139
Staff AAA

Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Embed Size (px)

Citation preview

Page 1: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Staff AAA

Page 2: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Radius is not an ISP AAA Option

Page 3: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

RADIUS TACACS+ Kerberos

Page 4: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What to Configure?

Page 5: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Simple Staff Authentication and Failsafe

Page 6: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Simple Staff Authentication and Failsafe

Page 7: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Simple Staff Authentication and Failsafe

Page 8: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Staff Authentication

Page 9: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Staff Accountability & Audit

Page 10: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Checkpoint with Authentication and Accounting

Page 11: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Limit Authority – Authorize Commands

Page 12: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Set Privileges

Page 13: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Checkpoint with default Authorization

Page 14: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Note on Privilege Levels and Authorization

Page 15: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

One Time Password – Checking the ID

Page 16: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What is One Time Password

Page 17: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

DoS the AAA Infrastructure

Page 18: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

How to protect the AAA Servers?

Page 19: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Source Routing

Page 20: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

ICMP Unreachable Overload

Page 21: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

ICMP Unreachable Overload

Page 22: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

ICMP Unreachable Overload

Page 23: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

ICMP Unreachable Rate-Limiting

Page 24: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Tip: scheduler allocate

Page 25: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Introducing a New Router tothe Network

Page 26: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Introducing a New Router tothe Network

Page 27: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Secure Template Sources

Page 28: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Input Hold Queue

Page 29: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Input Hold Queue

Page 30: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Input Hold Queue

Page 31: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What Ports Are open on the Router?

Page 32: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What Ports Are open on the Router?

Page 33: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What Ports Are open on the Router?

Page 34: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Receive ACL - Overview

Page 35: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Receive Adjacencies

Page 36: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Receive ACL Command

Page 37: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Receive ACL

Page 38: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Receive Path ACL

Page 39: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Packet Flow

Page 40: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Receive ACL – Traffic Flow

Page 41: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL Processing

Page 42: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL – Required Entries

Page 43: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL – Required Entries

Page 44: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL – Building Your ACL

Page 45: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Filtering Fragments

Page 46: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL – Iterative Deployment

Page 47: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Classification ACL Example

Page 48: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL – Iterative Deployment

Page 49: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL – Iterative Deployment

Page 50: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL – Iterative Deployment

Page 51: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL – Sample Entries

Page 52: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL – Sample Entries

Page 53: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

rACL – Sample Entries

Page 54: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Use Detailed Logging

Page 55: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Core Dumps

Page 56: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Core Dumps

Page 57: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Routing Protocol Security Why to Prefix Filter and Overview? (Threats) How to Prefix Filter? Where to Prefix Filter? Prefix Filter on Customers Egress Filter to Peers Ingress Filter from Peers Protocol Authentication (MD5) BGP BCPs that help add Resistance

Page 58: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Routing Protocol Security

Page 59: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Malicious Route InjectionPerceive Threat

Page 60: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Malicious Route InjectionReality – an Example

Page 61: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Garbage in – Garbage Out: What is it?

Page 62: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Garbage in – Garbage Out: Results

Page 63: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Garbage in – Garbage Out: Impact

Page 64: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Garbage in – Garbage Out: What to do?

Page 65: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Malicious Route InjectionAttack Methods

Page 66: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Malicious Route InjectionImpact

Page 67: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What is a prefix hijack?

Page 68: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Malicious Route InjectionWhat can ISPs Do?

Page 69: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Malicious Route InjectionWhat can ISPs Do?

Page 70: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Malicious Route InjectionWhat can ISPs Do?

Page 71: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What can ISPs Do?Containment Egress Prefix Filters

Page 72: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What can ISPs Do?Containment Egress Prefix Filters

Page 73: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What can ISPs Do?Containment Egress Prefix Filters

Page 74: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Malicious Route InjectionWhat can ISPs Do?

Page 75: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

How to Prefix Filter?Ingress and Egress Route Filtering

Page 76: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Ingress and Egress Route Filtering

Page 77: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Ingress and Egress Route Filtering

Page 78: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Ingress and Egress Route Filtering

Page 79: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Ingress and Egress Route Filtering

Page 80: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Two Filtering Techniques

Page 81: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Ideal Customer Ingress/Egress Route Filtering ….

Page 82: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

BGP Peering Fundamental

Page 83: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Guarded Trust

Page 84: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Where to Prefix Filter?

Page 85: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Where to Prefix Filter?

Page 86: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What to Prefix Filter? Documenting Special Use Addresses (DUSA) and Bo

gons

Page 87: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Documenting Special Use Addresses (DUSA)

Page 88: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Documenting Special Use Addresses (DUSA)

Page 89: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Documenting Special Use Addresses (DUSA)

Page 90: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Bogons

Page 91: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Ingress Prefix Filter Template

Page 92: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Ingress Prefix Filter Template

Page 93: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Prefix Filters on Customers

Page 94: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

BGP with Customer Infers Multihoming

Page 95: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Receiving Customer Prefixes

Page 96: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Receiving Customer Prefixes

Page 97: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Excuses – Why providers are not prefix filtering customers.

Page 98: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What if you do not filter your customer?

Page 99: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

What if you do not filter your customer?

Page 100: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Prefixes to Peers

Page 101: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Prefixes to Peers

Page 102: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Egress Filter to ISP Peers - Issues

Page 103: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Policy Questions

Page 104: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Ingress Prefix Filtering fromPeers

Page 105: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Ingress Routes from Peers or Upstream

Page 106: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Receiving Prefixes from Upstream & Peers (ideal case)

Page 107: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Receiving Prefixes — Cisco IOS

Page 108: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Net Police Route Filtering

Page 109: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Net Police Route Filtering

Page 110: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Net Police Filter Technique #1

Page 111: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Technique #1 Net Police Prefix List

Page 112: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Net Police Prefix List Deployment Issues

Page 113: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Technique #2 Net Police Prefix List Alternative

Page 114: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Technique #2 Net Police Prefix List Alternative

Page 115: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Net Police Filter – Technique #3

Page 116: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Technique #3 Net Police Prefix List

Page 117: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Net Police Filter – Technique #3

Page 118: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Bottom Line

Page 119: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Secure RoutingRoute Authentication

Page 120: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Plain-text neighbor authentication

Page 121: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

MD-5 Neighbor Authentication: Originating Router

Page 122: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

MD-5 Neighbor Authentication: Originating Router

Page 123: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Peer Authentication

Page 124: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Peer Authentication

Page 125: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

OSPF Peer Authentication

Page 126: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

OSPF and ISIS Authentication Example

Page 127: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

BGP Peer Authentication

Page 128: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

BGP Peer Authentication

Page 129: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

BGP MD5’s Problem

Page 130: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

BGP BCPs That Help Build Security Resistance

Page 131: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

BGP Maximum Prefix Tracking

Page 132: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

BGP Maximum Prefix Tracking

Page 133: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

BGP Maximum Prefix Tracking

Page 134: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Avoid Default Routes

Page 135: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Network with Default Route – Pointing to Upstream A

Page 136: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Network with Default Route – But not Pointing to Upstream

Page 137: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Network with No Default Route

Page 138: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Default Route and ISP Security - Guidance

Page 139: Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos

Default to a Sink-Hole Router/Network