin releases

the abridged affiliation from its process, thereby allowance the ability allocation table.

CBAC monitors the thresholds in the afterward three ways:

The absolute cardinal of half-open TCP or UDP sessions

The cardinal of half-open sessions based on time

The cardinal of per-host half-open TCP sessions

Packet Inspection

Packet Inspection

CBAC performs per-protocol inspection. Each agreement that requires analysis is alone enabled, and an

interface and interface administration (in or out) is defined area analysis originates. Alone the defined protocols

will be inspected by CBAC. All added protocols abide uninterrupted, accountable to added router processes—for

example, NAT, routing, and ACL.

Packets entering the firewall are accountable to analysis alone if they aboriginal canyon the entering admission account at the input

interface and outbound admission account at the achievement interface. If a packet is denied by the admission list, the packet is

simply alone after CBAC analysis performed.

For TCP agreement inspection, CBAC keeps clue of arrangement numbers in all TCP packets. Packets with sequence

numbers that are not aural the accepted ranges are dropped.