Local Area Networks / Laboratory
LABORATORY 06

Access lists and NAT

Duration: 2 hours Platform: the workbench in this page, or Packet Tracer Background: lectures 7 and 9 PDF: download the notes RO versiunea română

The security policy of a company is written in words, but the network understands only rules. This exercise makes the translation: five requirements stated by management become access lists, placed correctly on interfaces and in directions. Then the whole company reaches the Internet - on a single public address.

1How an access list is read

An access list is a list of rules, traversed from top to bottom, until the first match. Whatever matches first decides, and the rest of the list is not even read. At the end, if nothing matched, there is an invisible deny that discards the packet.

standard list
It sees only the source address. It is numbered 1–99. Useful when you want to say "from these hosts, nowhere" or "only from these hosts". It is placed as close as possible to the destination, precisely because it does not know what the destination is.
extended list
It sees the source, the destination, the protocol and the port. It is numbered 100–199, or is given a name. It is placed as close as possible to the source, so that forbidden traffic does not consume the network for nothing.
wildcard mask
The inverse of the network mask: 0 means "this bit must match", 1 means "anything". For a /24 network you write 0.0.0.255. Shortcuts: host 10.1.10.5 means 10.1.10.5 0.0.0.0, and any means 0.0.0.0 255.255.255.255.
the direction
in filters the packets that enter the router on that interface, before routing. out filters the packets that leave, after routing. The same list on the same interface, but in different directions, does completely different things.
Three mistakes that are made every single time 1. The order. A general rule placed above a specific one makes the second useless - it will never match.
2. The implicit deny. A list containing only deny rules blocks absolutely everything, including what you meant to permit.
3. The direction. The right list, applied in the wrong direction, never sees the traffic it was meant to filter - and its counter stays at zero.

2Equipment needed

QtyEquipmentModelPacket Tracer categoryWhat it is for here
2Router4331Network Devices → RoutersR-FIRMA (the edge router) and ISP
1Switch2960Network Devices → SwitchesSW1, with three VLANs
3ComputerPC-PTEnd Devicesone test host per department
2ServerServer-PTEnd DevicesSRV-WEB in the DMZ and "the Internet" (8.8.8.8)
1Serial cableSerial DCEConnectionsR-FIRMA ↔ ISP
6Straight cableCopper Straight-ThroughConnectionsthe remaining links

The topology takes up the structure of laboratory 3: three VLANs on SW1, a trunk to the router, subinterfaces on G0/0/0. The DMZ is attached to a separate physical interface, G0/0/1.

3The topology and the policy

ADMIN 10.1.10.0/24 BIROURI 10.1.20.0/24 OASPETI 10.1.30.0/24 SW13 VLANs R-FIRMAG0/0/0 trunk SRV-WEB10.1.40.10 · DMZ ISP203.0.113.2 Internet8.8.8.8 203.0.113.0/30 public block: 203.0.113.32/29 The company has a single public block of 8 addresses. All the rest is private.
Fig. 1 - The network of the company, with three internal segments, a demilitarized zone and a single way out to the Internet.
SegmentVLANNetworkGatewayTest host
ADMIN1010.1.10.0/2410.1.10.1PC-ADM 10.1.10.11
BIROURI2010.1.20.0/2410.1.20.1PC-BIR 10.1.20.11
OASPETI3010.1.30.0/2410.1.30.1PC-OSP 10.1.30.11
DMZ-10.1.40.0/2410.1.40.1SRV-WEB 10.1.40.10
The link to the ISP-203.0.113.0/30-R-FIRMA .1, ISP .2
Public block allocated-203.0.113.32/29-.33 – .38 usable
The security policy, as management stated it
P1. Guests have access to the Internet and to the web server in the DMZ, but to no other internal resource.
P2. The offices have access everywhere, except to the ADMIN segment.
P3. The web server in the DMZ is not allowed to initiate connections towards the internal network. It may only answer.
P4. The router may be administered through SSH only from the hosts in ADMIN.
P5. The web server must be reachable from the Internet, at a fixed public address.

4The workbench

5Step 0: a working network, with no filters

Before filtering anything, everything must work. It is a discipline that is hard to learn, but it saves hours: if you apply ACLs on top of a network that does not work, you will never know which problem belongs to which.

  1. VLANs on the switch
    on SW1
    Switch> enable
    Switch# configure terminal
    Switch(config)# hostname SW1
    SW1(config)# vlan 10
    SW1(config-vlan)# name ADMIN
    SW1(config-vlan)# vlan 20
    SW1(config-vlan)# name BIROURI
    SW1(config-vlan)# vlan 30
    SW1(config-vlan)# name OASPETI
    SW1(config-vlan)# exit
    
    SW1(config)# interface fastEthernet 0/1
    SW1(config-if)# switchport mode access
    SW1(config-if)# switchport access vlan 10
    SW1(config-if)# exit
    SW1(config)# interface fastEthernet 0/2
    SW1(config-if)# switchport mode access
    SW1(config-if)# switchport access vlan 20
    SW1(config-if)# exit
    SW1(config)# interface fastEthernet 0/3
    SW1(config-if)# switchport mode access
    SW1(config-if)# switchport access vlan 30
    SW1(config-if)# exit
    
    SW1(config)# interface gigabitEthernet 0/1
    SW1(config-if)# switchport mode trunk
    SW1(config-if)# end
    
  2. Router-on-a-stick, the DMZ and the way out to the ISP
    on R-FIRMA
    Router(config)# hostname R-FIRMA
    
    R-FIRMA(config)# interface gigabitEthernet 0/0/0
    R-FIRMA(config-if)# no ip address
    R-FIRMA(config-if)# no shutdown
    R-FIRMA(config-if)# exit
    
    R-FIRMA(config)# interface gigabitEthernet 0/0/0.10
    R-FIRMA(config-subif)# encapsulation dot1Q 10
    R-FIRMA(config-subif)# ip address 10.1.10.1 255.255.255.0
    R-FIRMA(config-subif)# exit
    R-FIRMA(config)# interface gigabitEthernet 0/0/0.20
    R-FIRMA(config-subif)# encapsulation dot1Q 20
    R-FIRMA(config-subif)# ip address 10.1.20.1 255.255.255.0
    R-FIRMA(config-subif)# exit
    R-FIRMA(config)# interface gigabitEthernet 0/0/0.30
    R-FIRMA(config-subif)# encapsulation dot1Q 30
    R-FIRMA(config-subif)# ip address 10.1.30.1 255.255.255.0
    R-FIRMA(config-subif)# exit
    
    R-FIRMA(config)# interface gigabitEthernet 0/0/1
    R-FIRMA(config-if)# description DMZ
    R-FIRMA(config-if)# ip address 10.1.40.1 255.255.255.0
    R-FIRMA(config-if)# no shutdown
    R-FIRMA(config-if)# exit
    
    R-FIRMA(config)# interface serial 0/1/0
    R-FIRMA(config-if)# ip address 203.0.113.1 255.255.255.252
    R-FIRMA(config-if)# clock rate 128000
    R-FIRMA(config-if)# no shutdown
    R-FIRMA(config-if)# exit
    
    R-FIRMA(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.2
    R-FIRMA(config)# end
    
    on ISP
    Router(config)# hostname ISP
    ISP(config)# interface serial 0/1/0
    ISP(config-if)# ip address 203.0.113.2 255.255.255.252
    ISP(config-if)# no shutdown
    ISP(config-if)# exit
    ISP(config)# interface gigabitEthernet 0/0/0
    ISP(config-if)# ip address 8.8.8.1 255.255.255.0
    ISP(config-if)# no shutdown
    ISP(config-if)# exit
    ISP(config)# ip route 203.0.113.32 255.255.255.248 203.0.113.1
    ISP(config)# end
    

    Notice what the ISP does not have: any route towards the private networks of the company. That is precisely the point of NAT, which we configure at the end.

  3. Fill in the reference table

    From every internal host, ping all the others and also SRV-WEB and the Internet. Everything must work. Note the results - it will be the reference against which you check the effect of each list.

    From \ toADMINBIROURIOASPETIDMZInternet
    ADMIN-
    BIROURI-
    OASPETI-
    DMZ-

6Translating the policy into rules

Each policy is translated by answering, in order, three questions: what kind of list I need, on which interface I put it and in which direction.

P1 - The guests

The analysis, before the command

The source is always the same (10.1.30.0/24), but the destination decides whether the traffic is permitted or not. A standard list sees only the source, so it cannot express the policy. We need an extended list.

The placement: an extended list is put as close as possible to the source, hence on the G0/0/0.30 subinterface, direction in - the forbidden traffic does not even get as far as being routed.

P1 on R-FIRMA
R-FIRMA(config)# ip access-list extended OASPETI-IN
R-FIRMA(config-ext-nacl)# remark permit access to the web server in the DMZ
R-FIRMA(config-ext-nacl)# 10 permit tcp 10.1.30.0 0.0.0.255 host 10.1.40.10 eq 80
R-FIRMA(config-ext-nacl)# remark block every other internal resource
R-FIRMA(config-ext-nacl)# 20 deny ip 10.1.30.0 0.0.0.255 10.0.0.0 0.255.255.255
R-FIRMA(config-ext-nacl)# remark the rest, that is the Internet, is permitted
R-FIRMA(config-ext-nacl)# 30 permit ip 10.1.30.0 0.0.0.255 any
R-FIRMA(config-ext-nacl)# exit

R-FIRMA(config)# interface gigabitEthernet 0/0/0.30
R-FIRMA(config-subif)# ip access-group OASPETI-IN in
R-FIRMA(config-subif)# end

Now test, from PC-OSP:

TestResultWhy
ping 10.1.10.11blockedrule 20: destination in 10.0.0.0/8
ping 10.1.40.10blockedrule 20 again - rule 10 permits only TCP port 80, and ping is ICMP
ping 8.8.8.8permittedrule 30: any other destination
The second row is worth reading twice The web server is reachable by the guests - but only on port 80. A ping towards it fails, and it is right that it should fail: the policy said "access to the web server", not "access to the server". An extended list makes exactly that distinction, and a test with ping would mislead you into thinking the rule does not work.

The order of the three rules is the whole solution. Rule 10 is more specific than 20, so it must be above it; rule 30 is the most general and closes the list. Swap rules 10 and 30 and test again: you will see exactly how the policy breaks.

P2 - The offices

P2
R-FIRMA(config)# ip access-list extended BIROURI-IN
R-FIRMA(config-ext-nacl)# 10 deny ip 10.1.20.0 0.0.0.255 10.1.10.0 0.0.0.255
R-FIRMA(config-ext-nacl)# 20 permit ip 10.1.20.0 0.0.0.255 any
R-FIRMA(config-ext-nacl)# exit
R-FIRMA(config)# interface gigabitEthernet 0/0/0.20
R-FIRMA(config-subif)# ip access-group BIROURI-IN in

Check: the offices no longer reach ADMIN, but do reach the DMZ and the Internet. Check the reverse direction as well - from PC-ADM towards PC-BIR: it works, because the list is applied only to the traffic that enters from the offices.

P3 - The DMZ does not initiate

The analysis

"It may only answer" means that traffic from the DMZ towards the inside is permitted only if it is part of a conversation started from the inside. A classic ACL cannot express that - it sees packets, not connections. The minimal solution is the keyword established.

P3
R-FIRMA(config)# ip access-list extended DMZ-IN
R-FIRMA(config-ext-nacl)# 10 permit tcp host 10.1.40.10 10.0.0.0 0.255.255.255 established
R-FIRMA(config-ext-nacl)# 20 deny ip host 10.1.40.10 10.0.0.0 0.255.255.255
R-FIRMA(config-ext-nacl)# 30 permit ip host 10.1.40.10 any
R-FIRMA(config-ext-nacl)# exit
R-FIRMA(config)# interface gigabitEthernet 0/0/1
R-FIRMA(config-if)# ip access-group DMZ-IN in
The limits of established It checks only the ACK and RST bits of the TCP header, so a packet forged with ACK set gets through. It does not work for UDP and ICMP. In a real network, a stateful firewall or a reflexive ACL, with reflect and evaluate, would be used here.

P4 - Administrative access

Traffic towards the VTY lines of the router is not filtered on an interface, but directly on the lines, with access-class. Here a standard list is enough: all that matters is where the connection comes from.

P4
R-FIRMA(config)# ip domain-name firma.local
R-FIRMA(config)# crypto key generate rsa
R-FIRMA(config)# username admin privilege 15 secret Admin123
R-FIRMA(config)# access-list 10 remark only the ADMIN hosts
R-FIRMA(config)# access-list 10 permit 10.1.10.0 0.0.0.255

R-FIRMA(config)# line vty 0 4
R-FIRMA(config-line)# transport input ssh
R-FIRMA(config-line)# login local
R-FIRMA(config-line)# access-class 10 in
R-FIRMA(config-line)# exec-timeout 5 0

Check your understanding

The OASPETI-IN list, tested on five packets

The last packet is important: it comes from BIROURI, so it matches no rule of this list and falls on the implicit deny. It has no consequence at all, though - the list is applied on G0/0/0.30, and that packet never passes there. An ACL matters only where it is applied.

7The counter, the best troubleshooting instrument

checking
R-FIRMA# show access-lists
R-FIRMA# clear access-list counters

The output shows, for each rule, how many times it matched:

what should appear
Extended IP access list OASPETI-IN
    10 remark permit access to the web server in the DMZ
    20 permit tcp 10.1.30.0 0.0.0.255 host 10.1.40.10 eq 80
    40 deny ip 10.1.30.0 0.0.0.255 10.0.0.0 0.255.255.255 (8 match(es))
    60 permit ip 10.1.30.0 0.0.0.255 any (4 match(es))
How it is read If a rule has zero matches, the traffic does not reach it: either the list is on the wrong interface, or in the wrong direction, or a rule above it already catches the traffic. If it has matches but the result is not the one you wanted, then the rule is written wrongly. The two cases are repaired in completely different ways, and the counter tells you which one you are in.

Now fill in the connectivity table of section 5 again and compare with the reference. Every cell that has changed must correspond to a policy - if something unforeseen has changed, you have a rule that is too broad.

8NAT: the way out to the Internet

All the internal addresses are private, hence unroutable on the Internet. The ISP does not even have routes towards them. We need translation.

  1. Mark the interfaces
    every interface is either "inside" or "outside"
    R-FIRMA(config)# interface gigabitEthernet 0/0/0.10
    R-FIRMA(config-subif)# ip nat inside
    R-FIRMA(config-subif)# exit
    R-FIRMA(config)# interface gigabitEthernet 0/0/0.20
    R-FIRMA(config-subif)# ip nat inside
    R-FIRMA(config-subif)# exit
    R-FIRMA(config)# interface gigabitEthernet 0/0/0.30
    R-FIRMA(config-subif)# ip nat inside
    R-FIRMA(config-subif)# exit
    R-FIRMA(config)# interface gigabitEthernet 0/0/1
    R-FIRMA(config-if)# ip nat inside
    R-FIRMA(config-if)# exit
    R-FIRMA(config)# interface serial 0/1/0
    R-FIRMA(config-if)# ip nat outside
    R-FIRMA(config-if)# exit
    

    Without these markings, NAT does absolutely nothing - however correct the rules are. It is the first thing to check when "NAT does not work".

  2. PAT for all the internal hosts
    PAT with the address of the outgoing interface
    R-FIRMA(config)# access-list 100 remark what gets translated
    R-FIRMA(config)# access-list 100 permit ip 10.1.10.0 0.0.0.255 any
    R-FIRMA(config)# access-list 100 permit ip 10.1.20.0 0.0.0.255 any
    R-FIRMA(config)# access-list 100 permit ip 10.1.30.0 0.0.0.255 any
    
    R-FIRMA(config)# ip nat inside source list 100 interface serial 0/1/0 overload
    

    Here is the second use of access lists, promised in lecture 7: here the list filters nothing - it merely describes the traffic that must be translated. The same syntax, a different role.

  3. Static NAT for the web server (P5)
    a fixed public address for SRV-WEB
    R-FIRMA(config)# ip nat inside source static 10.1.40.10 203.0.113.33
    

    Test from "the Internet": from the NET server, ping 203.0.113.33 - the server in the DMZ answers. And ping 10.1.40.10 from there does not work and cannot: the private address does not exist on the Internet.

    Alternatively, if you want to publish only port 80 and keep the public address for something else:

    port forwarding
    R-FIRMA(config)# ip nat inside source static tcp 10.1.40.10 80 203.0.113.1 80
    
  4. See the translation with your own eyes
    checking NAT
    R-FIRMA# show ip nat translations
    R-FIRMA# show ip nat statistics
    R-FIRMA# clear ip nat translation *
    

    In the workbench in this page: issue ping 8.8.8.8 from PC-BIR and read the Path of the last packet table. The Source IP column changes exactly on passing through R-FIRMA: up to there it is 10.1.20.11, after that 203.0.113.1.

    PositionSource IPDestination IP
    between SW1 and R-FIRMA10.1.20.118.8.8.8
    between R-FIRMA and ISP203.0.113.18.8.8.8
    the reply, between ISP and R-FIRMA
    the reply, between R-FIRMA and SW1

    Fill in the last two rows yourselves, then check in Packet Tracer, in Simulation.

    The exception to the rule of the two addresses In laboratory 1 you learned that the IP address never changes along the way. NAT is exactly the violation of that rule - and the reason it is criticized by purists. It is, at the same time, the reason IPv4 is still alive.
PAT, for reference: what the table looks like

9Assignments

  • Build the topology and demonstrate complete connectivity before any filter
  • Fill in the reference table of connectivity
  • Implement the policies P1–P4 and demonstrate the effect of each, through tests
  • Fill in the connectivity table again and explain every difference
  • Configure PAT for all the internal segments
  • Configure static NAT for the web server and demonstrate access from the Internet
  • Document the translation of the addresses, segment by segment
  • Provoke a rule with zero matches, explain why and repair it

10Going further

Three new requests, on the same day

Management comes back with three further requirements. Implement them all, without breaking the existing policies.

  1. Guests are not allowed on the Internet outside working hours (Monday–Friday, 8:00–18:00).
  2. One single computer in BIROURI, the one in accounts (10.1.20.50), must reach the ADMIN segment - but only on port 3389.
  3. FTP downloads are forbidden for everybody, except for ADMIN.

For each requirement, state: the kind of list, the exact position of the rule in the existing list, the interface and the direction.

See the hints

1. You need a time-range and a time-conditioned rule:

hint
R-FIRMA(config)# time-range PROGRAM
R-FIRMA(config-time-range)# periodic weekdays 8:00 to 18:00
! then, in the OASPETI-IN list, rule 30 becomes:
R-FIRMA(config-ext-nacl)# no 30
R-FIRMA(config-ext-nacl)# 30 permit ip 10.1.30.0 0.0.0.255 any time-range PROGRAM

2. The rule must be above rule 10 of BIROURI-IN, which blocks all traffic towards ADMIN. Here you see why explicit numbering of the rules is essential - you can insert at position 5, without rewriting the list:

hint
R-FIRMA(config)# ip access-list extended BIROURI-IN
R-FIRMA(config-ext-nacl)# 5 permit tcp host 10.1.20.50 10.1.10.0 0.0.0.255 eq 3389

3. FTP uses control port 21 and, in active mode, data port 20. A rule that blocks only eq 21 stops the session from being established, so it is enough in practice - but think about what happens with passive FTP, where the data port is negotiated dynamically and may be anything above 1024. It is exactly the limitation lecture 7 spoke of, and the reason modern firewalls inspect the content, not only the headers.

11Self-check questions

12Deliverables

DeliverableFormatWeight
The Packet Tracer file with the policies P1–P5 implemented.pkt35 %
The two connectivity tables, before and after, with the differences explaineddocument25 %
The documentation of the NAT translation, segment by segmentdocument20 %
Going further: the three new requirements, with rule, position, interface and directiondocument20 %