Article Sphere Logo
 
Main Article Categories
 Alternative Medicine
 Arts And Entertainment
 Automotives
 Beauty
 Business
 Communications
 Computer And Technology
 Disease And Illness
 Finance
 Food And Beverage
 Health And Fitness
 Home And Family
 Home Based Business
 Insurance
 Internet And E-Business
 Legal
 News And Society
 Pets And Animals
 Product Reviews
 Real Estate
 Recreation And Sports
 Reference And Education
 Self Improvement
 Shopping
 Travel And Leisure
 Women Health And Fitness
 Women Interests And Issues
 Work At Home
 Writing And Speaking
 All 511 Categories
 
"Computer And Technology" Article
 Article Directory Home Computer And Technology

Cisco CBAC: - The Poor Mans Firewall

By Expert Author: Nicholas Evra
View Summary | Submitted: 2008-06-21 | Word Count: 491 words
Nicholas Evra
CBAC Overview

The Cisco IOS Firewall Feature Set is a module that can be added to the existing IOS to provide firewall functionality without the need for hardware upgrades. There are two components to the Cisco IOS Firewall Feature Set in Intrusion Detection (which is an optional bolt-on) and Context-Based Access Control (CBAC). CBAC maintains a state table for all of the outbound connections on a Cisco router by inspecting tcp and udp connections at layer seven of the OSI model and populating the table accordingly. When return traffic is received on the external interface it is compared against the state table to see if the connection was originally established from within the internal network, and then either permitted or denied. Although basic this is a very effective mechanism to prevent unauthorized access to the internal network from external sources such as the internet.

CBAC Application-specific support

Cisco have also built in some additional functionality into CBAC in terms of application-specific inspection that enables the router to recognize and identify application specific data flows such as HTTP, SMTP, TFTP, and FTP. Understanding these applications and their data flows empowers the router to identify malformed packets or suspect application data flows and permit or deny accordingly. CBAC also provides the flexibility of downloading Java code from trusted sites, but it denying untrusted sites.

CBAC and Denial of Service (DOS) Attacks

Denial-Of-Service (DOS) attack protection is also in-built with real-time logging of alerts as well as pro-active responses to mitigate the threat. To do this CBAC can be configured to manage half-open TCP connections which are used in TCP SYN flood attacks to overload a targets resources resulting in a denial of service to legitimate users. To do this CBAC uses timeouts and thresholds, which are configurable, to determine how long state information for each connection should be kept for sessions and when to drop them. Note that UDP and ICMP require that an idle-timer limit is used to determine when a connection should be terminated. A very useful command to identify a DOS attack is ‘ip inspect audit-trail’ which logs all DOS connections including source and destination IP address and TCP or UDP ports allowing you to pin-point the exact source and destination of the attack.

Configuring CBAC

There are five steps to configuring CBAC on a Cisco router in order for it to function correctly. These are as follows:

1. Choose an interface to which inspection will be applied. This can be an internal or external interface as CBAC is only concerned with the direction of the first packet initiating the connection which is identified when applying CBAC to an interface.

2. Configure an IP access list in the correct direction on the selected interface to allow traffic through for CBAC to inspect.

3. Configure global timeouts and thresholds for established connections or sessions.

4. Define an inspection rule specifying exactly which protocols will be inspected by CBAC.

5. Apply the inspection rule to the interface in the correct direction.
About the Author/Author Bio

Nicholas Evra is a Senior IT Consultant for a Professional Services IT Organisation based in London, UK. As well as designing and developing network and security solutions for clients, Nicholas also regularly contributes technical tips and articles on Networkblue.net. Networkblue.net is a technical resource for novices and expert’s alike providing free articles and tips on numerous cisco topics such as Cisco’s CBAC and other network security topics.

Article Source: http://www.articlesphere.com/Article/Cisco-CBAC----The-Poor-Mans-Firewall/148924

More "Computer And Technology" Related Articles

 

Listed below are more articles related to the above article from the "Computer And Technology" article category.

People interested in the above article "Cisco CBAC: - The Poor Mans Firewall" are also interested in the related articles listed below:

In today’s rapidly changing and evolving markets computerized accounting and management systems are a must for any self-respecting company regardless of the field of activity or the objectives they may have. Computer consultancy assists with managed hosting for your domain, hardware/software upgrades, professional diagnosis and the resolution of software, hardware, and networking problems.
A printer outputs data that is seen on the computer screen. This is necessary to give you a "hard copy" or printed output of the information on your files in the computer. Basically there are two different types of printers are in use these days. First laser printer that utilizes a laser beam to produce an image on a drum, second inkjet printers that create characters and images by spraying fine streams of ink onto paper at high speeds.
An overview to understanding the terminology used for server racks and in the server racking industry. Way too many people don't know these simple terms and it's costing them money. Have you ever been tasked to find storage for servers? Well, if you have you will know how frustrating it can be, especially with all the different terminology. When you are looking for server storage, you get a mixture of conflicting information, the racks are called 19” rack mount racks, the width and depth is in millimetres and the mounting post’s are in U’s.
WAP allows service providers to separate the content and only send to the mobile handset the information the user needs. The possibilities of WAP are enormous. Basically, anything you can do on the Internet can now be accessed via your WAP cell phone.
Databases provide a convenient means of storing vast amounts of information, allowing the information to be sorted, searched, viewed, and manipulated according to the business needs and
goals.
The image sensor is a core component in camcorders, digital still cameras and wireless security cameras. The type of sensor used has dramatic effects on the quality, reliability, and price of the device. Here is the main differences between CCD and CMOS image sensors.
Bluetooth is such a unique kind of device which provides the facilities like low-cost wireless communications, networking between PCs, mobile phones and other devices. Bluetooth presents the “Low Bandwidth Wireless Connections” as the most feasible usage of the tool that it can easily be incorporated into daily life. Bluetooth would offer wireless connection between the Internet and other concerning devices. Bluetooth are operating these days in the “Global Radio-Frequency Standards” that functions at frequency 2.4 GHz ISM band and providing license-free operation in the United States and most of the other countries of the world.
Article Directory Home Computer And Technology

Can't find what you're looking for? Try Google Search!
(Search in 23 languages: English, Spanish, Japanese, Arabic, Italian, German,
Chinese Simplified, Chinese Traditional, Dutch, Korean, Portuguese, Russian, Greek,
Swedish, Romanian, Polish, Norwegian, Finnish, Danish, Czech, Croatian, Bulgarian)
 
 
Copyright © 2005 - by Larry Lim, Singapore - Article Search Engine Directory at ArticleSphere.com™
All Rights Reserved Worldwide. All Trademarks and Servicemarks are the property of the respective owners.
Template Design by Internet Marketing Singapore | Internet Marketing
Français Español 日本語 [أربيك] Italiano Deutsch 汉语 漢語 Nederlands 한국어 PortРусско
Ελληνικά Swedish Indo Romanian Polish Norwegian Hindi Finnish Danish Czech Croatian Bulgarian English - Original language