Book description
Identify, analyze, and resolve current and potential network security problems
Learn diagnostic commands, common problems and resolutions, best practices, and case studies covering a wide array of Cisco network security troubleshooting scenarios and products
Refer to common problems and resolutions in each chapter to identify and solve chronic issues or expedite escalation of problems to the Cisco TAC/HTTS
Flip directly to the techniques you need by following the modular chapter organization
Isolate the components of a complex network problem in sequence
Master the troubleshooting techniques used by TAC/HTTS security support engineers to isolate problems and resolve them on all four security domains: IDS/IPS, AAA, VPNs, and firewalls
With the myriad Cisco® security products available today, you need access to a comprehensive source of defensive troubleshooting strategies to protect your enterprise network. Cisco Network Security Troubleshooting Handbook can single-handedly help you analyze current and potential network security problems and identify viable solutions, detailing each step until you reach the best resolution.
Through its modular design, the book allows you to move between chapters and sections to find just the information you need. Chapters open with an in-depth architectural look at numerous popular Cisco security products and their packet flows, while also discussing potential third-party compatibility issues. By following the presentation of troubleshooting techniques and tips, you can observe and analyze problems through the eyes of an experienced Cisco TAC or High-Touch Technical Support (HTTS) engineer or determine how to escalate your case to a TAC/HTTS engineer.
Part I starts with a solid overview of troubleshooting tools and methodologies. In Part II, the author explains the features of Cisco ASA and Cisco PIX® version 7.0 security platforms, Firewall Services Module (FWSM), and Cisco IOS® firewalls. Part III covers troubleshooting IPsec Virtual Private Networks (IPsec VPN) on Cisco IOS routers, Cisco PIX firewalls with embedded VPN functionalities, and the Cisco 3000 Concentrator. Troubleshooting tools and techniques on the Authentication, Authorization, and Accounting (AAA) framework are discussed thoroughly on routers, Cisco PIX firewalls, and Cisco VPN 3000 concentrators in Part IV. Part IV also covers troubleshooting Cisco Secure ACS on Windows, the server-side component of the AAA framework. IDS/IPS troubleshooting on IDS/IPS appliances, IDSM-2 blade, and NM-CIDS blade on Cisco IOS routers are covered in
Part V. In Part VI, the author examines the troubleshooting techniques for VPN/Security Management Solution (VMS) tools used for managing products from all four security domains in greater detail: IDS/IPS, AAA, VPNs, and firewalls.
Cisco Network Security Troubleshooting Handbook prepares you to troubleshoot your network’s security devices and presents step-by-step procedures for tackling issues that arise, so that you can protect your network.
This security book is part of the Cisco Press® Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks.
Table of contents
- Copyright
- About the Author
- Acknowledgments
- Icons Used in This Book
- Command Syntax Conventions
- Introduction
-
I. Troubleshooting Tools and Methodology
- 1. Troubleshooting Methods
- 2. Understanding Troubleshooting Tools
-
II. Troubleshooting Cisco Secure Firewalls
-
3. Troubleshooting Cisco Secure PIX Firewalls
- Overview of PIX Firewall
- Diagnostic Commands and Tools
- Problem Areas Breakdown
- Case Studies
- Common Problems and Resolutions
- Best Practices
-
4. Troubleshooting Firewall Services Module
- Overview of FWSM Firewall
- Diagnostic Commands and Tools
- Analysis of Problem Areas
-
Case Studies
- Case Study 1: Multiple SVI for FWSM
-
Case Study 2: Understanding Access-List Memory Utilization
- The Compilation Process: Active and Backup Trees
- How Memory Is Allocated: Release 1.1(x) or 2.2(1) in Single Mode
- How memory is Allocated: Release 2.2(1) in Multiple Mode
- Trees and contexts: A Matter of Mapping
- FWSM Release 2.3: The ACL Partition Manager
- Examples of ACL Compilation
- Access-lists: Best Practices
- Common Problems and Resolutions
- Best Practices
-
5. Troubleshooting an IOS Firewall
- Overview of IOS Firewall (CBAC)
- Diagnostic Commands and Tools
-
Categories of Problem Areas
- Selection of Software for IOS Firewall Issues
-
Unable to Connect (Inbound and Outbound) across CBAC
- Packet Failure to Reach the Router’s Incoming Interface
- Misconfigured ACL
- Misconfigured NAT and Routing
- IP Inspection Applied In the Wrong Direction
- UDP Inspection Is Not Configured
- Return Traffic Might Not Be Coming Back to the Router
- ICMP Traffic Is Not Inspected
- There Is a Problem with Inspecting Single Channel Protocol
- Required Multi-Channel Protocol is Not Inspected
- IP URL Filtering Blocking The Connection
- Redundancy or Asymmetric Routing Problems
- Performance Issues
- Intermittent Packet Drops
- IP URL Filtering Is Not Working
- Case Studies
- Common Problems and Resolutions
- Best Practices
-
3. Troubleshooting Cisco Secure PIX Firewalls
-
III. Troubleshooting Virtual Private Networks
-
6. Troubleshooting IPsec VPNs on IOS Routers
- Overview of IPsec Protocol
- Diagnostic Commands and Tools
- Analysis of Problem Areas
- Case Studies
- Common Problems and Resolutions
- Best Practices
- 7. Troubleshooting IPsec VPN on PIX Firewalls
-
8. Troubleshooting IPsec VPNs on VPN 3000 Series Concentrators
- Diagnostic Commands and Tools
- Analysis of Problem Areas
-
Case Studies
- Clientless SSL VPN
- Thin Client
- Thick Client (SSL VPN Client)
- Common Problems and Resolutions
- Best Practices
-
6. Troubleshooting IPsec VPNs on IOS Routers
-
IV. Troubleshooting Network Access Control
-
9. Troubleshooting AAA on IOS Routers
- Overview of Authentication, Authorization, and Accounting (AAA)
- Diagnostic Commands and Tools
- Analysis of Problem Areas
- Case Studies
- Common Problems and Resolutions
- Best Practices
-
10. Troubleshooting AAA on PIX Firewalls and FWSM
- Overview of Authentication, Authorization, and Accounting (AAA)
- Diagnostic Commands and Tools
-
Problem Areas Analysis
- Firewall Management with AAA Troubleshooting
- Cut-Through Proxy Authentication
- Extended Authentication (X-Auth) Issues for Remote Access VPN Connection
- Case Studies
- Common Problems and Resolutions
- Best Practices
-
11. Troubleshooting AAA on the Switches
- Overview of AAA
- Diagnostic Commands and Tools
- Categorization of Problem Areas
- Case Studies
- Common Problems and Resolutions
- Best Practices
-
12. Troubleshooting AAA on VPN 3000 Series Concentrator
- AAA Implementation on the Concentrator
- Diagnostic Commands and Tools
-
Analysis of Problem Areas
- VPN Concentrator Management Troubleshooting
-
Group/User Authentication (X-Auth) Troubleshooting
- Both Group and User Authentication Are Performed Locally on the VPN 3000 Concentrator
- Group Authentication Is Done Locally and No User Authentication Is Done
- Group Authentication Is Done Locally on VPN 3000 Concentrator and User Authentication Is Done with RADIUS Server
- Group Authentication Is Done with a RADIUS Server and User Authentication Is Done Locally
- Both Group and User Authentications Are Performed with the RADIUS Server
- User Is Locked to a Specific Group
- Dynamic Filters on the VPN 3000 Concentrator
- Configuration of Dynamic Filters on CiscoSecure ACS
- Troubleshooting Steps
- Case Studies
- Common Problems and Resolutions
- Best Practices
-
13. Troubleshooting Cisco Secure ACS on Windows
- Overview of CS ACS
- Diagnostic Commands and Tools
- Categorization of Problem Areas
- Case Studies
- User/NAS Import Options
- Common Problems and Resolutions
- Best Practices
-
9. Troubleshooting AAA on IOS Routers
-
V. Troubleshooting Intrusion Prevention Systems
-
14. Troubleshooting Cisco Intrusion Prevention System
- Overview of IPS Sensor Software
- Diagnostic Commands and Tools
-
Classification of Problem Areas
- Initial Setup Issues
- User Management Issues
- Software Installation and Upgrade Issues
- Licensing Issues
- Communication Issues
- Issues with Receiving Events on Monitoring Device
- Blocking Issues
- TCP Reset Issues
- Inline IPS Issues
- Case Studies
- Common Problems and Their Resolution
- Best Practices
-
15. Troubleshooting IDSM-2 Blade on Switch
- Overview of IDSM-2 Blade on the Switch
- Diagnostic Commands and Tools
-
Common Problems and Resolutions
- Hardware Issues
- Communication Issues with IDSM-2 Command and Control Port
-
Failing to Get Traffic from the Switch with Promiscuous Mode
-
Configuration Steps
- SPAN Configuration on Switch Running Native IOS
- VACL Configuration on Switch Running Native IOS
- MLS IP IDS Configuration on Switch Running Native IOS
- SPAN Configuration on Switch Running CatOS
- VACL Configuration on Switch Running CatOS
- MLS IP IDS Configuration on a Switch Running CatOS
- IDSM-2 Blade Configuration
- Troubleshooting Steps
-
Configuration Steps
- Issues with Inline Mode
- Not Generating Events Issues
- TCP Reset Issues
- Case Study
- Common Problems and Resolutions
- Best Practices
-
16. Troubleshooting Cisco IDS Network Module (NM-CIDS)
- Overview of NM-CIDS on the Router
- Diagnostic Commands and Tools
- Common Problems and Resolutions
-
Case Studies
- CEF Forwarding Path
- IPS Insertion Points
- Network Address Translation (NAT)
- Encryption
- Access List Check
- IP Multicast, UDP Flooding, IP Broadcast
- Generic Routing Encapsulation (GRE) Tunnels
- Address Resolution Protocol (ARP) Packets
- Packets Dropped by the IOS
- Forwarding the Packets to the IDS at a Rate Higher Than the Internal Interface Can Handle
- Common Problems and Resolutions
- Best Practices
-
17. Troubleshooting CiscoWorks Common Services
- Overview of CiscoWorks Common Services
- Diagnostic Commands and Tools
-
Categorization of Problem Areas
-
Licensing Issues
- Registration for CiscoWorks Common Services
- Installing/Upgrading the License Key for CiscoWorks Common Services
- Registration for the Management Center for Cisco Security Agents (CSA MC)
- Installing the License Key for the Management Center for Cisco Security Agents (CSA MC)
- Common Licensing Issues and Work-Arounds
- Installation Issues
- Database Management Issues
-
Licensing Issues
- Case Studies
- Common Problems and Resolutions
- Best Practices
-
18. Troubleshooting IDM and IDS/IPS Management Console (IDS/IPS MC)
- Overview of IDM and IDS/IPS Management Console (IDS/IPS MC)
- Diagnostic Commands and Tools
-
Analysis of Problem Areas
-
Important Procedures and Techniques
- Verifying Allowed Hosts on the Sensor
- Adding Allowed Hosts on the Sensor
- Adding an Allowed Host Manually on a Sensor
- Verifying the SSH and SSL Connection Between IDS/IPS MC and a Sensor
- Resolving SSH and SSL Connection Problems Between IDS/IPS MC and a Sensor
- Verifying If the Sensor Processes Are Running
- Verifying That the Service Pack or Signature Level Sensor Is Running
- Verifying the Service Pack or Signature Level on IDS/IPS MC
- Verifying That the IDS/IPS MC (Apache) Certificate Is Valid
- Regenerating IDS/IPS MC (Apache) Certificate
- Resolving Issues with the IDS/IPS Sensor Being Unable to Get the Certificate
- Changing the VMS Server IP Address
- Manually Updating the Signature Level on the Sensor
- Unable to Access the Sensor Using IDM
- IDS/IPS MC Installation and Upgrade Issues
- IDS/IPS MC Licensing Issues
- Importing Sensor Issues with IDS/IPS MC
- Signature or Service Pack Upgrade Issues with IDS/IPS MC
- Configuration Deployment Issues with IDS/IPS MC
- Database Maintenance (Pruning) Issues
-
Important Procedures and Techniques
- Case Study
- Common Problems and Resolutions
- Best Practices
-
19. Troubleshooting Firewall MC
- Overview of Firewall MC
- Diagnostic Commands and Tools
- Analysis of Problem Areas
- Common Problems and Resolutions
- Best Practices
-
20. Troubleshooting Router MC
- Overview of Router MC
- Diagnostic Commands and Tools
- Analysis of Problem Areas
- Case Study
- Best Practices
-
21. Troubleshooting Cisco Security Agent Management Console (CSA MC) and CSA Agent
- Overview of CSA MC and Agent
- Diagnostic Commands and Tools
-
Categorization of Problem Areas
- Installation and Upgrade Issues
- Licensing Issues
- CSA MC Launching Issues
- CSAgent Communication, Registration, and Polling Issues with CSA MC
- Application Issues with CSAgent
- Report Generation Issues
- Profiler Issues
- Database Maintenance Issues
- Common Problems and Resolutions
- Best Practices
-
22. Troubleshooting IEV and Security Monitors
- Overview of IEV and Security Monitor
- Diagnostic Commands and Tools
- Categorization of Problem Areas
- Case Study
- Common Problems and Resolutions
- Best Practices
-
14. Troubleshooting Cisco Intrusion Prevention System
Product information
- Title: Cisco Network Security Troubleshooting Handbook
- Author(s):
- Release date: November 2005
- Publisher(s): Cisco Press
- ISBN: 9781587051890
You might also like
book
CCNP Security Cisco Secure Firewall and Intrusion Prevention System Official Cert Guide
The official Cisco Press Certification Guide designed to help candidates prepare for the new SNCF 300-710 …
book
Learning Web Design, 5th Edition
Do you want to build web pages but have no prior experience? This friendly guide is …
book
Network Warrior, 2nd Edition
Pick up where certification exams leave off. With this practical, in-depth guide to the entire network …
book
Network Automation Cookbook
Take your network automation skills to the next level with practical recipes on managing network devices …