Test of IPv6 in firewalls DNSSEC and IPv6 deployment workshop 2008



Similar documents
IPv6 support in firewalls. A report from.se by Håkan Lindberg and Tomas Gilså

IPv6 support in firewalls

Status of Open Source and commercial IPv6 firewall implementations

IPv6 Security from point of view firewalls

Firewalls und IPv6 worauf Sie achten müssen!

Track 2 Workshop PacNOG 7 American Samoa. Firewalling and NAT

Virtual Private Network VPN IPSec Testing: Functionality Interoperability and Performance

Internet Protocol: IP packet headers. vendredi 18 octobre 13

GregSowell.com. Mikrotik Security

IPv6 Security Best Practices. Eric Vyncke Distinguished System Engineer

Firewalls. Pehr Söderman KTH-CSC

The Myth of Twelve More Bytes. Security on the Post- Scarcity Internet

ASA 8.x: VPN Access with the AnyConnect VPN Client Using Self Signed Certificate Configuration Example

ScotGrid. Bolting the door. Network Based Security Mechanisms. David Crooks, Mark Mitchell on behalf of ScotGrid Glasgow

Recent advances in IPv6 insecurities Marc van Hauser Heuse Deepsec 2010, Vienna Marc Heuse

How To Set Up A Vns3 Controller On An Ipad Or Ipad (For Ahem) On A Network With A Vlan (For An Ipa) On An Uniden Vns 3 Instance On A Vn3 Instance On

Matt Ryanczak Network Operations Manager

How To Set Up An Ip Firewall On Linux With Iptables (For Ubuntu) And Iptable (For Windows)

INTRODUCTION TO FIREWALL SECURITY

Linux as an IPv6 dual stack Firewall

Securing the Transition Mechanisms

Cisco QuickVPN Installation Tips for Windows Operating Systems

IPv6 Fundamentals, Design, and Deployment

About the Technical Reviewers

PIX/ASA 7.x with Syslog Configuration Example

Configuring SSL VPN on the Cisco ISA500 Security Appliance

ACCREDITED SOLUTION. EXPLORER Cisco Systems VPN Client

About Me. Work at Jumping Bean. Developer & Trainer Contact Info: mark@jumpingbean.co.za

PIX/ASA: Allow Remote Desktop Protocol Connection through the Security Appliance Configuration Example

IPv6 Hardening Guide for Windows Servers

Joe Klein, CISSP IPv6 Security Researcher

Securing IPv6. What Students Will Learn:

SECURITY IN AN IPv6 WORLD MYTH & REALITY. SANOG XXIII Thimphu, Bhutan 14 January 2014 Chris Grundemann

Full version is >>> HERE <<<

Microsoft Azure Configuration

Virtual private network. Network security protocols VPN VPN. Instead of a dedicated data link Packets securely sent over a shared network Internet VPN

IPv4 and IPv6 Integration. Formation IPv6 Workshop Location, Date

Presentation_ID. 2001, Cisco Systems, Inc. All rights reserved.

I've applied for a goipv6 account and received my password via but I cannot log into my account. What should I do?

Lab Configuring Access Policies and DMZ Settings

Getting started with IPv6 on Linux

ACL Compliance Director FAQ

CIRA s experience in deploying IPv6

CSC574 - Computer and Network Security Module: Firewalls

IPv6 Network Security.

Optimisacion del ancho de banda (Introduccion al Firewall de Linux)

Security implications of the Internet transition to IPv6

IPv6 Transport Support and Market Segmentations

Use Shrew Soft VPN Client to connect with IPSec VPN Server on RV130 and RV130W

Chapter 11 Cloud Application Development

CenturyLink Cloud Configuration

IPv6 en Windows. Juan Jackson Pablo García

Internet Firewall CSIS Internet Firewall. Spring 2012 CSIS net13 1. Firewalls. Stateless Packet Filtering

Transactions. Georgian Technical University. AUTOMATED CONTROL SYSTEMS - No 1(8), 2010

Virtual Private Networks

Configuring an IPsec VPN to provide ios devices with secure, remote access to the network

Firewall Firewall August, 2003

Port Scanning. Objectives. Introduction: Port Scanning. 1. Introduce the techniques of port scanning. 2. Use port scanning audit tools such as Nmap.

VPN Configuration Guide D-Link DFL-800

Introduction to IP v6

DHCP, ICMP, IPv6. Computer Networking: A Top Down Approach 6 th edition Jim Kurose, Keith Ross Addison-Wesley DHCP. DHCP UDP IP Eth Phy

Computer Networks: DNS a2acks CS 1951e - Computer Systems Security: Principles and Prac>ce. Domain Name System

Multi-Homing Dual WAN Firewall Router

More details >>> HERE <<<

Firewalls and Network Defence

IPv6 Infrastructure Security

IPv6 Opportunity and challenge

Chapter 4 Customizing Your Network Settings

This chapter describes how to set up and manage VPN service in Mac OS X Server.

Using Opensource VPN Clients with Firetunnel

Debugging With Netalyzr

Firewalls. Chapter 3

Solutions techniques pour faciliter la coexistence et la transition vers IPv6

CS Computer and Network Security: Firewalls

+ iptables. packet filtering && firewall

Volume SYSLOG JUNCTION. User s Guide. User s Guide

IP Gateways. Gdansk University of Technology Mariusz Stankiewicz 24th March 2011

Firewall implementation and testing

Basic IPv6 WAN and LAN Configuration

Deploying IPv6, Now. Christian Huitema. Architect Windows Networking & Communications Microsoft Corporation

Building Your Firewall Rulebase Lance Spitzner Last Modified: January 26, 2000

Operational Problems in IPv6: Fallback and DNS issues

Moonv6 Test Suite DRAFT

WorldSkills Competition 2011 Austrian Championship. IT Network Systems Administrator Day 1

Cisco Configuring Commonly Used IP ACLs

Guide to Network Defense and Countermeasures Third Edition. Chapter 2 TCP/IP

Network Defense Tools

CS Computer and Network Security: Firewalls

Virtual Private Networks

How To Extend Security Policies To Public Clouds

Procedure: You can find the problem sheet on Drive D: of the lab PCs. 1. IP address for this host computer 2. Subnet mask 3. Default gateway address

An Introduction to Nmap with a Focus on Information Gathering. Ionuț Ambrosie

Security of IPv6 and DNSSEC for penetration testers

Table of Contents. Cisco Configuring the PPPoE Client on a Cisco Secure PIX Firewall

A host-based firewall can be used in addition to a network-based firewall to provide multiple layers of protection.

Workload Firewall Management

Automating Server Firewalls

UNDERSTANDING IDENTITY-BASED NETWORKING SERVICES AUTHENTICATION AND POLICY ENFORCEMENT

Chapter 7 Troubleshooting

NETGEAR ProSAFE WC9500 High Capacity Wireless Controller

Transcription:

v1.0 Test of IPv6 in firewalls DNSSEC and IPv6 deployment workshop 2008 hakan.lindberg@b3it.se, tomas_gilsa@yahoo.se

Agenda Tomas Gilså freelance journalist What, how and why? Hakan Lindberg B3IT Test and results Hakan Nohre Cisco Ola Holmberg 3COM Juniper Q & A

What did we test? This was a gentle test. We asked the companies that sell firewalls ls in Sweden if they wanted to participate in a small test about Firewalls with support for IPv6. Out of around 25 vendors we ended up with six machines from five different vendors. Why did we test it? To see the status of IPv6-readiness among the vendors and to document what works today. TheSwedish foundation for Internet Infrastrucure (IIS) that runs the top level domain.se wanted this as a part of the conference Internetdagarna in Stockholm October 20-22, 22, 2008 Who paid for this? The vendors and some ISP:s volunteered machines and time. IIS paid for project management, setup and documentation.

Why IPv6? We are running out of IPv4 addresses. The current use of DHCP, NAT and such is good for privacy but sometimes bad for security. With IPv6 addresses each machine on the net can have a unique address. This makes it easier to block individual computers and open up services for individual computers. Why now? Several ISP:s sell IPv6 connectivity. Windows Vista, Windows Server 2008, Mac OS X and All Linux distributions have good support for IPv6. Windows XP can basically do it all except DNS-queries over IPv6. So IIS wanted to see how the hardware were doing IPv6-wise.

What did we learn? In IPv6 the addresses should be handled by machines. A great deal of project management to gather suppliers Hard to get the IPv6 hardware Suppliers initially said they were on and then jumped off the tests The devil is in the details. When things are set up correctly things work as intended. Who won? We didn t t test that way. We even deliberately mixed apples and oranges. One reason was that there just isn t t that many IPv6- Firewalls available. Another reason was to get more of a survey and show that you can run IPv6 in both big and small machines today.

Tested: 3Com MSR 50 Cisco ASA 5505 (replaces the PIX) 2800 with IOS 12.4 Halon SX101 Juniper ISG 2000 Monowall 1.3b14 (on Soekris hardware) (SnapGear SG650) (D-link DIR-615, 524)

Positive from the beginning but Checkpoint / FW-1 Extreme Networks Fortinet Initially declined Clavister Netgear Sonicwall Watchguard and a few others

What is a firewall?

Do we need firewalls with IPv6? Will it differ between large enterprises via small offices to the home market? We have a possibility to build firewalls nice and clean without NAT. But still: it s s a firewall there + centralized security function, VPN-concentrator + policy or standard like PCI + In Sweden home networks are popular. One address would be a step backwards. - False sense of security. We can still download evil code! - NAT/masquerading. Security by obscurity NAT was not standardized (same with masquerading?)

When are we IPv6 ready? About 350 products have the IPv6-ready logo E.g. D-link DI-524 and DIR-615 has the logo. So we bought them (WLAN equipment with NAT, not explicitly a firewall). No IPv6-support in the tested equipment. D-link is not shipping the IPv6 release in the EU.

SSAC Typically looks like:

SSAC One of three firewalls has IPv6-support Limited support for advanced IPv6-firewall functions in the segment SOHO, SMB Suppliers say that the demand for IPv6 is limited The SSAC survey results do suggest that an organization that adopts IPv6 today may not be able to duplicate IPv4 security feature and policy support Our result from the tests: It is definitely good enough to start testing and for (limited) operation

A A Profile for IPv6 in the U.S. Government from NIST Item 6.12 is interesting and handles Network Protection Devices (firewalls, IDS, IPS) They put Application firewalls in a chapter of its own. Inspiration we got from the report: Persistence (power drop-out) out) Management Several levels? Logging Good quotes like Firewalls MUST perform properly up to their design load; in circumstances which exceed this load or otherwise result t in operational degradation or failure, they MUST fail in such a manner ner as not to allow unauthorized access.

S1 S2 IPv6 Test network Tele2 Cisco 7600 IPv6 Internet 2a00:801:f2:1/64 ::3 Ubuntu Linux eth0 eth1 ::3 2a00:801:f2:2 /64 IPv6 native (no dual stack) ::5 ::3 2a00:801:f2:3 /64 ::6 A B 2a00:801:f2:1000 /56 2a00:801:f2:2000 /56 IPv4 for config. C1 (Win Vista) C2 (Mac OS)

Test results 1 (2) Preliminary Equipment Cisco ASA 5505 Cisco 2800 w/ IOS 12.4 Juniper ISG 2000 C1 can reachipv6 resources (DNS, HTTP, SMTP) C1 could ping (ICMP) * Filtering of addresses Filtering of networks Filtering ICMP Up/down [Mbps] OK OK OK OK OK 65/ 80 OK OK OK OK OK OK 65/80 OK OK OK OK OK OK 75/90 OK Monowall OK OK OK OK OK 70/85 OK Filtering and logging reject, local log

Test results 2 (2) Preliminary Equipment C1 can reachipv6 resources (DNS, HTTP, SMTP) C1 could ping (ICMP) * Filtering of addresses Halon OK OK Problems with filtering DNS Filtering of networks same as address Filtering ICMP Hard. Must know ICMP type and code Up/down [Mbps] 60/ 75 OK 3COM * OK OK OK OK OK 75/85 OK Snapgear Basic 6to4 - - - - - - Filtering and logging reject, local log *) basically no SPI, only ACL

Test results Start testing now. Ready for 1st phase operation Get used to addresses, prefixes, rules Bad performance of IPv6-packets is a myth (or an old thruth) Logging and administration worked better than expected E.g. HTTP over IPv6 and SSH over IPv6 did work We did not send logs to remote hosts ICMP is tricky since it is used differently in IPv6 (e.g. Neighbor Discovery). If we accept ICMP echo reply we might implicitly reject other ICMP packets ICMPv4 rules cannot be applied DNS: since DNS-packets are bigger with IPv6 (> 512 byte) you may need to adjust rules

Further testing that could be done: Header extensions Fragmentation Intentionally to fool firewalls. IPsec We will test LAN-LAN IPsec the 21 and 22 Masquerading Applications above IPv6 Tunneling Prefix delegation

Further reading We will present the test in a report by the 22th of Nov. Check the IIS website. SAC report 021 ICANN Security and Stability Advisory Committe Survey of IPv6 Support in Commercial Firewalls October 2007 NIST National Institute of Standard and Technology A Profile for IPv6 in the U.S.Government Draft from Feb 2007 and later