<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CBAC on 2921 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818194#M456089</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ajay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the info. I´m not sure if i got you. If i remove the ACLtoLAN the returning packets are&lt;/P&gt;&lt;P&gt;coming in of course, but this would allow any other incoming packets as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The router is doing IPSec to several private networks and NAT to the internet; beside from that&lt;/P&gt;&lt;P&gt;it terminates a 802.1q-trunk, where one subinterface acts as a gateway to a Wireless LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don´t want to let incoming traffic in from these networks to GigabitEthernet0/0; just returning&lt;/P&gt;&lt;P&gt;traffic orginated from g0/0 should be allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This has worked with IOS 12.4T on a 2811 platform using the configuration i´ve depicted here,&lt;/P&gt;&lt;P&gt;but after migrating it to IOS 15.2T it seems to be that CBAC does not dynamically open the&lt;/P&gt;&lt;P&gt;ports for returning traffic destined for g0/0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas how to get this working again? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 29 Jan 2012 08:18:19 GMT</pubDate>
    <dc:creator>Frank Hobrecht</dc:creator>
    <dc:date>2012-01-29T08:18:19Z</dc:date>
    <item>
      <title>CBAC on 2921</title>
      <link>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818192#M456087</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i´ve migrated a working IOS configuration from an 2811 (12.4) to a 2921 (15.2(2)T) and it seems that&lt;/P&gt;&lt;P&gt;CBAC is behaving different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect log drop-pkt&lt;/P&gt;&lt;P&gt;ip inspect name OUTBOUND tcp&lt;/P&gt;&lt;P&gt;ip inspect name OUTBOUND ftp&lt;/P&gt;&lt;P&gt;ip inspect name OUTBOUND udp&lt;/P&gt;&lt;P&gt;ip inspect name OUTBOUND pptp&lt;/P&gt;&lt;P&gt;ip inspect name OUTBOUND icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;description Internal Network&lt;/P&gt;&lt;P&gt;ip address 10.20.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip access-group ACLtoLAN out&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ip nat inside&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip inspect OUTBOUND in&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ip virtual-reassembly in&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended ACLtoLAN&lt;/P&gt;&lt;P&gt;remark Outgoing Traffic to LAN&lt;/P&gt;&lt;P&gt;permit ip 10.21.0.0 0.0.1.255 any&lt;/P&gt;&lt;P&gt;deny&amp;nbsp;&amp;nbsp; ip any any log-input&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic initiated from the inside LAN (GigabitEthernet0/0) should be inspected by OUTBOUND rule, so returning&lt;/P&gt;&lt;P&gt;packets should be allowed going out of g0/0 back to the LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this is not working anymore on the 2921 under IOS 15. The returning packets are now being blocked by the&lt;BR /&gt;ACL ACLtoLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:20:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818192#M456087</guid>
      <dc:creator>Frank Hobrecht</dc:creator>
      <dc:date>2019-03-11T22:20:28Z</dc:date>
    </item>
    <item>
      <title>CBAC on 2921</title>
      <link>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818193#M456088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Frank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think in CBAC feature this does allow return traffic on inbound interface. You can check by removing -&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip access-group ACLtoLAN out&lt;/STRONG&gt; this command and put &lt;STRONG&gt;deny any any on outside interface.&lt;/STRONG&gt; configuring in/out on same interface i something manually opening the ports bi-directional.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Jan 2012 07:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818193#M456088</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2012-01-29T07:40:42Z</dc:date>
    </item>
    <item>
      <title>CBAC on 2921</title>
      <link>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818194#M456089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ajay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the info. I´m not sure if i got you. If i remove the ACLtoLAN the returning packets are&lt;/P&gt;&lt;P&gt;coming in of course, but this would allow any other incoming packets as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The router is doing IPSec to several private networks and NAT to the internet; beside from that&lt;/P&gt;&lt;P&gt;it terminates a 802.1q-trunk, where one subinterface acts as a gateway to a Wireless LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don´t want to let incoming traffic in from these networks to GigabitEthernet0/0; just returning&lt;/P&gt;&lt;P&gt;traffic orginated from g0/0 should be allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This has worked with IOS 12.4T on a 2811 platform using the configuration i´ve depicted here,&lt;/P&gt;&lt;P&gt;but after migrating it to IOS 15.2T it seems to be that CBAC does not dynamically open the&lt;/P&gt;&lt;P&gt;ports for returning traffic destined for g0/0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas how to get this working again? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Jan 2012 08:18:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818194#M456089</guid>
      <dc:creator>Frank Hobrecht</dc:creator>
      <dc:date>2012-01-29T08:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: CBAC on 2921</title>
      <link>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818195#M456090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok Let me try to explain -might help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---------&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACL IN (permit any any)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface LAN --------------------&amp;nbsp; Interface ANY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACL IN (deny any any)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;---------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt; ---------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Suppose things are allowed from LAN to any interface and deny on interface from return traffic is coming. Here inpection should work and ignore deny any any and return traffic will not be blocked by ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me add one more statement - you need to identify two interfaces on router internal or external to make it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With your current config if you feel CBAC feature is not working- These command can help you to verify use-&lt;EM&gt;&lt;STRONG&gt;show ip inspect session&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other Show Commands &lt;/P&gt;&lt;P&gt;show ip inspect config &lt;/P&gt;&lt;P&gt;show ip inspect interfaces &lt;/P&gt;&lt;P&gt;show ip inspect stat &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug Commands &lt;/P&gt;&lt;P&gt;debug ip inspect detail &lt;/P&gt;&lt;P&gt;debug ip inspect tcp &lt;/P&gt;&lt;P&gt;debug ip inspect object-cre &lt;/P&gt;&lt;P&gt;debug ip inspect object-del &lt;/P&gt;&lt;P&gt;debug ip inspect event &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Jan 2012 08:29:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818195#M456090</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2012-01-29T08:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: CBAC on 2921</title>
      <link>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818196#M456091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What you´ve described is how it currently works; there are already IN access lists with a&lt;/P&gt;&lt;P&gt;deny any any on all the other interfaces of the router, example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Serial0/0/0.50 point-to-point&lt;/P&gt;&lt;P&gt;description Internet&lt;/P&gt;&lt;P&gt;ip address &lt;REMOVED&gt;&lt;/REMOVED&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip access-group int-acl_internet in&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ip nat outside&lt;/P&gt;&lt;P&gt;ip virtual-reassembly&lt;/P&gt;&lt;P&gt;frame-relay interface-dlci &lt;REMOVED&gt;&lt;/REMOVED&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;crypto map vpn&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem here is that this incoming access list cannot examine the ESP payload; so when&lt;/P&gt;&lt;P&gt;traffic from the VPN is coming in, the encrypted packets are first traversing the IN access-list &lt;/P&gt;&lt;P&gt;(and are allowed there, because the destination is the router itself), before they are decrypted&lt;/P&gt;&lt;P&gt;and forwarded to the other interfaces (in this case the g0/0). In other words: It makes no sense &lt;/P&gt;&lt;P&gt;to modify this IN ACL by CBAC, because the returning packets are all encrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i need to have a mechanism that unwanted traffic initiated from outside (VPN) networks will &lt;/P&gt;&lt;P&gt;be prevented from beeing forwarded to the private segment behind g0/0, and this was the OUT&lt;/P&gt;&lt;P&gt;access list in conjunction with CBAC which worked perfect under 12.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Jan 2012 09:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-on-2921/m-p/1818196#M456091</guid>
      <dc:creator>Frank Hobrecht</dc:creator>
      <dc:date>2012-01-29T09:37:07Z</dc:date>
    </item>
  </channel>
</rss>

