Agenda Security Workshop Control Plane Forwarding Plane Management Plane

Similar documents
untitled

All Rights Reserved. Copyright(c)1997 Internet Initiative Japan Inc. 1

橡C14.PDF

total.dvi

Welcome! MPLS Japan で 初めて Multicast を特集します 2

Agenda IPv4 over IPv6 MAP MAP IPv4 over IPv6 MAP packet MAP Protocol MAP domain MAP domain ASAMAP ASAMAP 2

JANOG14-コンバージェンスを重視したMPLSの美味しい使い方

Win XP SP3 Japanese Ed. NCP IPSec client Hub L3 SW SRX100 Policy base VPN fe-0/0/0 vlan.0 Win 2003 SVR /

PowerPoint プレゼンテーション

2011 NTT Information Sharing Platform Laboratories

Cisco® ASA シリーズルーター向けDigiCert® 統合ガイド

ループ防止技術を使用して OSPFv3 を PE-CE プロトコルとして設定する

Microsoft PowerPoint - janog20-bgp-public-last.ppt

SCREENOS NAT ScreenOS J-Series(JUNOS9.5 ) NAT ScreenOS J-Series(JUNOS9.5 ) NAT : Destination NAT Zone NAT Pool DIP IF NAT Pool Egress IF Loopback Grou

IP IPv4-IPv6

橡2-TrafficEngineering(revise).PDF

橡sirahasi.PDF

Juniper Networks Corporate PowerPoint Template

橡3-MPLS-VPN.PDF

設定例集_Rev.8.03, Rev.9.00, Rev.10.01対応

untitled

untitled

アドレス プールの設定

BGPルートがアドバタイズされない場合のトラブルシューティング

設定例集

宛先変更のトラブルシューティ ング

Cisco ASA Firepower ASA Firepower

untitled

untitled

Dynamic VPN Dynamic VPN IPSec VPN PC SRX IPSec VPN SRX PC IPSec 2 Copyright 2010 Juniper Networks, Inc.

untitled

untitled

今日のトピック 実験結果の共有 RPKI/Router 周りの基本的な動き 今後の課題と展望 2012/7/6 copyright (c) tomop 2

Clos IP Fabrics with QFX5100 Switches

IIJ Technical WEEK SEILシリーズ開発動向:IPv6対応の現状と未来

untitled

IPv4aaSを実現する技術の紹介

SRX IDP Full IDP Stateful Inspection 8 Detection mechanisms including Stateful Signatures and Protocol Anomalies Reassemble, normalize, eliminate ambi

IP.dvi

Microsoft PowerPoint irs14-rtbh.ppt

WG /04/

IPSEC-VPN IPsec(Security Architecture for Internet Protocol) IP SA(Security Association, ) SA IKE IKE 1 1 ISAKMP SA( ) IKE 2 2 IPSec SA( 1 ) IPs

SRT/RTX/RT設定例集

初めてのBFD

ネットワークのおべんきょしませんか? 究める BGP サンプル COMMUNITY アトリビュートここまで解説してきた WEIGHT LOCAL_PREFERENCE MED AS_PATH アトリビュートはベストパス決定で利用します ですが COMMUNITY アトリビュートはベストパスの決定とは

SRX License

( )

JUNOSインターネットソフトウェアとIOSのコンフィグレーション変換

2

Microsoft PowerPoint - Amazon VPCとのVPN接続.pptx


3. LISP B EID RLOC ETR B 4. ETR B ITR A 1: LISP 5. ITR A B EID RLOC 6. A SYN 7. ITR A ITR A B EID RLOC SYN ITR A RLOC ETR B RLOC 8. ETR B SYN ETR B B

IPv6 IPv6 IPv4/IPv6 WG IPv6 SWG

CCIE IP Anycast RP Anycast RP Anycast RP Anycast RP PIM-SM RP RP PIM-SM RP RP RP PIM Register RP PIM-SM RP PIM-SM RP RP RP RP Auto RP/BSR RP RP RP RP

AMFマルチテナントソリューション

untitled

2

ES1018V2_24V2_MG.book

アライドテレシス ディストリビューション・スイッチ AT-x600シリーズで実現するMicrosoft® NAP

Packet Tracer: 拡張 ACL の設定 : シナリオ 1 トポロジ アドレステーブル R1 デバイスインターフェイス IP アドレスサブネットマスクデフォルトゲートウェイ G0/ N/A G0/

MOTIF XF 取扱説明書

外部ルート向け Cisco IOS と NXOS 間の OSPF ルーティング ループ/最適でないルーティングの設定例

MVPN VPN VPN MVPN P2MP TE & BGP

Cisco Aironet 1130AG アクセス ポイント クイック スタート ガイド

第1回 ネットワークとは

帯域を測ってみよう (適応型QoS/QoS連携/帯域検出機能)

RT300i/RT140x/RT105i 取扱説明書

Microsoft PowerPoint - ykashimu_dslite_JANOG26_rev

Z7000操作編_本文.indb

AirMac ネットワーク構成の手引き

IOS ゾーン ベースのポリシー ファイアウォールを使用した IOS ルータでの AnyConnect VPN クライアントの設定例

LSM-L3-24設定ガイド(初版)

2

Teradici Corporation # Canada Way, Burnaby, BC V5G 4X8 Canada p f Teradici Corporation Teradi

RT300/140/105シリーズ 取扱説明書

PowerPoint プレゼンテーション

Cisco Umbrella Branch Cisco Umbrella Branch Cisco ISR Umbrella Branch


RTX830 取扱説明書

Autonomous アクセス ポイント上の WEP の設定例

Transcription:

JANOG Interdomain Routing Security Workshop 7 July 2004 Miya Kohno (mkohno@cisco.com)

Agenda 2004 5 26 Security Workshop (@SanJose) Control Plane Forwarding Plane Management Plane

Agenda 2004 5 26 Security Workshop (@SanJose) Control Plane Forwarding Plane Management Plane

Security Workshop @ SanJose (26 May 2004) NANOG31(@SF) Cisco SanJose Tim Battle (AT&T Security Operations) Jared Mauch (Verio/NTT Operations) Ryan McDowell (Sprint Operations) Christopher L. Morrow (MCI Security Operations) Cisco

AT&T Receive ACL for GRP protection WRED for preventing buffer over utilization urpf + ACL for source address assurance Netflow for monitoring and detecting NW anomalies --- getting very important Remote Triggered Blackholes for diverting traffic to null0 and scrubbling device Configuration auditing for preventing mis-configuration Command Automation for quick trouble shooting

AT&T Consistency of configurations and commands across platforms. Feature commands should be identical between platforms and images. Consistency of services across SP platform (Netflow, racls)

Sprint Issues Lack of MIB for urpf drops Lack of MIB for racl matches Lack of uniform feature support across platforms urpf, racl, source-tracker Inability to kill listening processes e.g. UDP/496 (PIM-RP-DISC) ACLs are pathetic Need a bit mask to filter on any bit(s) anywhere in an IP packet BGP reorganization Too many CLIs BGP route analysis Only way to get full view is screen scrape

Sprint Issues BGP max-prefix Needs to try and reestablish or just stop accepting routes above limit No easy way to see how many routes advertised to BGP peer Put advertised routes in show ip bgp summary show ip bgp <domain-name> broken urpf any route needed Not just strict mode Source-Tracker Automatic shutoff if pps rate exeeds threshold Only show counts that match an ACL (e.g. TCP/80/SYN) Netflow Show cache that maches src/dst address, etc. SSH host keys n routers Need a way to copy to new RP

NTT/Verio - Challenges Not consistent or implemented on all IOS devices Interface ACLs don t scale No way to globally apply acl to all interfaces to block worm traffic (e.g. ms-sql/slammer) urpf setting global on 6k Lack of consistent packet inspection techniques in router configuration

NTT/Verio - Challenges How to stop (filter, police, otherwise) attacks rapidly? Rapidly pushing out configuration changes to hundreds of devices Differences in configuration semantics create troubles and inconsistency (platform, sw rev) Avoiding configuration drift Signaling across existing database infrastructure via BGP?

MCI Line Rate ACLs on all interfaces ACLs on all interfaces on all platforms Full packet match capability Line Rate ACLs on all platforms (core) Don t limit acls to edge platforms, todays core is tomorrows edge TTL filtering in ACLs and Services Set outbaound ttl/default-ttl

What s important Consistency, Consistency, Consistency!! Scalability Simplicity Stability

Agenda 2004 5 26 Security Workshop (@SanJose) Control Plane Forwarding Plane Management Plane

Control Plane Control Plane Peering Relationship Guarded Trust TCP MD5 BGP over Ipsec (?!) BTSH/GTSM (RFC3682) prefix AS originate S-BGP, SO-BGP (?!!!!)

Guarded Trust Egress Filter Ingress Filter Prefixes ISP A ISP B Prefixes Guarded Trust, Mutual Suspicion (J) ISP A ISP B Global Internet Table X prefixes ISP B ISP A X prefixes egress filter ISP A ISP B X prefixes igress filter ISP A ingress filter ISP B egress filter

TCP MD5 TCP MD5 Authentication Key distribution RFC1321 MD5. RFC2385 MD5 with BGP RFC3562 MD5 key TCP MD5

BGP over IPSec IP sec Transport Peering Relation draft-ward-bgp-ipsec?!!! IPsec

TTL sanity check BTSH BGP TTL security hack draft-gill-btsh GTSM Generalized TTL security Mechanism RFC3682 254 TTL reject TTL=255 ebgp speaker TTL =255 ebgp speaker 254 253 TTL A ebgp

TTL sanity check device BGP speaker accept BGP speaker 254 TTL reject TTL=255 A ebgp accept

Forwarding Plane ACL with performance and scalability urpf Strict Loose (triggered black hole filtering ) Netflow Traffic

Management Plane Default Access Denied AAA & encryption protocols for console login SSH, SSL, IPSec Isolation of Management Ports

Agenda 2004 5 26 Security Workshop (@SanJose) Control Plane Forwarding Plane Management Plane

What s Next???! BGP over IPSec?! S-BGP / SO-BGP? Ptomaine Prefix Taxonomy Ongoing Measurement & Internetwork Experiment http://www.ietf.org/html.charters/ptomaine-charter.html RPSEC Routing Protocol Security Requirements Working Group http://www.ietf.org/html.charters/rpsec-charter.html

S-BGP/SO-BGP Peering Relationship route flaps excessive routes AS prefix originate authorize prefix originate AS reachable prefix peer S-BGP, SO-BGP?!! S-BGP: http://www.net-tch.bbn.com/sbgp/sbgp-index.html SO-BGP: ftp://ftp-eng.cisco.com/sobgp/index.html

SO-BGP S-BGP SO-BGP central authority deploy AS deployment BGP UPDATE

SO-BGP Certificate Transport Certificate Processing Update Processing

Certificate Transport SO-BGP Transport Certificate SO-BGP device draft-ng-sobgp-bgpextensions New BGP SECURITY message Certificates are carried within TLVs security

Certificate Operation EntityCert Signer AS AS PubKey PolicyCert AS Policy AuthCert Auth AS AS Address Signature Signature Signature AS AS AS AS PubKey PubKey PubKey PubKey known valid keys policy database Auth database topology database topology graph Origin AS Path Prefix Update

Update Processing AS path hop(the origin AS) AuthCert Prefix AS authorize AuthCert AuthCert database policy database received Update Origin AS Path Prefix topology graph

Update Processing AS path AS path AuthCert database policy database received Update Origin AS Path Prefix topology graph

SO-BGP Deployment Deployment Options Incremental Deployment

Deployment Options ebgp peering point(as certificate ebgp certificate sobgp processing certificate exchange

Deployment Options ibgp AS certificate certificate Edge RADIUS UPDATE validation sobgp processing certificate exchange

Deployment Options multihop ebgp certificate sobgp processing certificate exchange

Deployment Options third party certificate Validation process certificate sobgp processing certificate exchange

Incremental Deployment SO-BGP AS ebgp multihop certificate sobgp AS certificate validation certificate update PolicyCerts connectivity AS Path second hop validate AS PATH validation no sobgp second hop validation sobgp no sobgp

SO-BGP

Inter-domain security feedback loop

Thank you!