Advanced Security: ACLs & Control-Plane Protection
CCIE Enterprise Infrastructure EVE-NG / GNS3
مقصدObjectiveObjective
اس سبق کے بعد آپ advanced ACLs لکھ سکیں گے، CoPP سے control plane محفوظ کر سکیں گے، اور spoofing کے خلاف uRPF لگا سکیں گے۔Is lesson ke baad aap advanced ACLs likh sakenge, CoPP se control plane mehfooz kar sakenge, aur spoofing ke khilaf uRPF laga sakenge.After this lesson you will be able to write advanced ACLs, protect the control plane with CoPP, and deploy uRPF against spoofing.
آسان مثالSimple AnalogySimple Analogy
ACL عمارت کے security guards ہیں — ہر دروازے پر ID چیک۔ CoPP مینیجر کے دفتر کے دروازے پر guard ہے: زیادہ مہمانوں سے مینیجر بھی پریشان نہیں ہو سکتا۔ uRPF چیک کرتا ہے کہ مہمان واقعی اسی دروازے سے آیا ہے۔ACL building ke security guards hain — har darwaze par ID check. CoPP manager ke daftar ke darwaze par guard hai: zyada mehmanon se manager bhi pareshan nahi ho sakta. uRPF check karta hai ke mehman waqai usi darwaze se aaya hai.ACLs are the building's security guards — checking ID at every door. CoPP is the guard at the manager's office door: even the manager can't be overwhelmed by too many visitors. uRPF checks whether the visitor actually came through that entrance.
سیٹ اپLab SetupLab Setup
دو روٹرز لیں ایک client segment کے ساتھ۔ ACL hits، ٹریفک flood میں CoPP drops، اور spoofed-source packets ٹیسٹ کریں گے۔Do routers lein ek client segment ke saath. ACL hits, traffic flood mein CoPP drops, aur spoofed-source packets test karenge.Use two routers with a client segment. You'll test ACL hits, CoPP drops under a traffic flood, and spoofed-source packets.
اقداماتStepsSteps
Step 1
Named extended ACLs source، destination، protocol اور port کے حساب سے deny/permit دیتے ہیں۔ 'log' keyword matches کو syslog میں record کرتا ہے۔Named extended ACLs source, destination, protocol aur port ke hisab se deny/permit dete hain. 'log' keyword matches ko syslog mein record karta hai.Named extended ACLs allow deny/permit by source, destination, protocol, and port. The 'log' keyword records matches in syslog.
ip access-list extended FILTER-TRAFFIC deny ip 192.168.1.0 0.0.0.255 10.0.0.0 0.255.255.255 permit tcp any host 10.0.0.1 eq 443 permit ip any any log
Step 2
Time-based ACLs مخصوص وقت میں access limit کرتی ہیں — جیسے صرف کام کے اوقات میں internet access۔Time-based ACLs makhsoos waqt mein access limit karti hain — jaise sirf kaam ke auqaat mein internet access.Time-based ACLs restrict access to specific hours — e.g. internet access only during work hours.
ip access-list extended HTTP-ONLY permit tcp any any eq www deny ip any any time-range WORK-HOURS time-range WORK-HOURS periodic weekdays 9:00 to 17:00
Step 3
CoPP مرحلہ 1: control-plane ٹریفک کو critical (OSPF/BGP)، normal (SSH/SNMP) اور undesired میں classify کریں۔CoPP step 1: control-plane traffic ko critical (OSPF/BGP), normal (SSH/SNMP) aur undesired mein classify karein.CoPP step 1: classify control-plane traffic into critical (OSPF/BGP), normal (SSH/SNMP), and undesired.
ip access-list extended COPP-CRITICAL permit ospf any any permit bgp any any permit icmp any any echo ip access-list extended COPP-NORMAL permit tcp any any eq 22 permit udp any any eq 161 class-map match-all COPP-CRIT-CLASS match access-group name COPP-CRITICAL class-map match-all COPP-NORM-CLASS match access-group name COPP-NORMAL
Step 4
CoPP مرحلہ 2: ہر class کو police کریں۔ Critical کو کھلا rate، باقی سب rate-limited۔ حملے کی صورت میں router زندہ رہتا ہے۔CoPP step 2: har class ko police karein. Critical ko khula rate, baqi sab rate-limited. Attack ki soorat mein router zinda rehta hai.CoPP step 2: police each class. Critical gets generous treatment, everything else is rate-limited. This keeps the router alive under attack.
policy-map COPP-POLICY class COPP-CRIT-CLASS police 8000 conform-action transmit exceed-action transmit class COPP-NORM-CLASS police 8000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY
Step 5
uRPF مرحلہ: وہ packets drop کریں جن کا source IP incoming انٹرفیس کے ذریعے واپس route نہیں رکھتا۔ اس سے spoofed source حملے رکتے ہیں۔uRPF step: wo packets drop karein jin ka source IP incoming interface ke zariye wapas route nahi rakhta. Is se spoofed source attacks rukte hain.uRPF step: drop packets whose source IP doesn't have a return route via the incoming interface. This blocks spoofed source attacks.
interface GigabitEthernet0/1 ip verify unicast source reachable-via rx show ip interface GigabitEthernet0/1 | include verify
Step 6
Verify کریں: ACL hit counts، CoPP policer statistics (load پر drops نظر آئیں)، انٹرفیس پر uRPF status۔Verify karein: ACL hit counts, CoPP policer statistics (load par drops nazar aayen), interface par uRPF status.Verify: ACL hit counts, CoPP policer statistics (drops visible under load), uRPF status on the interface.
show access-lists show policy-map control-plane show ip interface GigabitEthernet0/1
تصدیقVerifyVerify
یقین کریں کہ ACL hit counts بڑھ رہے ہیں، CoPP policers flood میں drops دکھا رہے ہیں، management ٹریفک گزر رہا ہے، اور edge interfaces پر uRPF active ہے۔Yaqeen karein ke ACL hit counts barh rahe hain, CoPP policers flood mein drops dikha rahe hain, management traffic guzar raha hai, aur edge interfaces par uRPF active hai.Confirm ACL hit counts increase, CoPP policers show drops under flood, management traffic passes, and uRPF is active on edge interfaces.
show access-lists show policy-map control-plane show ip verify source
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ ACL لگانے کے بعد درست ٹریفک بھی block ہو رہا ہے۔ACL lagane ke baad durust traffic bhi block ho raha hai.Legitimate traffic blocked after ACL applied.
✅ Direction چیک کریں (in vs out) اور آخر میں implicit deny — ایک permit line شامل کر کے دوبارہ ٹیسٹ کریں۔ Log سے مجرم کا پتا چلتا ہے۔Direction check karein (in vs out) aur akhir mein implicit deny — ek permit line shamil kar ke dobara test karein. Log se mujrim ka pata chalta hai.Check direction (in vs out) and the implicit deny at the end — add a permit line and retest. Log helps identify the culprit.
⚠️ uRPF asymmetric ٹریفک drop کر رہا ہے۔uRPF asymmetric traffic drop kar raha hai.uRPF dropping asymmetric traffic.
✅ جب routing asymmetric ہو تو strict کی بجائے loose mode (reachable-via any) استعمال کریں — strict صرف symmetric paths پر کام کرتا ہے۔Jab routing asymmetric ho to strict ki bajaye loose mode (reachable-via any) use karein — strict sirf symmetric paths par kam karta hai.Use loose mode (reachable-via any) instead of strict when routing is asymmetric — strict only works with symmetric paths.
⚠️ CoPP لگانے کے بعد SSH/SNMP نہیں کھل رہا۔CoPP lagane ke baad SSH/SNMP nahi khul raha.SSH/SNMP unreachable after CoPP applied.
✅ آپ کی normal class بہت سخت ہے۔ Management ٹریفک کے لیے policer نرم کریں یا اسے critical class میں شامل کریں۔Aap ki normal class bohat sakht hai. Management traffic ke liye policer naram karein ya use critical class mein shamil karein.Your normal class is too strict. Loosen the policer for management traffic or add it to the critical class.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ CoPP کیا محفوظ رکھتا ہے اور کیوں اہم ہے؟CoPP kya mehfooz rakhta hai aur kyun ahem hai?What does CoPP protect and why does it matter?
یہ control plane کی طرف جانے والے ٹریفک (routing protocols، management) کو کنٹرول کرتا ہے۔ حملے (DDoS) کی صورت میں CPU ختم ہونے سے بچاتا ہے تاکہ routing چلتی رہے۔Ye control plane ki taraf jane wale traffic (routing protocols, management) ko control karta hai. Attack (DDoS) ki soorat mein CPU khatam hone se bachata hai taake routing chalti rahe.It processes traffic destined for the control plane (routing protocols, management). Under attack (DDoS), it keeps the CPU from being exhausted so routing stays up.
❓ Strict اور loose uRPF سمجھائیں۔Strict aur loose uRPF samjhayein.Explain strict vs loose uRPF.
uRPF source IP کی تصدیق routing table سے کرتا ہے۔ Strict mode میں وہی انٹرفیس ضروری ہے جس پر packet آیا، loose mode میں کوئی بھی انٹرفیس جہاں route ہو کافی ہے۔uRPF source IP ki tasdeeq routing table se karta hai. Strict mode mein wahi interface zaroori hai jis par packet aaya, loose mode mein koi bhi interface jahan route ho kaafi hai.uRPF verifies the source IP by checking the routing table. Strict mode requires the exact receiving interface; loose mode allows any interface with a route.