Cisco Router Security Solutions
Total Page:16
File Type:pdf, Size:1020Kb
Cisco Router Security Solutions Technical Overview STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 1 Cisco Router Security Portfolio Service Integration 3800 Series Scaled to Fit Every Size Branch Office 3200 Series 2800 Series High Density and Performance for 1800 Series Concurrent Services Rugged and 800 Series Mobile Applications Embedded, Advanced Voice, Video, Data, and Security Services Performance and Services Density Services and Performance Embedded Wireless, Security, and Data Small Office and Medium Mobile/Rugged Medium to Teleworker Small Branch Branch Branch Large Branch STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 2 Only Cisco Router Security Delivers All This Secure Network Solutions Business Secure Secure Compliance Continuity Voice Mobility Integrated Threat Management 011111101010101 Advanced Content Intrusion Flexible Network Network 802.1x Firewall Filtering Prevention Packet Admission Foundation Matching Control Protection Secure Connectivity Management and Instrumentation Role-Based CCP NetFlow IP SLA GET VPN DMVPN Easy VPN SSL VPN Access STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 3 Cisco Router Security Certifications FIPS Common Criteria 140-2, Firewall IPSec (EAL4) Level 2 (EAL4) Cisco® 870 ISR Cisco 1800 ISR Cisco 2800 ISR Cisco 3800 ISR Cisco 7200 VAM2+ Cisco 7200 VSA --- Cisco 7301 VAM2+ Cisco 7600 IPSec VPN SPA --- Catalyst 6500 IPSec VPN SPA --- Cisco 7600 cisco.com/go/securitycert STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 4 Cisco Router Security Leadership in Innovation Industry First Cisco Integrated Services Router Innovations in Security . Industry-leading integration of VPN, routing, and QoS: DMVPN, GET VPN, SSL VPN, and Easy VPN . Router-embedded security services: Application firewall, IPS, and URL filtering . Cisco® Configuration Professional (CCP) with one- touch lockdown and security audit . Router-integrated voice and security . Router-integrated wireless with advanced security . Router-integrated switching; Layer 2/3 security . Secure WAN backup over DSL, cable, 3G, or satellite STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 5 Top Reasons to Buy Router Security 1. PROTECT THE ROUTER ITSELF – your first line of defense 2. A SINGLE BREACH could gravely impact the business 3. Advanced backup and teleworking for DISASTER RECOVERY 4. COMPLY with Government data and network privacy laws 5. Consolidate voice/video/data and wired/wireless SECURELY 6. Advanced ENCRYPTION for voice conversations and signaling 7. New ISRs deliver wire-rate PERFORMANCE WITH SERVICES 8. Easy to MANAGE a single-box Router/VPN/Firewall/IPS solution 9. REDUCE COST of service and subscription: single contract 10. 30-40% SAVINGS built into Security Router bundles STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 6 Cisco 800–3800 Security Router Bundles High Performance Voice and Security (HVSEC) . Security . Voice DSPs and Voice Gateway All Security Bundles have: . High Performance IPsec Acceleration and Compression . Cisco CallManager Express / Survivable Remote Site . Site-to-Site VPN and Remote Access VPN Telephony License . Embedded IPsec acceleration High Performance Secure Voice . SSL VPN* Security (HSEC) (VSEC)† ‡ . ICSA & EAL4 certified . Security . Security Advanced Firewall . No Voice DSPs . Voice DSPs and . High Performance Gateway . IPS IPsec Acceleration . Embedded IPsec . SDM, NetFlow Acceleration and Compression . WAN Backup, Router Availability and Service Protection Basic Security (SEC) . Security . No Voice DSPs . Embedded IPsec Acceleration * 10-25 user license included free on HSEC; additional licenses † Survivable Remote Site Telephony (SRST) version available $30 per user ‡ Cisco CallManager Express (CCME) version available STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 7 Integrated Threat Control Integrated Advanced Content Intrusion Flexible Network Network Threat Control 802.1x Firewall Filtering Prevention Packet Admission Foundation Matching Control Protection 011111101010101 STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 8 Integrated Threat Control Overview Industry-Certified Security Embedded Within the Network . Access branch Router Protection office has secure • Automated router lockdown Internet access and • Router availability during DoS no need for Hacker additional devices . Solution controls Branch Office worms, viruses, Branch Office Corporate Office and spyware right 011111101010101 at the remote site; Internet Content Security • Advanced Layer conserves WAN 3–7 firewall Illegal bandwidth Surfing • P2P and IM Malware Prevention control • Integrated IPS for • Reputation based . Solution protects distributed defense and content filtering the router itself rapid response • Control of wired and from hacking and wireless user access DoS attacks and noncompliant Small Office and devices Telecommuter STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 9 Cisco IOS Firewall Stateful Firewall: Full Layer three through Layer seven deep packet inspection Select List of Flexible Embedded ALG (Application Layer Recognized Protocols Gateway): Dynamic protocol and application . HTTP, HTTPS, JAVA engines for seamless granular control . Email: POP, SMTP, IMAP, Lotus Application Inspection and Control: Visibility . P2P and IM (AIM, MSN, Yahoo!) into both control and data channels to ensure . FTP, TFTP, Telnet protocol and application conformance . Voice: H.323, SIP, SCCP Virtual Firewall: Separation between virtual . Database: Oracle, SQL, MYSQL contexts, addressing overlapping IP addresses . Citrix: ICA, CitrixImaClient Intuitive GUI Management: Easy policy setup . Multimedia: Apple, RealAudio and refinement with SDM and CSM . IPsec VPN: GDOI, ISAKMP Resiliency: High availability for users and . Microsoft: MSSQL, NetBIOS applications with stateful firewall failover . Tunneling: L2TP, PPTP WAN Interfaces: Most WAN/LAN interfaces STGPresentation_ID-Router-Security © 20072006 Cisco Systems, Inc. All rights reserved. Cisco Confidential 10 Advanced Zone-Based Policy Firewall Firewall . Allows grouping of physical and Supported Features virtual interfaces into zones . Stateful Inspection . Application Inspection: IM, POP, . Firewall policies are configured on IMAP, SMTP/ESMTP, HTTP traffic moving between zones . URL filtering . Per-policy parameter . Simple to add or remove interfaces . Transparent firewall and integrate into firewall policy . VRF-aware firewall Private-DMZ Policy DMZ Private-DMZ Public-DMZ Policy Policy Trusted Internet Untrusted Private-Public Policy STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 11 Advanced Application Inspection and Control Firewall . Multichannel inspection Cisco IOS Firewall-Recognized –Recognizes application-specific Application-Layer Protocols protocols including control and . CU-SeeMe (cuseeme) data channels . FTP (ftp) –Detects and prevents . Java (http) application-level attacks . H.323 (h323) . Microsoft NetShow (netshow) . Protocol conformance . RealAudio (realaudio) Checks varying levels depending . Remote-procedure call (rpc) on the specific protocol . Session Initiation Protocol (sip) . Skinny Client Control Protocol (skinny) . Protocol control . Simple Mail Transfer Protocol (smtp/esmtp) . StreamWorks (streamworks) Granular enforcement for HTTP . Structured Query Language*Net (sqlnet) and P2P . TFTP (tftp) For example, permit PUTs but . UNIX R commands (rcmd) deny GETs . VDOLive (vdolive) . POP3 and IMAP (pop3 and imap) . Application Firewall (appfw) . UserDefined (user defined name) STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 12 Advanced Cisco IOS Firewall Voice Features Firewall Protocol Supported Comments Tested using CME 4.0 H.323 V1 & V2 Yes Locally generated/terminated traffic supported H.323 V3 & V4 No H.323 RAS Yes In 12.4(11)T H.323 T.38 Fax No CCM 4.2 supported SIP UDP Yes RFC 2543, RFC 3261 not supported SIP TCP No SCCP Yes Tested with CCM 4.2/CME 4.0 Locally generated traffic No inspection for SIP/SCCP Note: Cisco® ASA supports H.323 V3 and V4, T.38 Fax and SIP TCP STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 13 Advanced Denial of Service (DoS) Protection Firewall . DoS protection is enabled by default on Cisco® IOS® Firewall and IPS . Activating Cisco IOS IPS or Firewall (independently or together) causes these default DoS settings to be used: ip inspect max-incomplete high value (default 500) ip inspect max-incomplete low value (default 400) ip inspect one-minute high value (default 500) ip inspect one-minute low value (default 400) ip inspect tcp max-incomplete host value (default 50) [block-time minutes] . If DoS counters are not adjusted, users may see slow network performance and high router CPU . Firewall and IPS Design Guides include tuning procedure Design Guide : http://www.cisco.com/go/iosfw During lab performance tests, be sure to set DoS settings at maximum STG-Router-Security © 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential 14 Industry-First Firewall + WAN Acceleration Advanced Interoperability Solution Firewall . Full stateful firewall transparently protects WAN accelerated traffic . For integrated