Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, 25 July 2013

Juniper Dynamic VPN and Pulse

There are couple of different types of VPN which can be configured with Juniper products. The MAG and SA products configure SSL VPNs and there are different ways of doing this but this quick post is just to mention Dynamic VPN using the SRX.

Dynamic VPN is an IPSec type VPN but it's not a site-to-site VPN it is a remote access VPN for endpoints. The client used is still Pulse.

The below document is a great reference for Dynamic VPN and Junos Pulse.

References:
[Dynamic VPN] Using Junos Pulse to connect Dynamic VPN client to SRX

Tuesday, 2 April 2013

ASA, support and IPS signatures

Here's a specific  issue I ran into which I'll document here for reference, and maybe it'll stop someone else getting the same problem.

When buying an ASA firewall, if you want to use IPS you will need signature updates from Cisco. There is little point running IPS without signature updates because outdated security doesn't really help anyone.

A confusing point I found is that if you are a partner ordering partner support some ASA firewalls don't let you select a IPS signatures support level in the CCW, only the standard support levels without IPS updates. This is a strange omission and hopefully it will be fixed at some point but for now (March 2013) it's not.

Therefore to get IPS signature updates on ASA firewalls, You order an ASA with support, for example:

ASA5512-IPS-K9
CON-PSRT-A12IPS9    (This is partner support so will only be available to applicable partners)


And then once the device arrives (or when you have the serial number) you can order a SUSA IPS signatures service. it cannot be done all together at point of order.


After the contract has been generated (post shipping), the secondary coverage for Cisco IPS signature updates can be quoted or ordered in Cisco Service Contract Center (CSCC). You will need to use the serial number of the device that was shipped before you can create a quote for the IPS signature updates. 


Cisco Services for IPS:
http://www.cisco.com/en/US/services/ps2827/ps6076/services_qa0900aecd8022e96e.pdf

Thursday, 28 March 2013

ASA Mobile Device license

The mobile devices license on ASA appliances allows mobile devices to use a VPN tunnel to connect back to the ASA. it's an "enabling / feature  license" so rather than purchasing one per user you purchase it for the ASA just once. It must be used in conjunction with AnyConnect essentials or AnyConnect premium. Essentials is another example of a "enabling license" you purchase it once and you get the full number of basic VPNs tunnels available on your box. Premium is a per user license, you purchase the number of premium user licenses required for your number of users.

An example of these licenses combined would be:
An ASA5550 with 1000 devices, which could be mobile devices, laptops, destops etc. You would require:
The Appliance:
1 x ASA5550-BUN-K9
The SSL Premium Licenses or Essential Licenses:
1 x ASA5500-SSL-1000 or 1 x ASA-AC-E-5550
And the Mobile Devices License
1 x ASA-AC-M-5550 

If using premium SSL licenses the number can be raised or lowered depending on the number of users you have, the mobile license would be unaffected, you purchase this once and thats that.

On a side note AnyConnect essentials and premium are mutually exclusive, you cannot have both, you either have to have essentially VPNs or premium VPNs.

Cisco Security Manager CSM4.0 to 4.3 upgrade


Upgrading from version 4.0 to 4.3 is a minor upgrade and as such will be covered by a support contract.

If the customer does not have a valid software support on their existing CSM 4.0, then it will be chargeable.

Please check the links below for your reference:
http://www.cisco.com/en/US/partner/prod/collateral/vpndevc/ps5739/ps6498/qa_c67-711959.html

ACS Licensing and deployment sizes


The large deployment license is required per deployment if the deployment will control more than 500 nodes. If your had more than 500 AAA client devices (talking about switches, routers, etc. and not end-hosts or end-users), then they would need ONE Large Deployment license PER DEPLOYMENT.

If the customer has two ACS servers in the same deployment so one of them is a primary and the other is a secondary and they synchronize between each other, this is a deployment. A primary and all the secondary ACS that are kept in synchronized status by the primary consist a deployment.

The rule is the following: if there is more than 500 AAA clients (networking devices) in the same deployment, then they would need a Large Deployment license installed on the primary ACS.

If they didn't want to buy the Large Deployment license, then they would need to create two separate deployments each having a primary server only. However in this case there would be no configuration synchronization between the two servers so each and every user, policy and other settings must be configured on both appliances manually.

VS-6509 Common Criteria Certification for EAL3

So this was a question I had to punt to the partner helpline and below is the response I got:

Below is what I have found, but I believe this is the document where you found the certificate for 12.2(18)SXF11.

Industry Solutions - Common Criteria
http://www.cisco.com/web/strategy/government/security_certification/net_business_benefit_seccert_common_criteria.html

Below is some information I found from our internal resources regarding Common Criteria:

There is no targeting for new Common Criteria update for Sup720 at this
time.  We will have to rely on 12.2(33)SXF with the Sup720-3B.  For a new round of Common Criteria, we are targeting the Sup2T by June 2012.  The EAL4 designation is no longer being certified in the US and several other Common Criteria certifying countries like UK, Australia, etc. so we will have to go with what is offered in the US which is a EAL1/EAL2 based Network Device Protection Profile Common Criteria
Certification.  So going forward, the EAL4/3/2/1 designations won't mean anything with relation to Common Criteria.

You can refer to the link below for more information.

Security Requirements for Network Devices
http://www.commoncriteriaportal.org/files/ppfiles/pp_nd_v1.0.pdf

Hopefully this wont be too relevant any more because the Sup-720 is end of life and the SUP2T is the way forward but it's good to keep a not of it!

ASA Services module Code version 8.4 and below

Version 8.4 and before isn't available on the ASA services module, only version 8.5 onwards. So if you want to deploy version 8.4 or below then you will need a physical ASA appliance.

Release Notes for the Cisco Catalyst 6500 Series ASA Services Module, 8.5(x)
http://www.cisco.com/en/US/docs/security/asa/asa84/release/notes/asarn85.html

ISE Sizing on Virtual Machines


The current ISE VM performance/scalability guidelines are based on the ISE appliance configuration (i.e. similar configuration yields similar results). If you have the same VM requirements as the appliance has, it will have the same results. As an example 3315 can support up to 3,000 concurrent endpoints, 3355 can support up to 6,000 concurrent endpoints and 3395 can support up to 10,000 concurrent endpoints.

Below are the documents you need for reference. Installing the Cisco ISE System Software on a VMware Virtual Machine. See. Table 4-1 Minimum VMware System Requirements
http://www.cisco.com/en/US/docs/security/ise/1.0.4/install_guide/ise104_vmware.html
**Update 10/01/2014
http://www.cisco.com/en/US/docs/security/ise/1.2/installation_guide/ise_vmware.html

Introducing the Cisco ISE Hardware. See. Cisco ISE 3300 Series Appliance Hardware Summary
http://www.cisco.com/en/US/docs/security/ise/1.0.4/install_guide/ise104_ovr.html
**Update 10/01/2014
http://www.cisco.com/en/US/docs/security/ise/1.2/installation_guide/ise_ovr.html


So just to recap the maximum number of end points on the virtual appliance is 10,000 but it depends on the amount of resources allocated to that virtual appliance as to what can actually be supported.
If the virtual appliance only has a similar amount of resources as the physical 3315 appliance then it will only handle 3,000. And the same is true for the 3355 etc.

**Updates 10/01/2014
It's worth noting the ISE hardware has recently been updated, the appliances are now the SNS 3400 series and below is a link to the hardware specification:

Thursday, 1 November 2012

Securing Borderless Networks + NFP

Here's a few more revision points,this time with relation to securing borderless networks:

Borderless Network Components:
Borderless End Zone
Borderless Datacenter
Borderless Internet
Policy Management

SecureX and context aware security:
Context awareness
AnyConnect client
TrustSec
Security Intelligence Operations

Protecting the planes
Management:
AAA, NTP, SSH, SSL, Protected Syslog, SNMPv3, Parser views

Control:
CoPP, CPPr, Authenticated routing protocol updates

Data:
ACLs, Private VLANs, STP guards, IOS IPS, Zone Based Firewalls (IOS)

Management Plane Best Practices:
Strong Passwords, User authentication and AAA, RBAC, encrypted management protocols, logging, NTP, Secure system files





Monday, 29 October 2012

CCNA Security Buzzwords

So I've made a slight detour on the CCNA Wireless, it's been replaced by the CCNA Security, and my aim is before the end of the year!

Here's some buzzwords which I feel like I'll have to know and be able to explain should the needs arise. I'm not going to explain them here because it forces me to remember what each means (rather than just reading it) hopefully fixing them in my brain:

Asset
Vulnerability
Threat - Latent, Realised, Threat Vector / Agent
Risk
Countermeasure - Administrative, Physical, Logical

Classifications:
Governmental - Unclassified, SBU (sensitive but unclassified), Confidential, Secret, Top Secret
Public Sector - Public, Sensitive, Private, Confidential
Criteria - Value, age, replacement cost, usefulness lifetime
Roles - Owner, Custodian (implementation), User

Attack Methods:
Covert Channel
Trust Exploitation
Password Attacks
Botnet
DoS / DDoS

Secure Network Architecture Guidelines:
Rule of least privilege
Defence in Depth
Separation of Duties
Auditing


The 5 stages of the Secure Network Lifecycle are:
Initiation
Acquisition and Development
Implementation
Operations and Maintenance
Disposition

Methods to determine the financial impact:
Qualitative
Quantitative


That'll do for now although I may well add more as time goes on

Friday, 6 July 2012

Wireless Connection Process

Below is the process a wireless client goes through in order to get access to a wireless network:

Step 1 - Start
This is the initial connection between the client and AP. This is where L2 security authentication and encryption mechanisms are in place, for example: none, static WEP, 802.1X, WPA / WPA2.

Step 2 - DHCP
L3 operations start here, an IP address is attained as well as L3 security elements, such as authentication via a webpage at a hotspot. This could be the first phase if L2 security isn't configured.

Step 3 - Mobility
The clients final IP address is applied here and it can fully function at L3. The address could have well changed here from step 2 if web authentication was used.

Step 4 - Run
The client is live and sending data.

Layer 2 security comprises of:
Authentication - 802.1X or PSK
Encryption - None, WEP, WPA or WPA2 (TKIP or AES)


Tuesday, 3 July 2012

Wireless Security part 2 - Inc RADIUS

RADIUS:
Some benefits of RADIUS are:
Authorisation
Centralised access and control of that access
Accounting supervision - including client network access and rights
Recording access attempts

Encryption:
The basic encryption process is to take plain text, which is scrambled in a process called the cipher, and this gives cipher text. Types of cipers include stream ciphers which consists of performing modifications to each bit of data, and block ciphers, which performs the modifications on a block of data.

Symmetric and Asymmetric Encryption:
Symmetric encryption is faster than Asymmetric encryption because it requires less processing power. The disadvantage is that it is less secure.

Key Management:
There are 2 methods, a common key across all users or a unique key for each user. An issue with individual keys is with unicast and broadcast  / multicast traffic. Individual keys can be generated in 2 ways, either individuals keys should be configured on the client and APs or they can be derived from a common key and generated for each session the user has with the AP.

Encryption methods:
There are 2 types of encryption methods used: TKIP and AES. Prior to these there was only RC4 with static keys which is insecure and should not be used.
TKIP was a replacement to WEP. It is essentially a wrap around WEP with enhanced 128bit encryption but it is made more secure by the following:
It changes the packet's key. The packets key is made up of 3 things, a base key, the transmitting device's MAC, and the packet serial number. This is important because the serial number is a 48bit number which cycles, so a hacker reusing an old serial (replay attacks) are mitigated. Also the Base key is a unique value, so it can't be reused also.
AES is used in the WPA2 and 802.11i standard. It uses 128bit data encryption. AES is a block cipher. 


The 4 improvements of WPA:
Larger initialisation vector (IV) - increases the level of randomness making the encryption harder to crack
Message integrity check
key management using 802.11x
unicast and broadcast key management


Centralised Key Management:
This is a benefit of 802.11i and WPA2. As a client roams often the reauthentication can take long enough to break the applications connections. Two items which mitigate this are: Key Caching (AP caches the credentials of the client so if it roams away and back the AP already has the details) and preauthentication (If the AP comes close but not enough to associate it will perform the authentication process anyway so that if it comes within range later the authentication is much quicker). 


801.11i:
WPA2 was built with 802.11i in mind, when 802.11i was fully ratified some features were added:
A list of EAP methods that can be used
AES-CCMP instead of RC4
Better key management, for example the master key can be cached permitting a faster reconnect for clients


If performing an upgrade from TKIP to AES the same keys can be used


TKIP is used to encrypt data in WPA where as AES or TKIP can be used in WPA2 or 802.11i

Wireless Security - Inc. EAP, PKI,

DoS Protection:
Management Frame Protection (MFP) can be used to protect against the flooding of probe requests or transmissions. MFP comes in 2 forms, infrastructure and client.
In infrastructure MFP mode controllers generate a signature for each WLAN which is added to each management frame sent. Any attempt to alter this or frames with an unknown SSID are detected by the MIC (Message Integrity Check), an alarm is generated and the controller instructs the AP to drop the frame.
In client mode the client can be configured to detect and drop spoofed or invalid management frames. To support this CCX v5 must be used and WPA2 with TKIP or AES must be used.

Passive vs Active attacks. An Active attack is when the hacker is actively interacting with clients, the AP or the network in real time. A passive attack is usually wireless sniffing, for information gathering, either online (on the fly) or offline for analysis later.
IDS / IPS is used to guard against passive attacks.

Authentication:
The act of identifying a device or person. It should be based on something you know (username and passwords), Something you have (smart card / crypto token) or something you are (biometrics / retina scan etc). Authentication can be per user or per device (certificates).

Two types of authentication are open and shared-key. Open authentication is as it is, you only need the SSID, shared authentication relies on a clear text challenge from the AP, which is then encrypted by the clients WEP key and sent back, if it matches the challenge encrypted by the APs WEP key the user is authenticated. This is not secure as the WEP key can be worked out by a hacker snooping the clear tect challenge, then the encrypted challenge and decipher the WEP key.

EAP can be configured instead as a method of authentication. The AP can be configured to use a RADIUS server, LDAP server or for local-EAP where it does the authenticator and authentication server. Local-EAP supports LEAP, EAP-FAST and EAP-TLS, it is usually used as a backup if the RADIUS server becomes unavailable. A local user director or LDAP directory can be used. Here is the EAP process:

  1. Association request from Client to AP then the AP responds with the authentication response
  2. The EAPOL (over LAN) process starts with an EAPOL request send from the AP to client
  3. The client responds to the AP with an EAPOL response, which the AP forwards to the RADIUS server.
  4. The Server sends a EAP request to the client via the AP, the client sends and EAP response back
  5. If the EAP response is good the server sends back an EAP success and the encryption keys
Certificates and PKI (Public Key Infrasturcture):
Some flavours of EAP require certificates to be used as authentication credentials, this means you must have PKI in your network. A PKI requires a certificate server which issues certificates to devices or users. Certificates consist of a public key private key pair. 
Symmetric keys are both the same, where as Asymmetric the encrypt (public) and decrypt (Private) keys are different. PKI uses asymmetric keys. The certificate server is called the Certificate Authority (CA), this should be trusted by both parties in authentication. 

EAP-TLS:
Is the most secure and also most complicated. Certificates must be installed on both the client and server. Client and authentication server keys must be generated and signed by a PKI, then installed on each device.

EAP-FAST:
Cisco proprietary method of providing the same level of security as EAP-TLS but no PKI or certifictes are needed. It instead creates an encrypted tunnel. the server generates a PAC (Protected Access Credential), this is used in the same way as the key pair used in EAP-TLS. The PAC contains PAK key (like a private key), PAC opaque used to identify the client and retrieve the PAC key and PAC info which contains information about the server authority ID. After the PAC is used to create the tunnel the client is authenticated with passwords or security tokens.

PEAP:
PEAP is in the middle of EAP-TLS and EAP-FAST. It only requires a certificate on the server. The 2 variations are: PEAP-MSCHAPv2 (uses MSCHAPv2 authentication) and PEAP-GTC (uses generic Token Card authentication). Client identifies itself in plain text. Server sends certificate to client to verify identity, Client generates master key, encrypts it with the public key and a secure tunnel is created. Now the client identifies a second time as the transmissions are protected by the tunnel.

LEAP:
This is was developed by Cisco but made available to other devices through licensing and only uses a username and password. However it is no longer secure due to the ease of breaking it.

Thursday, 21 June 2012

Symmetric Key Algorithms

This is something which I should really know, and every time I hear it and look it up I do know it, I just couldn't recite it if someone asked. So here's a description to read a few times and hopefully cement it there a little more!

Symmetric Key Algorithms use the same keys for both the encryption of plain text and the decryption of cipher text. I.E. the same key is used to be encrypt and decrypt. In practice it is a shared secret password, which both parties know.

Tuesday, 12 June 2012

Proxies: Forward and Reverse

A proxy server is an intermediate device which sits between two objects, a common example is clients and a single or set of resources.

There are many different types of proxies but the ones I want to talk about here are forward and reverse proxies:
Forward Proxy:
A forward proxy is used to grant access to a collection of clients to a resource, for example the Internet. A client sends the request to the proxy server naming the destination server, so the client much be configured to know about the proxy in place. The proxy then requests the content from the destination server and returns it to the client.

Reverse Proxy:
A reverse proxy appears to the client as an ordinary server, there is no special configuration required on the client. The reverse proxy receives the request from the client and then decides where to send the request to, usually within a pool of resources, it returns the content as though it was the destination server. An example of a reverse proxy would be as a load balancer for a pool of resources.