Inspection, Threat Detection & IPS Concepts

Cisco ASA Firewall EVE-NG — ASAv (CLI + ASDM)

مقصدObjectiveObjective

Application traffic inspect کرنے کے لیے MPF use کریں، basic اور scanning threat detection enable کریں، اور سمجھیں FirePOWER ASA میں IPS کیسے add کرتا ہے۔Application traffic inspect karne ke liye MPF use karo, basic aur scanning threat detection enable karo, aur samjho FirePOWER ASA mein IPS kaise add karta hai.Use MPF to inspect application traffic, enable basic and scanning threat detection, and understand how FirePOWER adds IPS to the ASA.

آسان مثالSimple AnalogySimple Analogy

Modular Policy Framework گارڈ کی rulebook binder ہے جس میں tabs ہیں: ایک tab کہتی ہے کون سا traffic پکڑو (class-map)، دوسری کہتی ہے اس کے ساتھ کیا کرو (policy-map)، اور آخری کہتی ہے binder کن gates پر apply ہو۔Modular Policy Framework guard ki rulebook binder hai jisme tabs hain: ek tab kehti hai kaun sa traffic pakro (class-map), doosri kehti hai uske sath kya karo (policy-map), aur aakhri kehti hai binder kin gates par apply ho (service-policy).The Modular Policy Framework is the guard's rulebook binder with tabs: one tab says which traffic to grab (class-map), another says what to do with it (policy-map), and the last says which gates the binder applies to (service-policy).

سیٹ اپLab SetupLab Setup

پچھلی labs والا ASAv۔ ہم custom policy پر FTP inspect کریں گے، پھر threat detection on کرکے simulated scan میں observe کریں گے۔Pichli labs wala ASAv. Hum custom policy par FTP inspect karenge, phir threat detection on karke simulated scan mein observe karenge.ASAv from earlier labs. We will inspect FTP on a custom policy, then turn on threat detection and observe it under a simulated scan.

اقداماتStepsSteps

Step 1

MPF policy بنائیں: FTP traffic match کرنے والا class-map، اور policy-map جو اس پر FTP application inspection apply کرے۔MPF policy banao: FTP traffic match karne wala class-map, aur policy-map jo us par FTP application inspection apply kare.Build an MPF policy: a class-map matching FTP traffic, and a policy-map that applies FTP application inspection to it.

class-map FTP_TRAFFIC
match port tcp eq ftp
exit
policy-map FTP_INSPECT
class FTP_TRAFFIC
inspect ftp
exit
exit

Step 2

Policy کو inside interface پر attach کریں۔ Service-policy binding کے بغیر policy-map کچھ نہیں کرتا۔Policy ko inside interface par attach karo. Service-policy binding ke baghair policy-map kuch nahi karta.Attach the policy to the inside interface. Without the service-policy binding, the policy-map does nothing.

service-policy FTP_INSPECT interface inside

Step 3

Verify کریں MPF policy attached ہے اور per-class packet counters دیکھیں — proof کہ inspection engine traffic process کر رہا ہے۔Verify karo MPF policy attached hai aur per-class packet counters dekho — proof ke inspection engine traffic process kar raha hai.Verify the MPF policy is attached and see per-class packet counters — proof the inspection engine is processing the traffic.

show service-policy

Step 4

Basic threat detection اور scanning threat detection enable کریں، attackers کی automatic shunning کے ساتھ (اپنے inside LAN کو except کرکے تاکہ خود lock out نہ ہوں)۔Basic threat detection aur scanning threat detection enable karo, attackers ki automatic shunning ke sath (apne inside LAN ko except karke taake khud lock out na ho).Enable basic threat detection and scanning threat detection, with automatic shunning of attackers (except your inside LAN so you can't lock yourself out).

threat-detection basic-threat
threat-detection scanning-threat shun except ip-address 10.1.1.0 255.255.255.0

🖱️ ASDM: Monitoring > Properties > Threat Detection — drops، scans اور shunned hosts کے graphs۔ASDM: Monitoring > Properties > Threat Detection — drops, scans aur shunned hosts ke graphs.ASDM: Monitoring > Properties > Threat Detection — graphs of drops, scans, and shunned hosts.

Step 5

Threat-detection statistics اور shun list دیکھیں۔ Test host سے port scan چلائیں اور counters اور shun entries کو appear ہوتے دیکھیں۔Threat-detection statistics aur shun list dekho. Test host se port scan chalao aur counters aur shun entries ko appear hote dekho.View threat-detection statistics and the shun list. Run a port scan from a test host and watch the counters and shun entries appear.

show threat-detection rate
show threat-detection shun

Step 6

FirePOWER concept: ASA ایک FirePOWER (SFR) module host کر سکتا ہے جو next-gen IPS، URL filtering اور malware inspection add کرتا ہے۔ Traffic MPF `sfr` action سے module کی طرف redirect ہوتا ہے — hardware ASA topic، ASAv labs میں concept-only۔FirePOWER concept: ASA ek FirePOWER (SFR) module host kar sakta hai jo next-gen IPS, URL filtering aur malware inspection add karta hai. Traffic MPF `sfr` action se module ki taraf redirect hota hai — hardware ASA topic, ASAv labs mein concept-only.FirePOWER concept: the ASA can host a FirePOWER (SFR) module that adds next-gen IPS, URL filtering, and malware inspection. Traffic is redirected to the module via an MPF `sfr` action — a hardware ASA topic, concept-only on ASAv labs.

Step 7

Configuration save کریں۔Configuration save karo.Save the configuration.

write memory

تصدیقVerifyVerify

`show service-policy` میں FTP policy inside پر attached نظر آئے counters کے ساتھ، اور test scan کے بعد `show threat-detection rate` میں live statistics ہوں۔`show service-policy` mein FTP policy inside par attached nazar aaye counters ke sath, aur test scan ke baad `show threat-detection rate` mein live statistics hon.`show service-policy` shows the FTP policy attached to inside with counters, and `show threat-detection rate` shows live statistics after a test scan.

show service-policy
show threat-detection rate
show threat-detection shun

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ ACL port 21 permit کرتی ہے پھر بھی ASA سے FTP transfers fail ہو رہے ہیں۔ACL port 21 permit karti hai phir bhi ASA se FTP transfers fail ho rahe hain.FTP transfers fail through the ASA even though the ACL permits port 21.

✅ FTP کو اپنے dynamic data ports کے لیے application inspection چاہیے۔ Ensure کریں `inspect ftp` active policy-map میں ہے (`show service-policy`) — اس کے بغیر data-channel connections drop ہوتی ہیں۔FTP ko apne dynamic data ports ke liye application inspection chahiye. Ensure karo `inspect ftp` active policy-map mein hai (`show service-policy`) — iske baghair data-channel connections drop hoti hain.FTP needs application inspection for its dynamic data ports. Ensure `inspect ftp` is in the active policy-map (`show service-policy`) — without it, data-channel connections are dropped.

⚠️ Legitimate vulnerability scanner shun ہو گیا اور اب اس کا traffic drop ہو رہا ہے۔Legitimate vulnerability scanner shun ho gaya aur ab uska traffic drop ho raha hai.A legitimate vulnerability scanner got shunned and now its traffic is dropped.

✅ `no shun <ip>` (یا `clear threat-detection shun`) سے ہٹائیں، پھر scanner کے IP کو scanning-threat except list میں add کریں تاکہ دوبارہ shun نہ ہو۔`no shun <ip>` (ya `clear threat-detection shun`) se hatao, phir scanner ke IP ko scanning-threat except list mein add karo taake dobara shun na ho.Remove it with `no shun <ip>` (or `clear threat-detection shun`), then add the scanner's IP to the scanning-threat except list so it isn't shunned again.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ Modular Policy Framework کیا ہے اور اس کے تین parts کون سے ہیں؟Modular Policy Framework kya hai aur iske teen parts kaun se hain?What is the Modular Policy Framework and its three parts?

MPF class-maps سے traffic classify کرتا ہے، policy-maps میں actions define کرتا ہے (inspect، police، connection limits)، اور service-policy سے policy interfaces پر attach کرتا ہے۔ Global default policy پہلے سے DNS، FTP، HTTP جیسے common protocols inspect کرتی ہے۔MPF class-maps se traffic classify karta hai, policy-maps mein actions define karta hai (inspect, police, connection limits), aur service-policy se policy interfaces par attach karta hai. Global default policy pehle se DNS, FTP, HTTP jaise common protocols inspect karti hai.MPF classifies traffic with class-maps, defines actions in policy-maps (inspect, police, set connection limits), and attaches the policy to interfaces with service-policy. The global default policy already inspects common protocols like DNS, FTP, and HTTP.

❓ ASA پر basic اور scanning threat detection میں کیا فرق ہے؟ASA par basic aur scanning threat detection mein kya farq hai?What is the difference between basic and scanning threat detection on the ASA?

Basic threat detection ہر interface پر dropped packets، scans اور SYN attacks کی rates track کرتا ہے؛ scanning threat detection port/host sweeps کرنے والے hosts track کرتا ہے اور attackers کو automatically shun کر سکتا ہے۔ `threat-detection basic-threat` اور `threat-detection scanning-threat` سے enable کریں۔Basic threat detection har interface par dropped packets, scans aur SYN attacks ki rates track karta hai; scanning threat detection port/host sweeps karne wale hosts track karta hai aur attackers ko automatically shun kar sakta hai. `threat-detection basic-threat` aur `threat-detection scanning-threat` se enable karo.Basic threat detection tracks rates of dropped packets, scans, and SYN attacks per interface; scanning threat detection tracks hosts doing port/host sweeps and can shun attackers automatically. Enable with `threat-detection basic-threat` and `threat-detection scanning-threat`.