Friday, September 6, 2019

Configuring FTD 6.2.3 via Firepower Device Manager (FDM)

Here's a nice link for the Cisco Firepower Device Manager (FDM) Youtube video training.

You can login to FDM via HTTPS on a web browser. The FDM is purely managed via web/HTTPS and doesn't require Java installed unlike with the old ASDM.

The default HTTPS IP address is 192.168.45.45 and default login: admin / Admin123


You'll automatically walkthrough the FTD initial setup wizard.


The first step (you can optionally skip this) is to connect the FTD G0/0 (Outside) interface to your ISP modem/router > configure G0/0 Outside (WAN) Interface, under Configure IPv4 > select Using DHCP (auto obtain an IP address).

By default, the FTD setup wizard assumes G0/0 is connected to the Outside/ISP and G0/1 connects to the Inside LAN. In this case, my FTD G0/0 is connected to the ISP ONT fiber device. You can select Manually input to configure a static IP address.


I left the default OpenDNS for the Primary and Secondary DNS IP Address under the Management Interface.

You can edit the FTD hostname under Firewall Hostname. Click Next.



The changes took several minutes as FTD was testing the ISP/WAN connectivity and tried to connect to Cisco (www.cisco.com).


The FTD test to ISP/WAN/Gateway took around 2-3 minutes to complete. I encountered an error: Connection testing failed since I had my laptop directly connected to FTD's MGMT port.

Just ignore this error for now and continue with the FTD's initial setup.


Select the Time Zone (in my case UTC+8 Asia/Singapore). Click on the icon with the letter i to get more information.

I left the Default NTP Time Server under NTP Time Server. Click Next.
 

You'll need to register the FTD with Cisco Smart Licensing Server. You can skip this for now and just scroll down.


Select the Start 90-day evaluation period without registration to enable the free 90-day eval license: URL Filtering, Malware, Threat (IPS, Security Intelligence). Click Finish.


Click on option 1: Configure Interfaces. This will bring you to the Device Summary page for Interfaces.


Notice the three FTD ports are green or active: MGMT, G0/0 (outside) and G0/1 (inside).


I troubleshoot the FTD WAN/ISP connectivity via CLI and detected the Outside G0/0 is up/up (Layer 1 and 2) and received an IP address via DHCP from the ISP fiber ONT device.

It also received a default route and FTD can ping the Internet (Google DNS 8.8.8.8)

> show interface GigabitEthernet 0/0
Interface GigabitEthernet0/0 "outside", is up, line protocol is up
  Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
        Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
        Input flow control is unsupported, output flow control is off
        MAC address b0fa.eb97.72cc, MTU 1500
        IP address 222.164.10.189, subnet mask 255.255.254.0
        415741 packets input, 27314861 bytes, 0 no buffer
        Received 396234 broadcasts, 0 runts, 0 giants
        5 input errors, 5 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
        0 pause input, 0 resume input
        0 L2 decode drops
        302 packets output, 121222 bytes, 0 underruns
        0 pause output, 0 resume output
        0 output errors, 0 collisions, 22 interface resets
        0 late collisions, 0 deferred
        0 input reset drops, 0 output reset drops
        input queue (blocks free curr/low): hardware (485/456)
        output queue (blocks free curr/low): hardware (511/508)
  Traffic Statistics for "outside":
        413760 packets input, 19690501 bytes
        197 packets output, 53516 bytes
        17863 packets dropped
      1 minute input rate 361 pkts/sec,  17102 bytes/sec
      1 minute output rate 0 pkts/sec,  1 bytes/sec
      1 minute drop rate, 13 pkts/sec
      5 minute input rate 379 pkts/sec,  17956 bytes/sec
      5 minute output rate 0 pkts/sec,  0 bytes/sec
      5 minute drop rate, 14 pkts/sec

> show route

Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2, V - VPN
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route, + - replicated route
Gateway of last resort is 222.164.10.1 to network 0.0.0.0

S*       0.0.0.0 0.0.0.0 [1/0] via 222.164.10.1, outside
C        192.168.1.0 255.255.255.0 is directly connected, inside
L        192.168.1.1 255.255.255.255 is directly connected, inside
C        222.164.10.0 255.255.254.0 is directly connected, outside
L        222.164.10.189 255.255.255.255 is directly connected, outside

> ping 8.8.8.8
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/10 ms


You can also launch a CLI prompt and issue CLI commands by clicking the CLI Console icon.




I'm unable to perform FTD Updates since the MGMT interface requires an Internet connectivity to get its update from the Cisco Cloud.



I connected the devices according to my lab topology. The FTD MGMT and G0/1 (inside) interfaces are both in a common Layer 2 VLAN. I used a flat network on VLAN 1 on the switch for simplicity.


Notice the ISP/WAN/Gateway, Internet, DNS Server and NTP server turned green afterwards.


To perform FTD Updates: Geolocation, Rule (IPS), Vulnerability Database (VDB) and Security Intelligence (SI) Feed, click Device > Updates > View Configuration.

Click on the i and it informs you that Update may be large and can take up to 45 minutes. Click Update Now on each FTD Update.
 

Under Rule Update > click Update Now > click Yes to continue.


Under VDB Update > click Update Now > click Yes to continue.


Click See Task List to view the individual Update download/install status.



Click Configure to change the Frequency and Time under each Update.




To enable the Smart License features (Threat, Malware, URL), click Device > Smart License > View Configuration.


You can also view how many days are left for the 90-day Evaluation License (86 days left).

Notice only the Base License (included by default), which is used for Base Firewall Capabilities (switching/routing, ACL and NAT) and Application Visibility and Control (AVC), is automatically Enabled.


Aside from activating the 90-day Evaluation license, you'll also need to Enable each feature for Threat, Malware and URL. Click Enable under each feature.



To perform FTD Configuration backup and recovery, click Device > Backup and Restore > View Configuration.


You can configure the frequency on either Recurring (multiple) or Scheduled (one-time) Backup.


I'll just perform a Manual Backup (immediate) in this case by clicking Backup Now > type a Name for the Backup file (FTD-Config-31July2019) > optionally type a Description > click Backup Now.



The FTD Manual Backup took several minutes to complete (around 4 minutes).


Notice the Backup file will appear which you can download by hovering under Actions > click Download.


Click OK and the Backup file will be saved to your Downloads folder.



There's a couple of ways to roll back or restore to a previous configuration in FTD. The first option is under Upload > click Browse > choose a Backup file.


Click Upload to Continue.


The other way to restore the FTD configuration is to select a specific backup file > hover under Actions > click Restore (green icon).


Click Do not delete the backup after restoring if you want to keep the backup file. Click Restore. There's a warning: A restore will trigger a reset of the device. The FTD will automatically reboot after the backup restore.



To change the Management Access on FTD, click Device > System Settings > Management Access.

Under Management Interface, notice both the HTTPS and SSH management protocols are enabled by default for any IPv4 and IPv6 networks.


You can configure specific interface or security zones to allow management traffic on the FTD under Data Interfaces > hover under Actions to edit the inside interface.


Click the plus (+) icon to configure an interface for management access to the FTD.



You can configure Syslog under System Settings > Logging Settings (on the left). You can change the Logging Severity and configure an external Syslog server.


Click DHCP Server under System Settings.


In this case, I'll remove the default DHCP server for the inside interface since everything in my lab is using a static IP address.

Hover under Actions > Delete (trash icon) > OK to delete the DHCP server.
 


Notice an orange or amber dot on the Deployment icon if there's a pending change on the FTD.
 
You can make all your changes in one go and deploy once. Click the Deployment > Deploy Now.





Notice the orange/amber dot has disappeared after the Deployment push.

To create again a DHCP Server on a specific interface, click Create DHCP Server.


Toggle Enabled DHCP server > select an interface >type an Address Pool.


You can change the outside interface's DHCP configuration (from the ISP) under Configuration.

This is similar to the ASA ip address dhcp setroute command.


Click Monitoring to view the FTD System Dashboard statistics and various graphs.




Click Events to view Connection Logs. Hover a specific Connection Log > click View Details to see more info.


Click Policies to view NAT and Access Control policies.

Notice there's a default Dynamic NAT (PAT) policy under Manual NAT Rules configured for Any IPv4 Source Address and Any Source Port which is translated on the FTD outside interface going to Any Destination Address and Any Destination Port.


There's also a default Access Control rule #1 which has an Action: Trust for Any Networks and Any Ports sourced from the inside zone going to Any Destination Networks and Any Ports and Any Protocol on the outside zone.

Notice there's an implicit Default Action: Block at the bottom of the Access Control Rules.


Click Objects to view various Object Types: Networks, Ports, Security Zones, etc.


For troubleshooting and escalating to Cisco TAC, they might require you to send a troubleshooting file which is found under Troubleshoot > click Request File To Be Created.


There's a note: It can take up to 1 hour to generate the troubleshooting file depending on the device load.


Click See Task List to monitor the status.


A tar.gz compressed file will be generated.


You can download the Troubleshooting file by clicking the download icon (arrow pointing down).



Saturday, August 3, 2019

Cisco ASA 5515-X Password Recovery

I needed to perform a password recovery on a used Cisco ASA 5515-X firewall and do a factory reset afterwards. This is to prepare the ASA in converting to Firepower Threat Defense (FTD). This is my "new" lab rack with a Cisco 1921 ISR G2 router.


Booting from ROMMON

Cisco Systems ROMMON Version (2.1(9)8) #1: Wed Oct 26 17:14:40 PDT 2011


Use BREAK or ESC to interrupt boot.    // HIT ESC
Use SPACE to begin boot immediately.
Boot interrupted.                              

Management0/0
Link is DOWN
MAC Address: b0fa.eb97.7abc


Use ? for help.
rommon #0> confreg 0x41    // BYPASS STARTUP-CONFIG

Update Config Register (0x41) in NVRAM...

rommon #1> confreg

Current Configuration Register: 0x00000041
Configuration Summary:
  boot default image from Flash
  ignore system configuration

Do you wish to change this configuration? y/n [n]: <ENTER>

rommon #2> boot
Launching BootLoader...
Boot configuration file contains 2 entries.


Loading disk0:/asa952-2-smp-k8.bin... Booting...
Platform ASA5515

Loading...
IO memory blocks requested from bigphys 32bit: 36825
INIT: version 2.88 booting
Starting udev
Configuring network interfaces... done.


<SNIP>


                Cisco Systems, Inc.
                170 West Tasman Drive
                San Jose, California 95134-1706

Ignoring startup configuration as instructed by configuration register.  

INFO: Power-On Self-Test in process.
.......................................................................
INFO: Power-On Self-Test complete.

INFO: Starting HW-DRBG health test...
INFO: HW-DRBG health test passed.

INFO: Starting SW-DRBG health test...
INFO: SW-DRBG health test passed.
Type help or '?' for a list of available commands.
ciscoasa> enable
Password:  <ENTER>
ciscoasa# write erase
Erase configuration in flash memory? [confirm]
[OK]
ciscoasa# configure terminal
ciscoasa(config)#

***************************** NOTICE *****************************

Help to improve the ASA platform by enabling anonymous reporting,
which allows Cisco to securely receive minimal error and health
information from the device. To learn more about this feature,

Would you like to enable anonymous error reporting to help improve
the product? [Y]es, [N]o, [A]sk later:
ciscoasa(config)# no config-register   // REVERT BACK ORIGINAL CONFIG REGISTER TO 0x1
ciscoasa(config)# show version

Cisco Adaptive Security Appliance Software Version 9.5(2)2
Device Manager Version 7.1(1)52

Compiled on Tue 22-Dec-15 10:06 PST by builders
System image file is "disk0:/asa952-2-smp-k8.bin"
Config file at boot was "startup-config"

ciscoasa up 1 min 3 secs

Hardware:   ASA5515, 8192 MB RAM, CPU Clarkdale 3059 MHz, 1 CPU (4 cores)
            ASA: 3598 MB RAM, 1 CPU (1 core)
Internal ATA Compact Flash, 8192MB
BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB

Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
                             Boot microcode        : CNPx-MC-BOOT-2.00
                             SSL/IKE microcode     : CNPx-MC-SSL-SB-PLUS-0005
                             IPSec microcode       : CNPx-MC-IPSEC-MAIN-0026
                             Number of accelerators: 1
Baseboard Management Controller (revision 0x1) Firmware Version: 2.4


 0: Int: Internal-Data0/0    : address is b0fa.eb97.72c8, irq 11
 1: Ext: GigabitEthernet0/0  : address is b0fa.eb97.72cc, irq 10
 2: Ext: GigabitEthernet0/1  : address is b0fa.eb97.72c9, irq 10
 3: Ext: GigabitEthernet0/2  : address is b0fa.eb97.72cd, irq 5
 4: Ext: GigabitEthernet0/3  : address is b0fa.eb97.72ca, irq 5
 5: Ext: GigabitEthernet0/4  : address is b0fa.eb97.72ce, irq 10
 6: Ext: GigabitEthernet0/5  : address is b0fa.eb97.72cb, irq 10
 7: Int: Internal-Data0/1    : address is 0000.0001.0002, irq 0
 8: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 0
 9: Int: Internal-Data0/2    : address is 0000.0001.0003, irq 0
10: Ext: Management0/0       : address is b0fa.eb97.72c8, irq 0

Licensed features for this platform:
Maximum Physical Interfaces       : Unlimited      perpetual
Maximum VLANs                     : 100            perpetual
Inside Hosts                      : Unlimited      perpetual
Failover                          : Active/Active  perpetual
Encryption-DES                    : Enabled        perpetual
Encryption-3DES-AES               : Enabled        perpetual
Security Contexts                 : 2              perpetual
Carrier                           : Disabled       perpetual
AnyConnect Premium Peers          : 2              perpetual
AnyConnect Essentials             : Disabled       perpetual
Other VPN Peers                   : 250            perpetual
Total VPN Peers                   : 250            perpetual
AnyConnect for Mobile             : Disabled       perpetual
AnyConnect for Cisco VPN Phone    : Disabled       perpetual
Advanced Endpoint Assessment      : Disabled       perpetual
Shared License                    : Disabled       perpetual
Total UC Proxy Sessions           : 2              perpetual
Botnet Traffic Filter             : Disabled       perpetual
IPS Module                        : Disabled       perpetual
Cluster                           : Enabled        perpetual
Cluster Members                   : 2              perpetual

This platform has an ASA 5515 Security Plus license.

Serial Number: FCH1704JABC
Running Permanent Activation Key: 0x022ceb6a 0x98a0f168 0x0160d178 0xe22c1123 0xc213d456
Configuration register is 0x41 (will be 0x1 at next reload)

Image type          : Release
Key version         : A

Configuration last modified by enable_15 at 16:25:30.869 UTC Sat Jul 13 2019
ciscoasa(config)# write memory
Building configuration...
Cryptochecksum: 80058db4 55493994 722aeddf 194087d3

2465 bytes copied in 0.750 secs
[OK]
ciscoasa(config)# reload
Proceed with reload? [confirm]
ciscoasa(config)#


***
*** --- START GRACEFUL SHUTDOWN ---
Shutting down isakmp
Shutting down sw-module
Shutting down License Controller
Shutting down File system


***
*** --- SHUTDOWN NOW ---
Process shutdown finished
Rebooting.....
INIT: Sending processes the TERM signal
Deconfiguring network interfaces... done.
Sending all processes the TERM signal...
Sending all processes the KILL signal...
Deactivating swap...
Unmounting local filesystems...
Rebooting...


<SNIP>


Reading from flash...
!.
Cryptochecksum (unchanged): 80058db4 55493994 722aeddf 194087d3

INFO: Power-On Self-Test in process.
.......................................................................
INFO: Power-On Self-Test complete.

INFO: Starting HW-DRBG health test...
INFO: HW-DRBG health test passed.

INFO: Starting SW-DRBG health test...
INFO: SW-DRBG health test passed.
Type help or '?' for a list of available commands.
ciscoasa> enable
Password:  <ENTER>
ciscoasa# show version

Cisco Adaptive Security Appliance Software Version 9.5(2)2
Device Manager Version 7.1(1)52

Compiled on Tue 22-Dec-15 10:06 PST by builders
System image file is "disk0:/asa952-2-smp-k8.bin"
Config file at boot was "startup-config"

ciscoasa up 12 secs

Hardware:   ASA5515, 8192 MB RAM, CPU Clarkdale 3059 MHz, 1 CPU (4 cores)
            ASA: 3598 MB RAM, 1 CPU (1 core)
Internal ATA Compact Flash, 8192MB
BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB

Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
                             Boot microcode        : CNPx-MC-BOOT-2.00
                             SSL/IKE microcode     : CNPx-MC-SSL-SB-PLUS-0005
                             IPSec microcode       : CNPx-MC-IPSEC-MAIN-0026
                             Number of accelerators: 1

 0: Int: Internal-Data0/0    : address is b0fa.eb97.72c8, irq 11
 1: Ext: GigabitEthernet0/0  : address is b0fa.eb97.72cc, irq 10
 2: Ext: GigabitEthernet0/1  : address is b0fa.eb97.72c9, irq 10
 3: Ext: GigabitEthernet0/2  : address is b0fa.eb97.72cd, irq 5
 4: Ext: GigabitEthernet0/3  : address is b0fa.eb97.72ca, irq 5
 5: Ext: GigabitEthernet0/4  : address is b0fa.eb97.72ce, irq 10
 6: Ext: GigabitEthernet0/5  : address is b0fa.eb97.72cb, irq 10
 7: Int: Internal-Data0/1    : address is 0000.0001.0002, irq 0
 8: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 0
 9: Int: Internal-Data0/2    : address is 0000.0001.0003, irq 0
10: Ext: Management0/0       : address is b0fa.eb97.72c8, irq 0

Licensed features for this platform:
Maximum Physical Interfaces       : Unlimited      perpetual
Maximum VLANs                     : 100            perpetual
Inside Hosts                      : Unlimited      perpetual
Failover                          : Active/Active  perpetual
Encryption-DES                    : Enabled        perpetual
Encryption-3DES-AES               : Enabled        perpetual
Security Contexts                 : 2              perpetual
Carrier                           : Disabled       perpetual
AnyConnect Premium Peers          : 2              perpetual
AnyConnect Essentials             : Disabled       perpetual
Other VPN Peers                   : 250            perpetual
Total VPN Peers                   : 250            perpetual
AnyConnect for Mobile             : Disabled       perpetual
AnyConnect for Cisco VPN Phone    : Disabled       perpetual
Advanced Endpoint Assessment      : Disabled       perpetual
Shared License                    : Disabled       perpetual
Total UC Proxy Sessions           : 2              perpetual
Botnet Traffic Filter             : Disabled       perpetual
IPS Module                        : Disabled       perpetual
Cluster                           : Enabled        perpetual
Cluster Members                   : 2              perpetual

This platform has an ASA 5515 Security Plus license.

Serial Number: FCH1704JABC
Running Permanent Activation Key: 0x022ceb6a 0x98a0f168 0x0160d178 0xe22c1123 0xc213d456
Configuration register is 0x1

Image type          : Release
Key version         : A

Configuration has not been modified since last system restart.

ciscoasa# show module

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
   0 ASA 5515-X with SW, 6 GE Data, 1 GE Mgmt, AC ASA5515            FCH1704JABC
 ips Unknown                                      N/A                FCH1704JABC
cxsc Unknown                                      N/A                FCH1704JABC
 sfr Unknown                                      N/A                FCH1704JABC

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
   0 b0fa.eb97.72c8 to b0fa.eb97.72cf  1.0          2.1(9)8      9.5(2)2    // NEED ROMMON 1.1.8 OR ABOVE TO CONVERT ASA TO FTD
 ips b0fa.eb97.72c6 to b0fa.eb97.72c6  N/A          N/A         
cxsc b0fa.eb97.72c6 to b0fa.eb97.72c6  N/A          N/A         
 sfr b0fa.eb97.72c6 to b0fa.eb97.72c6  N/A          N/A         

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------
 ips Unknown                        No Image Present Not Applicable
cxsc Unknown                        No Image Present Not Applicable
 sfr Unknown                        No Image Present Not Applicable

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   0 Up Sys             Not Applicable       
 ips Unresponsive       Not Applicable       
cxsc Unresponsive       Not Applicable       
 sfr Unresponsive       Not Applicable       

Mod  License Name   License Status  Time Remaining
---- -------------- --------------- ---------------
 ips IPS Module     Disabled        perpetual    


I had inserted an SSD module on the ASA to store the FTD boot image and package file (OS).

ciscoasa# show inventory
Name: "Chassis", DESCR: "ASA 5515-X with SW, 6 GE Data, 1 GE Mgmt, AC"
PID: ASA5515           , VID: V01     , SN: FGL1707ABC

Name: "Storage Device 1", DESCR: "Micron 128 GB SSD MLC, Model Number: C400-MTFDDAC128MAM"
PID: N/A               , VID: N/A     , SN: MSA18230XYZ