Transcription of Infrastructure Protection on Cisco Catalyst 6500 and 4500 ...
1 Corporate Headquarters:Copyright 2004 Cisco Systems, Inc. All rights Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USAI nfrastructure Protection on Cisco Catalyst 6500 and 4500 series Switches A key element in an organization's overall security posture is the security of the network Infrastructure . The network Infrastructure is the foundation built with routers, switches, and other equipment that provide the fundamental network services that keep a network running. The Infrastructure is often the target of denial of service (DoS) and other attacks that can directly or indirectly disrupt the network operation. In order to ensure the availability of the network, it is critical to implement the security tools and best practices that help protect each network element, and the Infrastructure as a whole.
2 This document describes the tools that are currently available to protect Cisco Catalyst 6500 and 4500 series switches from direct attacks. These tools can also help prevent accidental misconfiguration, which could present a risk to the Infrastructure . This document also provides deployment guidelines to help implement these tools as an integrated security solution, rather than as isolated elements. The first portion of this document provides an overview of the basic tools and technologies that are available on Catalyst switches for network device hardening. Subsequent sections provide a closer look at more advanced features that require additional explanation. Later sections provide deployment guidelines that describe how to implement these features in an integrated way, followed by additional reference information.
3 ContentsBasic Tools and Techniques for Device Hardening 5 Disabling Unneeded Services 5 Controlling Switch Access 6 Access Control Lists 7 Router ACL 8 VLAN ACL(VACL) 8 Configuring VACLs in Catalyst OS 9 Configuring VACLs in Cisco IOS 10 Port ACL (PACL) 12 Configuring PACLs in Catalyst OS 132OL-11615-01 Configuring PACLs in Cisco IOS 13 Unicast MAC Address Filtering (MAC Address-Based Traffic Blocking) 14IP Permit Lists 15 Access-Class 15 Locking Down Unused Ports 16 Spanning Tree Protocol Security 17 Disabling Auto-Negotiated Trunking 18 Per VLAN Spanning Tree (PVST) 19 BPDU Guard 20 STP Root Guard 23 Routing Protocol Security 24 Neighbor Authentication 24 Route Filtering 25 TTL Security Check 26 Catalyst Integrated Security 27 Port Security 27 Configuring Port Security in Catalyst OS 28 Configuring Port Security in Cisco IOS 29 MAC Address Monitoring 30 Configuring MAC Address Monitoring in Catalyst OS 30 Configuring MAC Address Monitoring in Cisco IOS 31 Traffic Storm Control 32 Catalyst 6500 Broadcast Suppression ( Catalyst OS) 33 Catalyst 6500 Traffic Storm Control ( Cisco IOS) 34 Catalyst 4500 Port-Based Traffic Control ( Cisco IOS)
4 35 Unicast and Multicast Flood Blocking 37 Catalyst 6500 and Catalyst 4500 Unicast Flood Blocking ( Catalyst OS) 37 Catalyst 6500 Unknown Unicast Flood Blocking ( Cisco IOS) 38 Catalyst 4500 Port Unicast and Multicast Flood Blocking ( Cisco IOS) 38 DHCP Snooping 39 Catalyst 6500 DHCP Snooping ( Catalyst OS) 40 Catalyst 6500 and Catalyst 4500 DHCP Snooping ( Cisco IOS) 41IP Source Guard 43IP Source Guard in Catalyst OS ( Catalyst 6500 ) 43IP Source Guard in Cisco IOS ( Catalyst 4500) 45 Dynamic ARP Inspection (DAI) 46 Dynamic ARP Inspection (DAI) in Catalyst OS ( Catalyst 6500 ) 47 Dynamic ARP Inspection (DAI) in Cisco IOS ( Catalyst 6500 and Catalyst 4500) 50 Control Plane Policing 523OL-11615-01 CoPP Technology Overview 53 CoPP on Supervisors 720 and 32 ( Catalyst 6500 ) 54 Configuring CoPP on Supervisors 720 and 32 ( Catalyst 6500 ) 55 Catalyst 6500 series Switch CoPP Considerations and Restrictions 56 CoPP on Catalyst 4500 57 Configuring CoPP on Catalyst 4500 series Switches 59 Catalyst 4500 series Switch CoPP Considerations and Restrictions 60 Defining CoPP Traffic Classes 61 Recommended CoPP Deployment Methodology 62 Sample CoPP Configuration 64 Additional Catalyst 6500 Infrastructure Protection Features 67 Unicast Reverse Path Forwarding (uRPF)
5 67 Hardware-Based Rate Limiters on Supervisor 2 69 Ingress-Egress ACL Bridged Packets (Unicast Only) 69 FIB (CEF) Receive and FIB Glean Cases (Unicast Only) 70 VACL Log (Unicast Only) 70 Layer 3 Security Features (Unicast Only) 71 Routing Protocol Policing 71 Hardware-Based Rate Limiters on Supervisors 32 and 720 72 Ingress-Egress ACL Bridged Packets (Unicast Only) 73uRPF Check Failure (Unicast Only) 73 ICMP Unreachable (Unicast Only) 74 ICMP Redirects (Unicast Only) 75IP Errors (Unicast Only) 75 FIB (CEF) Receive (Unicast Only) 75 FIB (CEF) Glean (Unicast Only) 76 VACL Log (Unicast Only) 76 Layer 3 Security Features (Unicast Only) 77 TTL Failure (Unicast and Multicast) 77 MTU Failure (Unicast and Multicast) 78 Layer 2 PDU 78 Layer 2 Protocol Tunneling 78 Layer 2 Multicast IGMP Snooping 79 IPv4 Multicast 79 IPv6 Multicast 80 Routing Protocol and ARP Policing 81 Configuring Hardware-Based Rate Limiters in Catalyst OS 82 ACL Bridge Packets 82 The ACL Feature (ARP Inspection, DHCP Snooping, )
6 82 VACL Log 834OL-11615-01 Layer 2 Port Security 84 Layer 2 PDU 84 Layer 2 Protocol Tunneling 85 Multicast IGMP 85 Integrated Deployment Guidelines 86 Deploying Basic Device Hardening Tools and Techniques 86 Spanning Tree Protocol Security 87 Deploying Routing Protocol Security 88 Deploying Catalyst Integrated Security 89 Catalyst 6500 Hardware Rate Limiters and CoPP 90 Additional References 91 Unneeded Services 91 Unneeded Services in Cisco IOS and Catalyst OS 92 Cisco Discovery Protocol (CDP) 92 ICMP Redirects 93 ICMP Unreachables 93 Possible Unneeded Services in Cisco IOS 94 Directed Broadcast 95 Finger Protocol 95IP BOOTP Server 95IP Source Routing 96 PAD 96 Proxy ARP 96 TCP and UDP Small Servers 97IP version 6 (IPv6)
7 97 Access Control 98 Secure Local Password Management 98 Password Management in Catalyst OS 98 Password Management in Cisco IOS 100 Interactive Access Control 102 Interactive Access in Catalyst OS 102 Interactive Access in Cisco IOS 103 Cisco IOS Login Enhancements 104 Warning Banners 104 Web-Based GUI Access 105 Web-Based GUI Access in Catalyst OS 105 Web-Based GUI Access in Cisco IOS 106 Secure Shell (SSH) 107 SSH in Catalyst OS 1075OL-11615-01 SSH in Cisco IOS 108 SNMP Access 108 Other Security Services 109 TCP Intercept 109 Private VLANs Authentication 110 Catalyst 6500 Security Service Modules 110 Firewall Services Module (FWSM) 111 IPSec VPN Services Module 111 WebVPN Services Module 111 Content Switching Module with SSL (CSM-S) 111 Anomaly Guard Services Module 111 Traffic Anomaly Detector Services Module 111 Network Analysis Module (NAM)
8 112 Commonly Used Protocols 112 Basic Tools and Techniques for Device HardeningDevice hardening ensures the security of a device by controlling access to the device, disabling services that are not needed, and by establishing mechanisms to help control the use of system section presents a compilation of best practices for device hardening on Cisco Catalyst 6500 and 4500 series switches. Most of these best practices are based on tools and techniques that have been available for quite some time, and which can be considered following is a list of the recommended hardening best practices for Catalyst switches: Disabling Unneeded Services, page 5 Controlling Switch Access, page 6 Access Control Lists, page 7 Locking Down Unused Ports, page 16 Disabling Unneeded ServicesTo facilitate deployment, Cisco Catalyst switches arrive with many services that are considered appropriate for most network environments already enabled.
9 However, because not all networks have the same requirements, some of these services might not be needed and can be disabled. Disabling unneeded services has two benefits. It helps preserve system resources, and eliminates the potential of security exploits on the disabled services. Disabling unneeded services becomes especially important for services that are known to be prone to being used for malicious purposes. Some services that are enabled by default can be used by attackers to obtain network and user information, bypass security controls, and even generate DoS attacks. A directed broadcast is a good example of a default service found in some switches and routers that could be used for DoS attacks. An IP-directed broadcast packet is an IP packet with a destination address that is a valid broadcast address for an IP subnet.
10 When a directed broadcast packet reaches a switch that is 6OL-11615-01directly connected to its destination subnet, and if the switch is configured to do so, that packet is exploded as a broadcast on the destination subnet. In this way, a single directed broadcast packet can reach multiple destinations, and can be used by programs such as smurf, to amplify the effects of an attack. A smurf attack, named after its exploit program, is a DoS attack that uses spoofed broadcast ping messages to flood a target you identify the services that are needed, it is a good practice to enable them only as they are needed. Most network devices allow a selective configuration of services. Some services can be activated either for the entire system, globally, or per component, typically at a module or interface level.