The security policy of a company is written in words, but the network understands only rules. This exercise makes the translation: five requirements stated by management become access lists, placed correctly on interfaces and in directions. Then the whole company reaches the Internet - on a single public address.
1How an access list is read
An access list is a list of rules, traversed from top to bottom, until the first match. Whatever
matches first decides, and the rest of the list is not even read. At the end, if nothing matched, there is an
invisible deny that discards the packet.
0 means "this bit must match", 1 means "anything".
For a /24 network you write 0.0.0.255. Shortcuts: host 10.1.10.5 means
10.1.10.5 0.0.0.0, and any means
0.0.0.0 255.255.255.255.in filters the packets that enter the router on that interface, before routing.
out filters the packets that leave, after routing. The same list on the same interface,
but in different directions, does completely different things.2. The implicit deny. A list containing only
deny rules blocks absolutely everything,
including what you meant to permit.3. The direction. The right list, applied in the wrong direction, never sees the traffic it was meant to filter - and its counter stays at zero.
2Equipment needed
| Qty | Equipment | Model | Packet Tracer category | What it is for here |
|---|---|---|---|---|
| 2 | Router | 4331 | Network Devices → Routers | R-FIRMA (the edge router) and ISP |
| 1 | Switch | 2960 | Network Devices → Switches | SW1, with three VLANs |
| 3 | Computer | PC-PT | End Devices | one test host per department |
| 2 | Server | Server-PT | End Devices | SRV-WEB in the DMZ and "the Internet" (8.8.8.8) |
| 1 | Serial cable | Serial DCE | Connections | R-FIRMA ↔ ISP |
| 6 | Straight cable | Copper Straight-Through | Connections | the remaining links |
The topology takes up the structure of laboratory 3: three VLANs on SW1, a trunk to the router,
subinterfaces on G0/0/0. The DMZ is attached to a separate physical interface,
G0/0/1.
3The topology and the policy
| Segment | VLAN | Network | Gateway | Test host |
|---|---|---|---|---|
| ADMIN | 10 | 10.1.10.0/24 | 10.1.10.1 | PC-ADM 10.1.10.11 |
| BIROURI | 20 | 10.1.20.0/24 | 10.1.20.1 | PC-BIR 10.1.20.11 |
| OASPETI | 30 | 10.1.30.0/24 | 10.1.30.1 | PC-OSP 10.1.30.11 |
| DMZ | - | 10.1.40.0/24 | 10.1.40.1 | SRV-WEB 10.1.40.10 |
| The link to the ISP | - | 203.0.113.0/30 | - | R-FIRMA .1, ISP .2 |
| Public block allocated | - | 203.0.113.32/29 | - | .33 – .38 usable |
P2. The offices have access everywhere, except to the ADMIN segment.
P3. The web server in the DMZ is not allowed to initiate connections towards the internal network. It may only answer.
P4. The router may be administered through SSH only from the hosts in ADMIN.
P5. The web server must be reachable from the Internet, at a fixed public address.
4The workbench
5Step 0: a working network, with no filters
Before filtering anything, everything must work. It is a discipline that is hard to learn, but it saves hours: if you apply ACLs on top of a network that does not work, you will never know which problem belongs to which.
- VLANs on the switch
on SW1
Switch> enable Switch# configure terminal Switch(config)# hostname SW1 SW1(config)# vlan 10 SW1(config-vlan)# name ADMIN SW1(config-vlan)# vlan 20 SW1(config-vlan)# name BIROURI SW1(config-vlan)# vlan 30 SW1(config-vlan)# name OASPETI SW1(config-vlan)# exit SW1(config)# interface fastEthernet 0/1 SW1(config-if)# switchport mode access SW1(config-if)# switchport access vlan 10 SW1(config-if)# exit SW1(config)# interface fastEthernet 0/2 SW1(config-if)# switchport mode access SW1(config-if)# switchport access vlan 20 SW1(config-if)# exit SW1(config)# interface fastEthernet 0/3 SW1(config-if)# switchport mode access SW1(config-if)# switchport access vlan 30 SW1(config-if)# exit SW1(config)# interface gigabitEthernet 0/1 SW1(config-if)# switchport mode trunk SW1(config-if)# end
- Router-on-a-stick, the DMZ and the way out to the ISP
on R-FIRMA
Router(config)# hostname R-FIRMA R-FIRMA(config)# interface gigabitEthernet 0/0/0 R-FIRMA(config-if)# no ip address R-FIRMA(config-if)# no shutdown R-FIRMA(config-if)# exit R-FIRMA(config)# interface gigabitEthernet 0/0/0.10 R-FIRMA(config-subif)# encapsulation dot1Q 10 R-FIRMA(config-subif)# ip address 10.1.10.1 255.255.255.0 R-FIRMA(config-subif)# exit R-FIRMA(config)# interface gigabitEthernet 0/0/0.20 R-FIRMA(config-subif)# encapsulation dot1Q 20 R-FIRMA(config-subif)# ip address 10.1.20.1 255.255.255.0 R-FIRMA(config-subif)# exit R-FIRMA(config)# interface gigabitEthernet 0/0/0.30 R-FIRMA(config-subif)# encapsulation dot1Q 30 R-FIRMA(config-subif)# ip address 10.1.30.1 255.255.255.0 R-FIRMA(config-subif)# exit R-FIRMA(config)# interface gigabitEthernet 0/0/1 R-FIRMA(config-if)# description DMZ R-FIRMA(config-if)# ip address 10.1.40.1 255.255.255.0 R-FIRMA(config-if)# no shutdown R-FIRMA(config-if)# exit R-FIRMA(config)# interface serial 0/1/0 R-FIRMA(config-if)# ip address 203.0.113.1 255.255.255.252 R-FIRMA(config-if)# clock rate 128000 R-FIRMA(config-if)# no shutdown R-FIRMA(config-if)# exit R-FIRMA(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.2 R-FIRMA(config)# end
on ISPRouter(config)# hostname ISP ISP(config)# interface serial 0/1/0 ISP(config-if)# ip address 203.0.113.2 255.255.255.252 ISP(config-if)# no shutdown ISP(config-if)# exit ISP(config)# interface gigabitEthernet 0/0/0 ISP(config-if)# ip address 8.8.8.1 255.255.255.0 ISP(config-if)# no shutdown ISP(config-if)# exit ISP(config)# ip route 203.0.113.32 255.255.255.248 203.0.113.1 ISP(config)# end
Notice what the ISP does not have: any route towards the private networks of the company. That is precisely the point of NAT, which we configure at the end.
- Fill in the reference table
From every internal host, ping all the others and also SRV-WEB and the Internet. Everything must work. Note the results - it will be the reference against which you check the effect of each list.
From \ to ADMIN BIROURI OASPETI DMZ Internet ADMIN - BIROURI - OASPETI - DMZ -
6Translating the policy into rules
Each policy is translated by answering, in order, three questions: what kind of list I need, on which interface I put it and in which direction.
P1 - The guests
The source is always the same (10.1.30.0/24), but the destination decides whether the traffic is permitted or not. A standard list sees only the source, so it cannot express the policy. We need an extended list.
The placement: an extended list is put as close as possible to the source, hence on the
G0/0/0.30 subinterface, direction in - the forbidden traffic does not even get as
far as being routed.
R-FIRMA(config)# ip access-list extended OASPETI-IN R-FIRMA(config-ext-nacl)# remark permit access to the web server in the DMZ R-FIRMA(config-ext-nacl)# 10 permit tcp 10.1.30.0 0.0.0.255 host 10.1.40.10 eq 80 R-FIRMA(config-ext-nacl)# remark block every other internal resource R-FIRMA(config-ext-nacl)# 20 deny ip 10.1.30.0 0.0.0.255 10.0.0.0 0.255.255.255 R-FIRMA(config-ext-nacl)# remark the rest, that is the Internet, is permitted R-FIRMA(config-ext-nacl)# 30 permit ip 10.1.30.0 0.0.0.255 any R-FIRMA(config-ext-nacl)# exit R-FIRMA(config)# interface gigabitEthernet 0/0/0.30 R-FIRMA(config-subif)# ip access-group OASPETI-IN in R-FIRMA(config-subif)# end
Now test, from PC-OSP:
| Test | Result | Why |
|---|---|---|
ping 10.1.10.11 | blocked | rule 20: destination in 10.0.0.0/8 |
ping 10.1.40.10 | blocked | rule 20 again - rule 10 permits only TCP port 80, and ping is ICMP |
ping 8.8.8.8 | permitted | rule 30: any other destination |
The order of the three rules is the whole solution. Rule 10 is more specific than 20, so it must be above it; rule 30 is the most general and closes the list. Swap rules 10 and 30 and test again: you will see exactly how the policy breaks.
P2 - The offices
R-FIRMA(config)# ip access-list extended BIROURI-IN R-FIRMA(config-ext-nacl)# 10 deny ip 10.1.20.0 0.0.0.255 10.1.10.0 0.0.0.255 R-FIRMA(config-ext-nacl)# 20 permit ip 10.1.20.0 0.0.0.255 any R-FIRMA(config-ext-nacl)# exit R-FIRMA(config)# interface gigabitEthernet 0/0/0.20 R-FIRMA(config-subif)# ip access-group BIROURI-IN in
Check: the offices no longer reach ADMIN, but do reach the DMZ and the Internet. Check the reverse direction as well - from PC-ADM towards PC-BIR: it works, because the list is applied only to the traffic that enters from the offices.
P3 - The DMZ does not initiate
"It may only answer" means that traffic from the DMZ towards the inside is permitted only if it is
part of a conversation started from the inside. A classic ACL cannot express that - it sees packets, not
connections. The minimal solution is the keyword established.
R-FIRMA(config)# ip access-list extended DMZ-IN R-FIRMA(config-ext-nacl)# 10 permit tcp host 10.1.40.10 10.0.0.0 0.255.255.255 established R-FIRMA(config-ext-nacl)# 20 deny ip host 10.1.40.10 10.0.0.0 0.255.255.255 R-FIRMA(config-ext-nacl)# 30 permit ip host 10.1.40.10 any R-FIRMA(config-ext-nacl)# exit R-FIRMA(config)# interface gigabitEthernet 0/0/1 R-FIRMA(config-if)# ip access-group DMZ-IN in
established
It checks only the ACK and RST bits of the TCP header, so a packet forged with ACK set gets through. It does
not work for UDP and ICMP. In a real network, a stateful firewall or a reflexive ACL, with
reflect and evaluate, would be used here.P4 - Administrative access
Traffic towards the VTY lines of the router is not filtered on an interface, but directly on the lines,
with access-class. Here a standard list is enough: all that matters is where the
connection comes from.
R-FIRMA(config)# ip domain-name firma.local R-FIRMA(config)# crypto key generate rsa R-FIRMA(config)# username admin privilege 15 secret Admin123 R-FIRMA(config)# access-list 10 remark only the ADMIN hosts R-FIRMA(config)# access-list 10 permit 10.1.10.0 0.0.0.255 R-FIRMA(config)# line vty 0 4 R-FIRMA(config-line)# transport input ssh R-FIRMA(config-line)# login local R-FIRMA(config-line)# access-class 10 in R-FIRMA(config-line)# exec-timeout 5 0
Check your understanding
The last packet is important: it comes from BIROURI, so it matches no rule of this list and falls on the
implicit deny. It has no consequence at all, though - the list is applied on
G0/0/0.30, and that packet never passes there. An ACL matters only where it is
applied.
7The counter, the best troubleshooting instrument
R-FIRMA# show access-lists R-FIRMA# clear access-list counters
The output shows, for each rule, how many times it matched:
Extended IP access list OASPETI-IN
10 remark permit access to the web server in the DMZ
20 permit tcp 10.1.30.0 0.0.0.255 host 10.1.40.10 eq 80
40 deny ip 10.1.30.0 0.0.0.255 10.0.0.0 0.255.255.255 (8 match(es))
60 permit ip 10.1.30.0 0.0.0.255 any (4 match(es))
Now fill in the connectivity table of section 5 again and compare with the reference. Every cell that has changed must correspond to a policy - if something unforeseen has changed, you have a rule that is too broad.
8NAT: the way out to the Internet
All the internal addresses are private, hence unroutable on the Internet. The ISP does not even have routes towards them. We need translation.
- Mark the interfaces
every interface is either "inside" or "outside"
R-FIRMA(config)# interface gigabitEthernet 0/0/0.10 R-FIRMA(config-subif)# ip nat inside R-FIRMA(config-subif)# exit R-FIRMA(config)# interface gigabitEthernet 0/0/0.20 R-FIRMA(config-subif)# ip nat inside R-FIRMA(config-subif)# exit R-FIRMA(config)# interface gigabitEthernet 0/0/0.30 R-FIRMA(config-subif)# ip nat inside R-FIRMA(config-subif)# exit R-FIRMA(config)# interface gigabitEthernet 0/0/1 R-FIRMA(config-if)# ip nat inside R-FIRMA(config-if)# exit R-FIRMA(config)# interface serial 0/1/0 R-FIRMA(config-if)# ip nat outside R-FIRMA(config-if)# exit
Without these markings, NAT does absolutely nothing - however correct the rules are. It is the first thing to check when "NAT does not work".
- PAT for all the internal hosts
PAT with the address of the outgoing interface
R-FIRMA(config)# access-list 100 remark what gets translated R-FIRMA(config)# access-list 100 permit ip 10.1.10.0 0.0.0.255 any R-FIRMA(config)# access-list 100 permit ip 10.1.20.0 0.0.0.255 any R-FIRMA(config)# access-list 100 permit ip 10.1.30.0 0.0.0.255 any R-FIRMA(config)# ip nat inside source list 100 interface serial 0/1/0 overload
Here is the second use of access lists, promised in lecture 7: here the list filters nothing - it merely describes the traffic that must be translated. The same syntax, a different role.
- Static NAT for the web server (P5)
a fixed public address for SRV-WEB
R-FIRMA(config)# ip nat inside source static 10.1.40.10 203.0.113.33
Test from "the Internet": from the NET server,
ping 203.0.113.33- the server in the DMZ answers. Andping 10.1.40.10from there does not work and cannot: the private address does not exist on the Internet.Alternatively, if you want to publish only port 80 and keep the public address for something else:
port forwardingR-FIRMA(config)# ip nat inside source static tcp 10.1.40.10 80 203.0.113.1 80
- See the translation with your own eyes
checking NAT
R-FIRMA# show ip nat translations R-FIRMA# show ip nat statistics R-FIRMA# clear ip nat translation *
In the workbench in this page: issue
ping 8.8.8.8from PC-BIR and read the Path of the last packet table. The Source IP column changes exactly on passing through R-FIRMA: up to there it is10.1.20.11, after that203.0.113.1.Position Source IP Destination IP between SW1 and R-FIRMA 10.1.20.11 8.8.8.8 between R-FIRMA and ISP 203.0.113.1 8.8.8.8 the reply, between ISP and R-FIRMA the reply, between R-FIRMA and SW1 Fill in the last two rows yourselves, then check in Packet Tracer, in Simulation.
The exception to the rule of the two addresses In laboratory 1 you learned that the IP address never changes along the way. NAT is exactly the violation of that rule - and the reason it is criticized by purists. It is, at the same time, the reason IPv4 is still alive.
9Assignments
- Build the topology and demonstrate complete connectivity before any filter
- Fill in the reference table of connectivity
- Implement the policies P1–P4 and demonstrate the effect of each, through tests
- Fill in the connectivity table again and explain every difference
- Configure PAT for all the internal segments
- Configure static NAT for the web server and demonstrate access from the Internet
- Document the translation of the addresses, segment by segment
- Provoke a rule with zero matches, explain why and repair it
10Going further
Management comes back with three further requirements. Implement them all, without breaking the existing policies.
- Guests are not allowed on the Internet outside working hours (Monday–Friday, 8:00–18:00).
- One single computer in BIROURI, the one in accounts (
10.1.20.50), must reach the ADMIN segment - but only on port 3389. - FTP downloads are forbidden for everybody, except for ADMIN.
For each requirement, state: the kind of list, the exact position of the rule in the existing list, the interface and the direction.
See the hints
1. You need a time-range and a time-conditioned rule:
R-FIRMA(config)# time-range PROGRAM R-FIRMA(config-time-range)# periodic weekdays 8:00 to 18:00 ! then, in the OASPETI-IN list, rule 30 becomes: R-FIRMA(config-ext-nacl)# no 30 R-FIRMA(config-ext-nacl)# 30 permit ip 10.1.30.0 0.0.0.255 any time-range PROGRAM
2. The rule must be above rule 10 of BIROURI-IN, which blocks all traffic
towards ADMIN. Here you see why explicit numbering of the rules is essential - you can insert at position 5,
without rewriting the list:
R-FIRMA(config)# ip access-list extended BIROURI-IN R-FIRMA(config-ext-nacl)# 5 permit tcp host 10.1.20.50 10.1.10.0 0.0.0.255 eq 3389
3. FTP uses control port 21 and, in active mode, data port 20. A rule that blocks only
eq 21 stops the session from being established, so it is enough in practice - but think about
what happens with passive FTP, where the data port is negotiated dynamically and may be anything above 1024.
It is exactly the limitation lecture 7 spoke of, and the reason modern firewalls inspect the content, not
only the headers.
11Self-check questions
12Deliverables
| Deliverable | Format | Weight |
|---|---|---|
| The Packet Tracer file with the policies P1–P5 implemented | .pkt | 35 % |
| The two connectivity tables, before and after, with the differences explained | document | 25 % |
| The documentation of the NAT translation, segment by segment | document | 20 % |
| Going further: the three new requirements, with rule, position, interface and direction | document | 20 % |