Monday, November 21, 2011

Snort 2.9.1.2 on Solaris 10_x86

The Snort 2.9.0.5 package I built worked fine on my x86 VM, but would segfault when installed on SunFire 4400:

--== Initialization Complete ==--

,,_ -*> Snort! <*-
o" )~ Version 2.9.0.5 (Build 135)
'''' By Martin Roesch & The Snort Team: http://www.snort.org/snort/snort-team
Copyright (C) 1998-2011 Sourcefire, Inc., et al.
Using libpcap version 1.1.1
Using PCRE version: 8.12 2011-01-15

Preprocessor Object: SF_SDF Version 1.1
Preprocessor Object: SF_DCERPC2 Version 1.0
Preprocessor Object: SF_SSLPP Version 1.1
Preprocessor Object: SF_DNS Version 1.1
Preprocessor Object: SF_SSH Version 1.1
Preprocessor Object: SF_SMTP Version 1.1
Preprocessor Object: SF_FTPTELNET Version 1.2
Commencing packet processing (pid=14777)
Segmentation Fault (core dumped)

# pstack core_prodids01_snort_0_0_1321551044_14777
core 'core_prodids01_snort_0_0_1321551044_14777' of 14777: ../bin/
snort -c snort.conf
----------------- lwp# 1 / thread# 1 --------------------
080deeb7 TcpSessionCleanup (e1f7078, 1f90, 90dc, 0) + 41b
080e92ce DeleteLWSession (9437400, e1f7078, 81234dc, 9eafcf0,
8046e98, ac6301a) + de
080e445b ???????? (8046fa0, 9eafcf0, 0, 8046ff0)
080e6620 Stream5ProcessTcp (80470d0, e1f7078, 9eafcf0, 8046ff0) + 194
080cf75b ???????? (80470d0, 0, 80f052f, 808dd13)
0808df7b Preprocess (80470d0, ffffffff, 1a24c60a, 1d04c60a, 80470e8,
80a6785) + 5cf
080842f7 ProcessPacket (0, 80479b0, e1457b2, 0, d4, feffb818) + 203
080874a8 ???????? (0, 80479b0, e1457b2, 8047a84)
080fda31 ???????? (df2ac70, 8047a10, e1457b2, 3c, 8047a00, fefd176f)
fed847e1 pcap_process_pkts (df29b08, 80fd9d8, df2ac70, ffff3da1,
e13bb0a, ff78) + ad
fed7424e pcap_read_dlpi (df29b08, ffff3da1, 80fd9d8, df2ac70) + a2
fed75a81 pcap_dispatch (df29b08, ffff3da1, 80fd9d8, df2ac70) + 19
080fda93 ???????? (df2ac70, ffffffff, 80872f8, 0, 0, feffdd58)
0809d199 DAQ_Acquire (ffffffff, 80872f8, 0, 0) + 21
0808845c SnortMain (3, 8047cd0, 8139964, 8139a44, 0, 80fecde) + 798
08088dd8 main (3, 8047cd0, 8047ce0) + 24
08066184 _start (3, 8047d9c, 8047da9, 8047dac, 0, 8047db7) + 80
----------------- lwp# 2 / thread# 2 --------------------
fece99d7 ___nanosleep (1, 0, 0, 0) + 7
080890ab ???????? (0)
fece7390 _thr_setup (fe850200) + 4e
fece7680 _lwp_start (fe850200, 0, 0, fe95eff8, fece7680, fe850200)

I posted this on the Snort discussion group, and the feedback was "interesting...try 2.9.1.2?" Which wouldn't have been an issue, if I could make any progress on compiling 2.9.1.2 on Solaris:

gcc -DHAVE_CONFIG_H -I. -I../.. -I../.. -I../../src -I../../src/sfutil -I../../src/output-plugins -I../../src/detection-plugins -
I../../src/dynamic-plugins -I../../src/preprocessors -I../../src/preprocessors/portscan -I ../../src/preprocessors/HttpInspect/include -I../../src/preprocessors/Stream5 -I../../src/target-based -I../../src/
control -I/usr/local/OAMsnort/include -I/usr/local/OAMsnort/include -DDYNAMIC_PLUGIN -I/usr/local/OAMsnort/include -DZLIB -DGRE -DMPLS -DPREPROCESSOR_AND_DECODER_RULE_EVENTS -DPPM_MGR -DSOURCEFIRE -DPERF_PROFILING -DPREPROCESSOR_AND_DECODER_RULE_EVENTS -DPPM_MGR -DENABLE_PAF -DENABLE_REACT -DENABLE_RESPOND -DENABLE_RESPONSE3 -
DBSD_COMP -D_REENTRANT -DSF_WCHAR -DSUP_IP6 -DTARGET_BASED -DPERF_PROFILING -DPERF_PROFILING -DSNORT_RELOAD -DNORMALIZER -DACTIVE_RESPONSE -g -O2 -Wall -c ipobj.c
In file included from ../../src/ipv6_port.h:29,
from ipobj.h:44,
from ipobj.c:51:
./sf_ip.h:77: error: syntax error before "u_int8_t"
I was pretty sure this was related to the uint8_t and uint16_t definitions....but because I am not all that proficient at programming, and couldn't figure out where to fix it. Luckily for me I got a response from the group:

See where it says "from ipobj.c:51:" below, if you add #include "sf_types.h" on the line before that, you should get that file to compile. There may be others with the same problem and you will have to fix them similarly. - RCombs @ Source Fire
Yup, that make sense...I need to include the sf_types.h before any of the offending integer types are used. sf_types.h will properly define them.

So, now it just a matter of putting this in all of the offending files...which was a fun exercise in:

# make > ../logfile 2>&1
# more logfile
# vi src/snort.c
Repeat the above processes editing each file that it fails on. In the end you will have edited the following 89 files (file name: Line #):

  • ipobj.c:51
  • sf_ip.c:40
  • sf_vartable.c:35
  • sf_iph.c:28
  • sfPolicy.c:28
  • sfPolicyUserData.c:27
  • spo_alert_syslog.c:60
  • spo_log_null.c:49
  • spo_log_tcpdump.c:62
  • spo_unified.c:57
  • spo_unified2.c:42
  • sp_hdr_opt_wrap.c:28:
  • sp_react.c:62:
  • sf_snort_plugin_hdropts.c:34:
  • sf_snort_detection_engine.c:40
  • sf_snort_plugin_api.c:33:
  • sf_snort_plugin_byte.c:36:
  • sf_snort_plugin_content.c:37
  • sf_snort_plugin_hdropts.c:34
  • sf_snort_plugin_loop.c:34:
  • sf_snort_plugin_pcre.c:36:
  • sf_snort_plugin_rc4.c:34
  • sf_decompression.c:43
  • sf_dynamic_plugins.c:64:
  • sf_convert_dynamic.c:29:
  • hi_paf.c:69:
  • snort_stream5_udp.c:27:
  • snort_stream5_icmp.c:27:
  • snort_stream5_session.c:42:
  • stream5_common.c:27:
  • spp_rpc_decode.c:58:
  • stream_ignore.c:53:
  • spp_httpinspect.c:51:
  • portscan.c:114:
  • spp_sfportscan.c:56:
  • stream_api.c:41:
  • spp_normalize.c:26:
  • normalize.c:36:
  • ssl.c:33:
  • sf_dynamic_preproc_lib.c:33:
  • mempool.c:42:
  • sf_email_attach_decode.c:26
  • ftp_bounce_lookup.c:46
  • ftp_cmd_lookup.c:46:
  • ftpp_eo_log.c:51:
  • ftpp_si.c:54:
  • ftpp_ui_client_lookup.c:46:
  • ftpp_ui_config.c:49:
  • ftpp_ui_server_lookup.c:44:
  • pp_ftp.c:59:
  • pp_telnet.c:55:
  • snort_ftptelnet.c:64:
  • spp_ftptelnet.c:56:
  • pop_config.c:47:
  • pop_log.c:47:
  • spp_pop.c:52:
  • imap_config.c:47:
  • imap_log.c:47:
  • spp_imap.c:52:
  • smtp_config.c:48:
  • smtp_log.c:47:
  • smtp_normalize.c:41:
  • smtp_xlink2state.c:50:
  • spp_smtp.c:52:
  • spp_ssh.c:41:
  • spp_dns.c:42:
  • spp_ssl.c:31:
  • dce2_debug.c:39:
  • snort_dce2.c:28:
  • spp_sdf.c:42:
  • sdf_pattern_match.c:28:
  • sdf_credit_card.c:25:
  • sdf_us_ssn.c:25:
  • sdf_detection_option.c:29:
  • spp_sip.c:37:
  • sip_config.c:30:
  • sip_parser.c:32
  • sip_dialog.c:29
  • sip_utils.c:28
  • reputation_config.c:32
  • reputation_utils.c:28
  • sftarget_protocol_reference.c:31
  • decode.c:40
  • encode.c:37
  • active.c:36:
  • snort.c:86
  • tag.c:35:
  • pcrm.c:207:
  • obfuscation.c:27:

However, in the end I had the latest version of Snort compiled and running on my Solaris 10_x86 dev system:

--== Initializing Snort ==--
Initializing Output Plugins!
pcap DAQ configured to passive.
Acquiring network traffic from "e1000g0".
Decoding Ethernet

--== Initialization Complete ==--

,,_ -*> Snort! <*-
o" )~ Version 2.9.1.2 IPv6 GRE (Build 84)
'''' By Martin Roesch & The Snort Team: http://www.snort.org/snort/snort-team
Copyright (C) 1998-2011 Sourcefire, Inc., et al.
Using libpcap version 1.1.1
Using PCRE version: 8.12 2011-01-15
Using ZLIB version: 1.2.3

Commencing packet processing (pid=28106)

Now, I just need to package this all into a nice neat Solaris package and install it on the production servers. When I get a chance I will also zip up the Snort source code that I edited and post it here for any other Solaris users that are having issues.


Friday, March 25, 2011

Custom Snort 2.9 package for Solaris 10 x86

So...for the past week I've been spending most of my time trying to build a custom Snort 2.9 package for our Solaris customers. Nothing special about the package, other than the fact that it will be self contained to include all dependencies (libpcap, libdnet, pcre, etc..).

Its just an easy way to install and manage Snort without worrying about impacting other applications on the system.

I am using the gcc and gmake that come with Solaris 10 in /usr/sfw so I had to add the following to my path:
setenv PATH ${PATH}:/usr/sfw/bin:/usr/sfw/sbin:/usr/ccs/bin
Since I am plan on building a package I also wanted to have a build directory that will only contain the files I will be packaging.
mount -F lofs /export/home/build /usr/local
I then proceeded to build and install the pre-requisite libraries libdnet, libpcap, and pcre:
# configure --prefix=/usr/local/AVGsnort
# gmake
# gmake install
I didn't have any issues building or installing the libraries. Now was the time to start building the snort binaries. First up was DAQ 5.0...and I had issues right out of the gate:
checking for libpcap version >= “1.0.0″… no
ERROR! Libpcap library version >= 1.0.0 not found.

Get it from http://www.tcpdump.org

At first this seems straightforward, simply point the configure script to the location of libpcap. From the configure help:
--with-libpcap-includes=DIR libpcap include directory
--with-libpcap-libraries=DIR libpcap library directory
That's obvious enough:
# configure --prefix=/usr/local/AVGsnort --with-libpcap-includes=/usr/local/AVGsnort/include -with-libpcap-libraries=/usr/local/AVGsnort/lib
Still failed....at which point I spotted this little nugget:
ld.so.1: conftest: fatal: libpcap.so.1: open failed: No such file or directory
I pulled the conftest.c code out of the config.log, this is the program that configure builds and runs to test the version of libpcap. I figured I could narrow this down a bit more if I could figure out why that section of code was failing.
# gcc -o conftest -g -O2 -std=c99 -D_GNU_SOURCE -I/usr/local/AVGsnort/include/ -L/usr/local/AVGsnort/lib conftest.c -lpcap
#
Interestingly there were no issues building the code...however when I ran it:
# ./conftest
ld.so.1: conftest: fatal: libpcap.so.1: open failed: No such file or directory
Killed
Huh?!?!?! The issue is appears to be that conftest does not know where the libraries are, so when it fails to find pcap. Despite the fact that it is designated with the -L and -I flags when built.

To resolve this I simply had to adjust my library path. This can be done two ways:
# setenv LD_LIBRARY_PATH /lib:/usr/lib:/usr/local/AVGsnort/lib
or
# crle -l /usr/local/AVGsnort/lib
Either way will ensure that conftest succeeds when run. That should get you through the configure. However, during the make I ran into the following error:
sll.h:87: error: syntax error before "u_int16_t"
sll.h:87: warning: no semicolon at end of struct or union
The issue here is the fact that Solaris uses uint16_t instead of u_int16_t. To get around this I just added a typdef to map for the two u_int types:
typedef uint8_t u_int8_t;
typedef uint16_t u_int16_t;

Still working on the build....will update with other findings as they pop-up

UPDATE

decode.c: In function `DecodePflog':
decode.c:1928: warning: long unsigned int format, unsigned int arg (arg 3)
decode.c: In function `DecodeIP':
decode.c:3118: error: `IPPROTO_GRE' undeclared (first use in this function)
decode.c:3118: error: (Each undeclared identifier is reported only once
decode.c:3118: error: for each function it appears in.)

The first issue at line 1928 can be solved by changing the code as follows:# diff decode.c.orig decode.c
1928c1928
< "(%d < %lu)\n", cap_len, PFLOG2_HDRMIN);
---
> "(%d < %u)\n", cap_len, PFLOG2_HDRMIN);
The issue appears to be from the printf error message, which was set to have a decimal integer (%d) which it got from cap_len and a long unsigned (%lu) integer which was from PFLOG2_HDRMIN. However, it appears the PFLOG_HDRMIN is returning just an unsigned integer (%u) and not a long unsigned (%lu).

The next one is a bit trickier...and I can find my "Programming C" book to assist me. (As programming really isn't something I do often).

Well, I've found a workaround. The code is expecting GRE to be defined:
#ifdef GRE
if (p->greh != NULL)
pc.gre_ip++;
#endif

However, it apparently isn't. So I could either try to find some GRE code and add an #else section to the #ifdef above OR I could enable GRE when I complile and see if that adds the code I need without me having to muck about any more than usual.
# gmake distclean
# ./configure --prefix=/usr/local/AVGsnort --enable-gre
# gmake
What do you know it works:
# ./snort
Running in packet dump mode

--== Initializing Snort ==--
Initializing Output Plugins!
pcap DAQ configured to passive.
Acquiring network traffic from "e1000g0".
Decoding Ethernet

--== Initialization Complete ==--

,,_ -*> Snort! <*-
o" )~ Version 2.9.0.4 GRE (Build 111)
'''' By Martin Roesch & The Snort Team: http://www.snort.org/snort/snort-team
Copyright (C) 1998-2011 Sourcefire, Inc., et al.
Using libpcap version 1.1.1
Using PCRE version: 8.12 2011-01-15

Commencing packet processing (pid=863)
03/29-11:38:14.606885 ARP who-has 10.0.2.15 (FF:FF:FF:FF:FF:FF) tell 10.0.2.15

Now I simply follow the steps posted by the fine people that run sunfreeware.com to create a package







Thursday, November 11, 2010

VirtualBox Seamless Mode

It's been about two years since I really used VirtualBox, and at that point it was mainly so I could develop packages on various OSs (Solaris, Windows, Linux, etc..). I can't recall if Seemless Mode was available, but it wasn't a feature I used at the time. I would normally boot my VM in full screen and go from there.

But my current job requires me to VPN into their environment for certain functions, but the VPN actually hampered my ability to perform other job functions. To allow me to be both on VPN and off-vpn, I loaded up virtualbox with my companies standard linux build. Now, I was prepared to simply switch back & forth between the VM and my desktop...until I found seamless mode.

This is not a new feature, if you use VMware, parallels, or VirtualBox you have most likely already come across it. A good write-up on it can be found here: http://blogs.techrepublic.com.com/opensource/?p=757

Now I can switch between my linux and windows applications seamlessly (get it just like the name!).

Like I said, nothing ground breaking...but its still really really cool.

Friday, November 05, 2010

netbook chrome

Well...I installed one of the Flow builds (Chromium OS) by Hexxah: http://chromeos.hexxeh.net/

If all you want is a browser, and let's face it with the number of web accessible application its a valid market, then chromium is decent. This isn't going to much of a review, because I really didn't get too deep into testing it. Additionally, I think it would be unfair to talk about bugs or missing features that I assume will be fixed by launch.

Anyway, I liked it for a beta and look forward to the official release when its finally available. It worked on my HP with no issues. It booted and ran well off of a thumb drive, and installed easily on the HD.

I'm now going to check out Ubuntu 10.10 Netbook Edition...in general I like the Ubuntu distros so I expect to be generally pleased with their Netbook OS. Guess we'll see in a couple weeks.


Monday, October 25, 2010

Moblin Update

Well its been about two weeks with the netbook, and given the choice between the netbook and a tablet I'm currently leaning towards the tablet. I like the fact that I can be on AIM while I search the web and generally play around on the netbook. However, my thumbs always hit the touch pad moving the cursor and making it generally annoying to do much typing on it.

It's main use, for me at least, is a web browser and even that is annoying due to the smaller screen than a tablet. I also like the tablet games more due to the touch screen interface. Add to that the apps that are available for the tablets, and the cross-platform (tablet/phone) nature of the apps and I've got to give the advantage to the tablets.

Next up for me will be the Chrome OS. Going to download the most recent beta build and give it a run.

Wednesday, October 13, 2010

Got to keep Moblin on...

I came into posession of an HP Mini 2140. Now, in general I don't really get the purpose of thes netbook. Personally, I think its too small to be useful and too big to be portable, but that's the opinion of a person whose fingers are too fat for a full size keyboard. Now that I have one, I figure I might as well see if my opinions are correct.

I had to load an OS, since HD was cleaned before I received it. It comes with a Windows 7 licenses, but whats the fun in that? So...my plan is to load various Netbook OS's and see if I get to the point that I change my opinion. First up in the little experiment is Moblin

Moblin intrigues me, its got a user interface that is different from the other netbook OSs. So I downloaded and installed it using the instructions on the site. The installation was straight forward and in an hour I went from a blank netbook and no idea what I was going to do with it...to a Moblin netbook.

The only piece that didn't work out of the box was the wireless card...which is a show stopper for a netbook. I mean...the whole point is the portability. Luckily it just needed the Broadcom drivers...the instruction can be found here: http://slaine.org/_slaine/Dell_Mini_9.html

So far so good...still getting it set-up and customized. I did post this blog from it using blogtk. Which showed a bit of a bug when inserting a link, the link windows pops up in its own zone. Other than that..its seem like a decent OS, but not a easy to use as I had hoped. The menus seem like they might be easier to navigate on a touch device.

I'll keep playing with it...but I'm also looking for the next OS to try. Looking at OSX86, unless chrome os comes out before then.

(Note: I ended up cleaning up this post...still getting the hang of BlogTK)

Wednesday, June 09, 2010

RSA ACE Queries or how I spent my summer

Well...just got done spending way to much time writing what is probably a basic SQL query for what I know is an outdated RSA ACE server ( ver. 6.0). However, its to prepare for our eventual upgrade and help reign in the management of the system.

Problem: We have multiple business units that use SecurID authentication. These business units have various groups set-up with specific agent hosts assigned.

What I need is a list of all AgentHosts including their IP, Site, and Group. I can then send this to the POC for the site, who can verify the agent hosts and groups.

I won't bore you with my ramp-up time on OUTER and INNER joins, or the way I love to insert typos randomly, or how the ACE server only give useful 'syntax error' pop-up messages. Suffice it to say, something that should have only taken a few hours...blossomed into a couple day journey. Live and learn.

So, first the bookmarks:

The database schema's are listed here:
http://theether.net/download/RSA/SecurID/6.1/authmgr_admin_toolkit.pdf

Some info on syntax can be found:
http://theether.net/download/RSA/SecurID/6.1/authmgr_admin.pdf


Here is the first *working* version, there are no options..it just prints that information I needed for ALL AgentHosts:

SELECT SDClient.chName, SDClient.chNetAddress, SDSite.chName, SDGroup.chName FROM SDClient
LEFT JOIN SDEnabledGroup ON SDClient.iClientNum = SDEnabledGroup.iClientNum
LEFT OUTER JOIN SDGroup ON SDEnabledGroup.iGroupNum = SDGroup.iGroupNum
LEFT OUTER JOIN SDSite on SDClient.iSiteNum = SDSite.iSiteNum
ORDER BY SDSite.chName, SDGroup.chName, SDClient.chName


Easy enough, a few join statements...bam.

Wednesday, March 17, 2010

Checkpoint Firewall..no thanks..

Checkpoint Firewalls remain a bane of my IT existence.

I have worked with many versions...in almost all cases the version I am using is NOT the current version of the software.

Why would so many shops use out dated checkpoint software? I imagine due to the buggy nature and overall annoyance of the upgrade processes. Sure if you have a policy server, you can just push the policy to the system.

Just kidding. You need to make sure you have your license correct...make sure you have saved all the local configuration...and don't forget your local.arp...what about routes...sure hope this works....

I've done it...and anyone out there can tell me "oh..its not that hard..did you export...did you run x, did you.."

All I'm going to say is CISCO or NETSCREEN. I can upgrade in less then 15 minutes...with a cluster I can do it with no downtime. I've done it...could not have been a more pleasurable experience.

Now...how about when it comes time to audit? Ever try to export the rules so they can be reviewed? Good luck with that. Screen capture and print to PDF are not good solutions. I can do a 'sho access-list' on Cisco and export to MS Excel.

If you are out there and contemplating purchasing checkpoint firewalls..don't

If you have checkpoint firewalls..and are looking to upgrade...Upgrade to a Cisco ASA or a Juniper Netscreen.

If you are a Checkpoint administrator and believe it to be the superior firewall platform...you clearly have not had the pleasure of using a system with a command line.

CLI 4 LIFE!

Thursday, March 11, 2010

OSSIM, VMTools, and YOU!

I have had the pleasure of installing OSSIM for use at our company. It is replacing our old Cisco MARS appliance which, after using it at several place, I can say is a sub-par correlation and monitoring system.

I'm still setting up OSSIM, so I can't give it a review yet. I will say it's easy to install and looks great. I need to get some event pumping through it to really test it.

Anyway, if you are like me you want to do-it-yourself when it comes to installing something for the first time. In this case instead of using the configured VM image, I installed OSSIM from the installation media onto a VM.

Everything installed easily, now it's time to install the VMware tools. First I need to mount the virtual CD with the VM image:
# mount -t iso9660 /dev/cdrom1 /cdrom
I chose to install the tools from the tar.gz instead of the .rpm.
# ./vmware-install.pl
I accept the default, just to ensure ease of management. This is a personal choice, but I believe that unless their is a valid technical reason to change the settings, you shouldn't.

Which works fine until you get the following errors:
None of the pre-built vmmemctl modules for VMware Tools is suitable for your running kernel. Do you want this program to try to build the vmmemctl module for your system (you need to have a C compiler installed on your system)?
One solution is to load the generic Debian kernel. I boot from the AlienVault kernel and assume there is a valid reason they have their own kernel, and would prefer to keep it. So I decided to compile the VMtools for loading into the kernel.

First, you need to install the compliler and headers:
# apt-get install build-essential linux-headers-$(uname -r)
Next, we run the install and just choose yes when it asks us to build the modules:

None of the pre-built vmmemctl modules for VMware Tools is suitable for your running kernel. Do you want this program to try to build the vmmemctl module for your system (you need to have a C compiler installed on your system)?
[yes] Yes
If all goes well, after each module is compiled, you will get a success message:
The vmmemctl module loads perfectly into the running kernel.
I checked, and the VMTools appear to be running perfectly. I still have some testing to do...but it works great.

Wednesday, January 20, 2010

Never say it can't be done

I have recently come across a fairly simple task, that as decidedly difficult to figure out how to implement on the Cisco ASA, multiple external IPs NAT'd to a single internal IP.

A google search will bring up several forums in which the consensus is that it can't be done:

"There is no way the device would allow you to have 2 public ip to point to the same internalip."

That's not correct, sadly if you call tier 1 Cisco support they will give you the same answer. The issue is how the ASA performs various NATs:

static - This is a bi-directional NAT that is used for traffic to the host and from the host
static (inside,outside) public-ip internal-ip netmask 255.255.255.255

nat (pat) - This is for traffic FROM the host only, traffic cannot be initiated TO the NAT IP
nat (inside) 1 inside-ip
global (outside) 1 outside-ip

The issue is that the static is bi-directional, so the ASA will not let you add two statics since this would cause a conflict for outgoing traffic.

Now, I refused to accept the answer "it can't be done"...I refuse to believe that Checkpoint..the peak of early 90's technology can do this..yet the ASA cannot. So I escalated.

I was right it can be done, and here is how:

Given two Public IPs: 200.100.30.40 & 200.100.30.41
Given one Private IP: 10.10.10.1

First, you create an ACL for each NAT:

access-list nat1 extended permit ip host 10.10.10.1 any
access-list nat2 extended permit ip host 10.10.10.1 any

Now you create that static NAT statement:

static (inside, outside) 200.100.30.40 access-list nat1
static (inside, outside) 200.100.30.41 access-list nat2

NOTE: Traffic generated FROM the inside will always get NAT'd to the first static entry.

You can verify by doing a show xlate:

Global 200.100.30.41 Local 10.10.10.1
Global 200.100.30.40 Local 10.10.10.1

Monday, January 18, 2010

Cisco Nexus gear

We recently installed a Nexus 5020 with 12 2048T Fabirc Extenders (FEX). This will become the core switching environment for our new network. These are some pretty sweet switches with some wicked cool features. Some of the nice features:
  • Unified Fabirc - Allows IP and Native SAN over the same infrastructure.
  • VMWare intergration - Allowes the creation of VM network profiles that can travel with the VM.
  • Multi-switch Etherchannel - On the Nexus it's refered to as Virtual Port Channel (vPC)
  • No Spanning Tree - Can be either a plus or minus..but for us its simplifies in our current deployment.
For all of the good features there are a few gotcha's that we ran into:
  • FEX ports are GigE...only...don't even think of doing 10/100
  • 5020 has limited GigE....16 ports are GigE the remaing 32 are 10Gig
  • vPC limits the number of Etherchannel ports per FEX to ONE
One of the interesting things we ran into with this system was configuring TACACS+ for authentication. Normally it's pretty straight foreward you define TACACS servers & the key..bam you're good to go. For the nexus it's slightly different:

1. Enable TACACS on the system:
switch (config)# feature tacacs+
2. Add TACACS+ servers:
switch (config)# tacacs-server host 12.123.34.5
3. Add TACACS+ Key:
switch(config)# tacacs-server key
4. Add authentication group:
swith (config)# aaa group server tacacs+ tacplus
5. Add Server to auth group:
switch (config-tacacs+)# server 12.34.56.7
6. set AAA to use the tacplus group:
switch (config)# aaa authentication login default group tacplus
7. Log it on the tacacs server:
switch (config)# aaa accounting default group tacplus
8. Finally, this line was needed for our set-up:
(config)# aaa authentication login ascii-authentication
So far, fairly pleased with the Nexus. We aren't doing anything too cutting edge, but our set-up on the Nexus cost considerably less than a comparable 6509 configuration. Obviously, there are pros & cons to each set-up so your mileage may vary based on the requirements for your specific deployment.

Tuesday, January 12, 2010

ASA, ASDM, and longevity

I have spent the last several day cleaning up firewall configurations. These were brand new, out of the box firewalls and in less than a year their configuration was utter crap. I blame this on two things the administrator and the ASDM gui.

I blame the administrator, for relying soley on the GUI and operating under the impression that it doesn't matter how the changes are made. Let me assure you...it does.

I blame the ASDM GUI for all of the extraneous crap that it puts in the configuration. Some are due to the administrator not using it correctly, and some of it is just the way the GUI works.

Let me just give a few do's and don'ts to ASA management:

  1. DO use object-groups in rules. Let's face it, it's easier to update one object-group than multiple rules.
  2. DO use descriptive names for object-groups and access-lists. When troubleshooting it's much easier when you know what things are.
  3. DO NOT accept the default names the GUI assignes for anything. It is for this reason that I have object-groups like DM_INLINE_NETWORK_1, interfaces name OUTSIDE_VPN_VLAN999, and access-list named OUTSIDE_VPN_VLAN999_access_in

Now, there are few other tips I have, these are really dependent on your site...but I find them to be pretty standard:

DO NOT use interface access-lists for your VPNs:

I've seen this done at several places, and honestly I don't know why. This actually introduces a new risk..especially if public IPs are used on both ends of the tunnel.What happens if the tunnel configuration is removed, but the ACL is not? The traffic will go out the interface unencrypted.

DO use VPN filters to apply ACLs to VPNs:

group-policy tunnel-name-filter internal
group-policy tunnel-name-filter attributes
vpn-filter value access-list-name

tunnel-group peer-ip general-attributes
default-group-policy tunnel-name-filter

Now, if we use descriptive names...we can tell which ACLs pertain to which tunnels.

DO NOT use names in the configuraiton:

no names

This is really just a preference, but when troubleshooting I like to be able to run the command 'sh access-list | in 12.234.45.6' and get all rules associated with that host. If I have names, I would first need to resolve that host to the name configured and then search for the name.

What happens if the hostname has changed or the host is known by several names?

DO AUDIT your firewall periodically:

Now, if you've followed the tips I've laid out auditing should be able to breeze. Simply capture the output from 'show access-list'. It's in cvs delimited format with the [space] as the delimiter. You can easily import into EXCEL.

Now if your object-group names are descriptive...you should be able to tell what each rule is for and since the object-groups are expanded..you can verify all of the IPs that have access. You can annotate the excel with the any POC information for a set of rules, justifications, etc.. that you will need during your audit.

In my experience by following these tips, you will have a firewall that is easy to manage for years to come. Troubleshooting issues is simpler, since you can visually distinguish what ACLs and object-groups apply.

I have to thank my mentor at Sun Sam Munzani, who casually mentioned these tips to me as he handed off some ASA firewalls. It was immediately clear the genius behind it the first time I had to audit the firewall. It was also amazingly simple to troubleshoot issues.

Thursday, November 05, 2009

Websense on CentOS 5

Websense is the current bane of my IT existence. The configuration of it, once it is installed is not too difficult. However, I've had the following issues:

1. Could not get Windows AD integration working in version 7.1 under Windows 2008 (32-bit) or CentOS 5. I know CentOS 5 is not supported...but try getting an all windows shop to pay for RHEL when Windows is free. I refuse to run production software on Windows is possible, it's come a long way....but it's still NOT a server platform as far as I'm concerned.

2. I was able to get Websense 6.3.3 with Windows AD integration working under CentOS 5. Installed relatively easy. I've installed, configured, and tested the following components with no issue under Centos 5:
  • Policy Server
  • User Service
  • Filter Agent
  • Product Integration (Checkpoint FW...the other bane of my IT existence)
3. DC Agent install is not available for linux under 6.3.3. This was something I missed, since I thought the last .3 meant minor revision...not removing a feature completely. So, I had a Windows 2003 server set-up and installed the DC Agent on it. Still could not get per user policies working. This was due to the fact that the dc_config.txt was not being created. This was solved with websense KB 3329, editing the transid.ini file. But this was the last bit in a long line of Websense failures...poor programming?

That said, the one component that I had serious trouble installing was the Logserver and ExplorerUI. This is due to the installation program using LD_LIBRARY_PATH, specifically it set LD_LIBRARY_PATH=${Logserver Install dir/lib} & LD_ASSUME_KERNEL="2.4.1". This prevented it from finding any of the standard shared libs, causing the following error:

./logserverd-dbsetup: error while loading shared libraries: libdl.so.2: cannot open shared object file: No such file or directory

At this point you have the logserver installed, but not running. So I did the following:
  1. echo "/opt/Websense/UnixExplorer/logserverd/lib" >> /etc/ld.so.conf.d/websense-ux.conf
  2. ldconfig -v
  3. cd /opt/Websense/UnixExplorer/logserverd/bin/
  4. ./logserverd-dbsetup.bin -sa
  5. ./logserverd.bin &
I basically avoid the wrapper scripts and run the commands without setting the offending environment variables. I have added the Websense shared libraries to the system wide ld.so.conf which could be an issue for some sites, but this is a dedicated websense box so I don't have any issues with that. However, if I believe if you simply remove the LD_ASSUME_KERNAL line from the wrapper scripts and run you should be fine.

The key to the manual set-up I used, is to use the -sa switch to build the database, if you don't logging will work but when you pull up a report you will notice some information is unavailable (disposition, date/time, etc..).

You will then need to re-run the installation script to install the ExplorerUI, since the ExplorerUI won't install after the logserver installation fails.

For clean-up you will need to edit the scripts so that your service startup scripts work after reboot.

Thursday, October 08, 2009

SecureID my CentOS 5

I ran into an issue recently installing SecurID authentication on a CentOS 5 server...so I decided to document how I got it working.

The Pre-Requisites:
  • OS CentOS 5
  • RSA Authentication Agent for PAM 6.0
  • RSA Agent Host record configured

First, we make the VAR_ACE directory:

Centos # mkdir /var/ace
Centos # chown root:root /var/ace
Centos # chmod 700 /var/ace

Next we create the install directory under /opt (optional)

Centos # mkdir /opt/ace
Centos # chown root:root /var/ace


Now we install the Authentication Agent:

Centos # VAR_ACE=/var/ace; export VAR_ACE
Centos # tar xf AuthenticationAgent_60_PAM_95_060308.tar
Centos # ./install.sh

Follow the prompts, answering as necessary. At this point you should run a quick test to ensure SecurID is installed and working:

Centos# /opt/ace/pam/bin/acetest
Enter USERNAME:
Enter PASSCODE:
Authentication successful.
Centos #

Now we need to configure the SSHD to use SecureID:

Centos # vi /etc/pam.d/ssh

We comment out the first line:
#auth include system-auth

And add the following line:
auth required pam_securid.so


At this point, if you attempt to ssh in to the system you will NOT be able to. Looking at the logs you should see something like:

Oct 8 12:36:28 centos sshd[26923]: PAM [error: /lib/security/pam_securid.so: cannot restore segment prot after reloc: Permission denied]
Oct 8 12:36:28 centos sshd[26923]: PAM adding faulty module: /lib/security/pam_securid.so

A quick google search will show you that this is due to the SELinux enforcing. Now there are two options:

1) Shutdown SELinux: /usr/sbin/setenforce 0

2) Properly configure enforcement profile for the PAM module

Centos # ls --scontext /lib/security/pam_securid.so
system_u:object_r:ib_t /lib/security/pam_securid.so

To work properly the pam_securid module needs access to text relocation. To do this we add it to the correct profile for text relocation:

Centos # chcon -t texrel_shlib_t pam_securid.so
Centos # ls --scontext /lib/security/pam_securid.so
system_u:object_r:textrel_shlib_t /lib/security/pam_securid.so

Once that is done, you should be up and running with SecurID for SSH access

Tuesday, June 10, 2008

Cisco Woes

I am going to make a suggestion, do NOT put Cisco non-switching blades into a catalyst switch. I am talking specifically about the IDSM and ACE modules, but I'm not impressed with the FWSM either.

IDSM2 Blades:

You should be able to add and remove individual blades without effecting the switch. I can assure you that this is not the case with the IDSM. I do not have these issues with the ASA IPS module...but the IDSM2 is a nightmare.

Why would cisco create and IDS/IPS system that doesn't have remote syslog capabilities? Why must you enable or disable SNMP traps on individual signatures? Is remote logging not a critical requirement when it comes to security monitoring? I guess they just want you to dump a couple grand into the MARS system.

ACE Blades:

Hrmm...I don't know that I can even document how unimpressed I am with these blades. These are buggy as hell to start with, I've only been working with it for a few months and have already run into several show stopping bugs.

Add to that the documentation...less than necessary to really administer them. I'm not an idiot...so it annoys me that I have to put in TAC cases for configuration help simply because its not properly documented.

FWSM:

These blades have their pros and cons. I don't hate them like the IDSM2, I think they are a great idea. What annoys me is that some of the debugging tools available on the ASAs and PIXs are not available on the FWSM.

What I want to see is 'packet-tracer' is that too much to ask? How about some line numbers on the ACLs so I can adjust the policy for performance without having to re-do the entire list?

Switching and routing are Cisco strong points.....but application level stuff....they just induce headaches.

Friday, November 30, 2007

Cisco IDS

First, the link to research signatures:
http://tools.cisco.com/security/center/home.x

Now a tip for using the Cisco IDSM module without purchasing their overpriced control station. The IDSM module will not syslog alert, it also will not SNMP trap by default. So how do I get the IDSM module to trap when an event is triggered?

The Key is the "Event Action Override", this allows you to set a default action for all signatures that fall withing a specified Risk Rating (RR) range. In my case I set the default action of sending an SNMP trap for signatures with a RR of 18-100. 100 is the max RR, 18 is the lowest RR of signatures that by default alert. This will ensure that all signatures that are set to "alert" will produce an SNMP trap.

What about signatures that have a RR that is 18 or more, but shouldn't alert? Such as signatures that are apart of meta-events?

That is where the "Event Action Filter" comes into play. It allows us to specify signatures that we don't want to send a trap. You can specify signature(s), sub-signature(s), RR, etc.. Then you simply select to over-ride the SNMP trap action.

You might be thinking that this seems convoluted, why not simply adjust the signatures to trap? Well, because there are hundreds of signatures and they will need to be reviewed everytime they are updated. By using the "Event Action Override" new signature will automatically send a trap by default. The Event Action Filtering will only be needed for a few noisy signatures based on your environment.

Friday, November 09, 2007

Cisco VPN and Filters

access-list vpn-crypto-domain permit ip object-group local-hosts object-group remote-hosts



# Note these are used for both incoming and outgoing connection!

access-list vpn-acl permit tcp object-group remote-hosts object-group localhosts eq 22

access-list vpn-acl permit icmp object-group remote-hosts object-group localhosts

access-list vpn-acl permit tcp object-group localhosts object-group remote-hosts

crypto map VPN_MAP1 230 match address vpn-crypto-domain

crypto map VPN_MAP1 230 set peer xx.xx.xx.xx

crypto map VPN_MAP1 230 set transform-set ESP-AES256-SHA

group-policy vpn-filter internal

group-policy vpn-filter attributes

vpn-filter value vpn-acl

pfs disable

tunnel-group xx.xx.xx.xx type ipsec-l2l

tunnel-group xx.xx.xx.xx ipsec-attributes

pre-shared-key *

tunnel-group xx.xx.xx.xx general-attributes

default-group-policy vpn-filter

Thursday, September 27, 2007

Tunnel of Love

Quick and easy SSH tunneling:

Scenario: I'm at home and I need to connect to a gui at work. The problem is that I cannot get to the gui directly through the firewall.

Solution: An SSH tunnel to proxy the connection from...since SSH is allowed through.

Systems Involved:
1. Home Computer (Windows with Cygwin & ssh)
2. Work computer (Solaris with SSH running)
3. HTTPS gui server.

Step 1: Create a listner on the work computer that will forward the ssh connection to the https server.
work-computer # ssh -R 22:guiserver:443 username@work-computer

Step 2: Create a listner on your home computer that will forward the https connection through SSH to the work computers proxy.
home-computer # ssh -L 8080:localhost:22 username@work-computer

Step 3: Test
https://localhost:8080


* This is nothing new
** This is my cheat sheet

Monday, September 17, 2007

Upgrading Snort

Upgrading Snort is not really that difficult of a procedure, the basics are:
  1. Stop the current snort running
    • Backup the current snort installation
    • mv /usr/local/snort /usr/local/snort.old
  2. Configure Snort
    • ./configure --prefix=/usr/local/snort
  3. Compile & Install
    • make; make install
  4. Now, I usually copy the old configuration files to the new installations.
  5. Run the rc scripts and BAM! good as gold.
Except when you go from such an old version, you will get the following error:

FATAL ERROR: database: The underlying database seems to be running an older version of the DB schema (current version=106, required minimum version= 107). If you have an existing database with events logged by a previous version of snort, this database must first be upgraded to the latest schema (see the snort-users mailing list archive or DB plugin documention for details). If migrating old data is not desired, merely create a new instance of the snort database using the appropriate DB creation script (e.g. create_mysql, create_postgresql, create_oracle, create_mssql) located in the contrib\ directory. See the database documentation for cursory details (doc/README.database). and the URL to the most recent database plugin documentation.

The problem we run into, is that the new version of Snort requires an upgrade to the Database schema. Now, the readme in the distro will point you to the scripts included in the distro's contrib directory. These will build a new snort database.

The problem is that I have 90 days worth of events I don't want to loose. So, the question how to change the schema without loosing the data. The answer is to simply:
  1. ALTER TABLE signature ADD sig_gid INT UNSIGNED;
    • This is the only addition needed by the new version of snort.
  2. INSERT INTO schema (vseq, ctime) VALUES ('107', now());
    • Snort queries the schema version when it starts to make sure the DB is compatible.
  3. DELETE from schema where vseq=;
    • Now we need to remove the previous version from the table
Now, restart Snort...and everything should come up fine.

Friday, May 11, 2007

Solaris & Linux Apps

You can read the full instructions here:
http://www.opensolaris.org/os/community/brandz/install/


# zonecfg -z Citrix
Citrix: No such zone configured
Use 'create' to begin configuring a new zone.
zonecfg:Citrix> create -t SUNWlx
zonecfg:Citrix> set zonepath=/export/zones/Citrix_root
zonecfg:Citrix> add net
zonecfg:Citrix:net> set address=192.168.0.20/24
zonecfg:Citrix:net> set physical=iprb0
zonecfg:Citrix:net> end
zonecfg:Citrix> add attr
zonecfg:Citrix:attr> set name="audio"
zonecfg:Citrix:attr> set type=boolean
zonecfg:Citrix:attr> set value=true
zonecfg:Citrix:attr> end
zonecfg:Citrix> commit
zonecfg:Citrix> exit
#

I used the CentOS tar ball dist that was made for Solaris10 SCLA:
http://opensolaris.org/os/community/brandz/downloads.


# zoneadm -z Citrix install -d /export/home/jc209962/centos_fs_image.tar
Installing zone 'Citrix' at root directory '/export/zones/Citrix_root'
from archive '/export/home/jc209962/centos_fs_image.tar'

# zoneadm list -iv
ID NAME STATUS PATH BRAND IP
0 global running / native shared
- Citrix installed /export/zones/Citrix_root lx shared

#
# zlogin Citrix
[Connected to zone 'Citrix' pts/5]
Welcome to your shiny new Linux zone.

- The root password is 'root'. Please change it immediately.

- To enable networking goodness, see /etc/sysconfig/network.example.

- This message is in /etc/motd. Feel free to change it.

For anything more complicated, see:
http://opensolaris.org/os/community/brandz/

You have mail.
-bash-2.05b# uname -a
Linux Citrix 2.4.21 BrandZ fake linux i686 i686 i386 GNU/Linux