Incomplete Packet Tracer - Configuring a Firewall in an Industrial Network

Addressing Table

Zone

IP Network Address

Subnet Mask

Enterprise Zone

10.1.200.0

255.255.255.0

Industrial Zone

10.1.100.0

255.255.255.0

Cell Zone 1

10.1.1.0

255.255.255.0

Cell Zone 2

10.1.2.0

255.255.255.0

Cell Zone 3

10.1.3.0

255.255.255.0

Objectives

In this lab, you will complete the following objectives:

  • Part 1: Configure a Firewall to Restrict Traffic
  • Part 2: Configure a VLAN to Segment Traffic
  • Part 3: Test and Verify Connectivity to New Cell Zone

Background / Scenario

You are the network administrator for an automated industrial plant that manufactures precision components. The plant uses a mix of industrial protocols for communication between its different operational zones, which include cell zones, the Industrial Zone, and the Enterprise Zone. The network in the plant is segmented to ensure security and performance, with a Cisco ISA industrial firewall in each cell zone positioned between the cell zone networks (where Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), and the Industrial Zone (where Supervisory Control and Data Acquisition (SCADA) systems reside). In addition, a firewall in the IDMZ segments the Industrial Zone from the Enterprise Zone.

The plant has just expanded and added a separate cell zone, Cell Zone 3, for the rubber rolling process. This cell zone will need to be protected with a firewall configurated like the Cell Zone 1 and 2 firewalls.

Your task is to complete the configuration of the new ISA3000 firewall in Cell Zone 3 and the firewall in the IDMZ. You will allow specific traffic while ensuring that only permitted protocols can traverse the firewall, which will protect both the cell and industrial zones from unauthorized access.

Instructions

Part 1: Configure a Firewall to Restrict Traffic

Cell Zones 1 and 2 are already configured. Your task is to configure the firewall for Cell Zone 3.

Step 1: Review existing Cell Zone 1 firewall configuration.

  1. Enter the Cell Zone 1 – Mixing Chamber cluster. Navigate to CellZone1FW. In the privileged EXEC mode, issue the show run command and begin output at the interface configuration. Press <enter> when prompted for a password.
  2. CellZone1FW# show run | begin interface
    interface GigabitEthernet1/1
     description connection to industrial zone
     nameif outside1
     security-level 0
     ip address 10.1.101.2 255.255.255.252
    !
    interface GigabitEthernet1/2
     description connection to cell zone
     nameif inside1
     security-level 100
     ip address 10.1.1.1 255.255.255.0
  3. Review the configuration.
  4. Note that interfaces are designated as inside1 and outside1.

    The Inside interface is typically connected to the trusted, internal network, such as a Cell Zone. It has a higher security level (commonly set to 100 in Cisco devices), meaning that traffic originating from this inside interface is considered more trusted. Traffic from the inside interface to the outside interface is usually allowed by default (though this can be restricted with policies) because it is moving from a trusted to an untrusted area.

    The Outside interface is typically connected to a less trusted network like the Industrial or Enterprise Zone. It has a lower security level (commonly set to 0), indicating that traffic from this interface is considered untrusted. Traffic from the outside to the inside is not allowed by default, and firewall rules or policies must be created to explicitly permit it.

  5. Repeat the steps above to review the configuration on the firewall in Cell Zone 2.

Step 2: Configure interfaces on the Cell Zone 3 firewall.

  1. Designate the GigabitEthernet1/1 as the outside interface that is connected to the Industrial Zone. Add an interface description to aid in documentation and troubleshooting. Set the security level of this interface to 0. Then add the IP address and enable the interface as needed.
  2. CellZone3FW# config terminal
    CellZone3FW(config)# interface GigabitEthernet1/1
    CellZone3FW(config-if)# nameif outside
    CellZone3FW(config-if)# description connected to industrial zone
    CellZone3FW(config-if)# security-level 0
    CellZone3FW(config-if)# ip address 10.1.103.2 255.255.255.252
    CellZone3FW(config-if)# no shutdown
  3. Repeat the process with interface GigabitEthernet1/2, which is the inside interface. Use the following information:
    • Interface name: inside
    • Description: connected to the cell zone
    • Security level: 100
    • IP address: 10.1.3.1
    • Subnet mask: 255.255.255.0
    Be sure to activate the interface as needed.

Step 3: Configure static routes on Cell Zone 3 firewall.

The firewall in Cell Zone 3 will need to know how to send traffic to the other networks. This will be done through static routes.
The syntax of a static route is route <interface> <destination network> <subnet mask> <next hop>
  1. Add a static route to the Industrial Zone network 10.1.100.0.
  2. CellZone3FW(config)# route outside 10.1.100.0 255.255.255.0 10.1.103.1
  3. Add a static route to the Enterprise Zone network 10.1.200.0.
  4. CellZone3FW(config)# route outside 10.1.200.0 255.255.255.0 10.1.103.1
  5. Add a static route to the Cell Zone 1 network 10.1.1.0.
  6. CellZone3FW(config)# route outside 10.1.1.0 255.255.255.0 10.1.103.1
  7. Add a static route to the Cell Zone 2 network 10.1.2.0.
  8. CellZone3FW(config)# route outside 10.1.2.0 255.255.255.0 10.1.103.1

Step 4: Configure access lists to control the traffic allowed into Cell Zone 3 from the Industrial Zone.

Cisco extended access control lists (ACLs) are a powerful feature used to control network traffic by specifying which packets are permitted or denied based on a variety of criteria. They consist of at least one access-control entry (ACE) which specifies an action (permit/deny) to apply to traffic the meets the criteria specified.

There are several types of ACLs. In this lab you will use extended ACLs. Extended ACLs provide granular control by allowing filtering based on the following parameters:

  • Source and Destination IP Addresses: using host, network, and subnet addresses with masks to identify which hosts the access-list statement applies to.
  • Protocol Types: IP, ICMP, TCP, UDP, etc.
  • Port Numbers: TCP and UDP port numbers identify which specific protocols are subject to the list condition.

There also specific rules concerning the application of access lists to interfaces. Access lists are applied in either an inboard (in) or an outbound (out) direction on an interface.

  • Inbound (in): Applies the ACL to traffic entering the interface. This is often used to filter traffic before it is processed by the device.
  • Outbound (out): Applies the ACL to traffic leaving the interface. This is used to control traffic after it has been processed and routed.
  • Note that you can apply an ACL in only one direction per interface at a time, meaning one ACL for inbound traffic and one for outbound traffic.

In addition, you can only apply one IP ACL per direction (inbound or outbound) per protocol (IPv4 or IPv6) on an interface. For example:

  • IPv4: Only one ACL for inbound IPv4 traffic and one ACL for outbound IPv4 traffic.
  • IPv6: Only one ACL for inbound IPv6 traffic and one ACL for outbound IPv6 traffic.
  • If you attempt to apply multiple ACLs in the same direction for the same protocol, the most recent ACL will overwrite the previous one.

This is an example of an ACE from an ACL called outside1_access_in. All ACEs with the same name make up a single ACL.

access-list outside1_access_in permit tcp 10.1.100.0 255.255.255.0 any eq 502

This ACE can be interpreted as follows: In the extended access-list named outside1_access_in, permit TCP packets using the Modbus/TCP protocol (equals TCP port 502) from the 10.1.100.0 network with subnet mask 255.255.255.0 to any host. The syntax of an extended ACL is explained in the table below.

Parameter

Explanation

access-list

All access-control entries begin with this command.

outside1_access_in

This is the name of the ACL that the ACE belongs to.

permit

The action to be executed on the packets that match the list criteria.

tcp

The protocol that packets must match.

10.1.100.0

The source of the traffic, either a network, subnet, or host address.

255.255.255.0

The subnet mask of the source traffic.

any

The destination that the packets are destined for. In this case the destination can be any host or hosts.

eq

An operator that is used to evaluate the port number. In this case it is the for packets with traffic that equals the port number.

502

The TCP port number of the traffic.

Later, this ACL will be associated with a firewall interface for packets that either leave or enter the interface.

When allowing traffic between two cell zones in an IACS network, the type of traffic allowed should be highly controlled based on the specific functions that need to be performed between the Cell Zones. Because each cell zone contains critical industrial control devices like PLCs, HMIs, and other OT systems, it is crucial to allow only the necessary communication for operational and safety purposes, while blocking any unnecessary or potentially harmful traffic.

Refer to the table below for information about the various protocols to be permitted.

Traffic Type

Protocol / Port

Purpose

Modbus / TCP

TCP 502

For communication between PLCs or controllers.

EtherNet / IP

UDP / TCP 2222, 44818

For communication between Rockwell devices.

PROFINET

UDP 34964, 34962

For Siemens or PROFINET-compatible devices.

HTTPS

TCP 443

Secure web-based access to device management consoles.

SSH

TCP 22

For secure remote management of devices such as switches, PLCs, or firewalls in the cell zone.

SNMPv3

UDP 161

For secure monitoring and management of network devices in the cell zone.

Syslog

UDP 515

For sending logs from devices in the Industrial Zone to a logging server in the Enterprise Zone. Port 515 is used for TLS-encrypted Syslog communication.

Note: To minimize the number of ACEs configured for this activity, you will only configure ACEs that can be tested in this activity.
You will configure ACEs on CellZone3FW to only allow Engineering Workstation (10.1.100.2) from Industrial Zone, Enterprise Zone, and the other specific cell zones to access the devices in Cell Zone 3.
  1. Configure an ACE to allow HTTPS. HTTPS will be allowed from the Engineering Workstation (10.1.100.2) in the Industrial Zone, Enterprise Zone, and the other cell zones.
  2. Note: In the CLI, use the up-arrow key to recall the last entered command. You can then edit the previous command to save time.
    CellZone3FW(config)# access-list outside_access_in extended permit tcp host 10.1.100.2 any eq 443
    CellZone3FW(config)# access-list outside_access_in extended permit tcp 10.1.200.0 255.255.255.0 any eq 443
    CellZone3FW(config)# access-list outside_access_in extended permit tcp 10.1.1.0 255.255.255.0 any eq 443
    CellZone3FW(config)# access-list outside_access_in extended permit tcp 10.1.2.0 255.255.255.0 any eq 443
  3. Configure an ACE to allow SSH (TCP 22). SSH will be allowed from the Engineering Workstation in the Industrial Zone and the other cell zones.
  4. CellZone3FW(config)# access-list outside_access_in extended permit tcp host 10.1.100.2 any eq 22
    CellZone3FW(config)# access-list outside_access_in extended permit tcp 10.1.1.0 255.255.255.0 any eq 22
    CellZone3FW(config)# access-list outside_access_in extended permit tcp 10.1.2.0 255.255.255.0 any eq 22
  5. Configure an ACE to allow ICMP traffic from the Engineering Workstation in the Industrial Zone. Specify the ICMP protocol and refer to the IP address of the Engineering Workstation host as the source of the ICMP echo request.
  6. CellZone3FW(config)# access-list outside_access_in extended permit icmp host 10.1.100.2 any
  7. Configure an ACE to deny all other traffic that is not explicitly permitted by the statements above.
  8. CellZone3FW(config)# access-list outside_access_in extended deny ip any any

Step 5: Apply the ACL to a firewall interface.

The access lists should be applied to the GigabitEthernet 1/1 interface, which is connected to the Industrial Zone, in an in-bound direction. This will permit or deny traffic as it enters the firewall interface.
CellZone3FW(config)# access-group outside_access_in in interface outside
CellZone3FW(config)# end

Step 6: Configure an ACL for the return traffic from Cell Zone 3 to the Industrial Zone.

In this step, you will configure ACEs for the return traffic from the cell zone to the Industrial Zone on the inside interface. You will use the established option to specify traffic that is responses to TCP sessions that were started in Cell Zone 3.
  1. Allow return traffic for HTTPS (TCP 443).
  2. CellZone3FW(config)# access-list inside_access_in extended permit tcp any eq 443 any
  3. Allow return traffic for SSH (TCP 22).
  4. CellZone3FW(config)# access-list inside_access_in extended permit tcp any eq 22 any
  5. Allow return ICMP echo responses for pings from the Engineer Workstation in the Industrial Zone.
  6. CellZone3FW(config)# access-list inside_access_in extended permit icmp any any
  7. Deny all other traffic.
  8. CellZone3FW(config)# access-list inside_access_in extended deny ip any any

Step 7: Apply the ACL to the firewall interface.

The access lists should be applied to the GigabitEthernet 1/1 interface that is connected to the Industrial Zone in an in-bound direction. This will permit or deny traffic as it enters the interface.
CellZone3FW(config)# access-group inside_access_in in interface inside
CellZone3FW(config)# end
Note: For a more comprehensive ACEs that include other TCP ports, enter the show access-list or show run commands on CellZone1FW and CellZone2FW.

Step 8: Verify the configurations.

  1. You can view the ACE configurations using the show commands.
  2. CellZone3FW# show access-list
    <output omitted>
    access-list outside_access_in; 9 elements; name hash: 0xc64b0dc2
    access-list outside_access_in line 1 extended permit tcp host 10.1.100.2 any eq 443(hitcnt=0) 0xc56250e7
    access-list outside_access_in line 2 extended permit tcp 10.1.200.0 255.255.255.0 any eq 443(hitcnt=0) 0x51759d6c
    access-list outside_access_in line 3 extended permit tcp 10.1.1.0 255.255.255.0 any eq 443(hitcnt=0) 0xdbe10d0c
    access-list outside_access_in line 4 extended permit tcp 10.1.2.0 255.255.255.0 any eq 443(hitcnt=0) 0x998a7829
    access-list outside_access_in line 5 extended permit tcp host 10.1.100.2 any eq 22(hitcnt=0) 0xe1c7a146
    access-list outside_access_in line 6 extended permit tcp 10.1.1.0 255.255.255.0 any eq 22(hitcnt=0) 0x1a60e473
    access-list outside_access_in line 7 extended permit tcp 10.1.2.0 255.255.255.0 any eq 22(hitcnt=0) 0xae9688d0
    access-list outside_access_in line 8 extended permit icmp host 10.1.100.2 any(hitcnt=0) 0x2ea2d704
    access-list outside_access_in line 9 extended deny ip any any(hitcnt=0) 0x0d85a86e
    access-list inside_access_in; 4 elements; name hash: 0xce394db0
    access-list inside_access_in line 1 extended permit tcp any eq 443 any(hitcnt=0) 0xa698a934
    access-list inside_access_in line 2 extended permit tcp any eq 22 any(hitcnt=0) 0x66539acb
    access-list inside_access_in line 3 extended permit icmp any any(hitcnt=0) 0x00074960
    access-list inside_access_in line 4 extended deny ip any any(hitcnt=0) 0x86ad2977
  3. Leave the CellZone3FW window open for the next step. As you test the access list in the next step, enter show access-list command to verify if the traffic is denied or permitted by the ACE as indicated by the hitcnt.

Part 2: Configure VLANs to Segment the Network

The Industrial Zone switch, Industrial_SW1, is already configured with connections to Cell Zones 1 and 2. You will need to configure the switch to connect to the newly added Cell Zone 3.

VLANs for Cell Z ones 1 and 2 are already configured. Your task is to configure the VLAN for Cell Zone 3.

Step 1: Review existing configuration on Industrial_SW1.

  1. Exit the Cell Zone 3 – Rolling Mill cluster as necessary.
  2. Enter the Industrial Zone cluster.
  3. Navigate to the Industrial_SW1 switch. Issue the show run command and begin output at the interface configuration section.
  4. Note the VLAN interfaces for VLAN 10 and 20. These connect to cell zones 10 and 20 respectively. You will create on for cell zone 3 in the next step.

    Industrial_SW1# show run | begin 1/3
    interface GigabitEthernet1/3
     description connected to Cell Zone 1
     switchport access vlan 10
     switchport mode access
     spanning-tree portfast
    !
    interface GigabitEthernet1/4
     description connected to Cell Zone 2
     switchport access vlan 20
     switchport mode access
     spanning-tree portfast
    <output omitted>
    interface GigabitEthernet1/6
     description connection to IDMZ
     no switchport
     ip address 10.1.0.6 255.255.255.252
     duplex auto
     speed auto
    !
    interface GigabitEthernet1/7
     description connection to industrial workstation
     switchport access vlan 100
     switchport mode access
     spanning-tree portfast
     duplex full
    !
    interface GigabitEthernet1/8
     description connection to MRP Server
     switchport access vlan 100
     switchport mode access
     spanning-tree portfast
    !
    interface GigabitEthernet1/9
     description connection to SCADA Server
     switchport access vlan 100
     switchport mode access
     spanning-tree portfast
    <output omitted>
    interface Vlan10
     description Cell Zone 1 Interface
     mac-address 0002.17d5.c901
     ip address 10.1.101.1 255.255.255.252
    !
    interface Vlan20
     description Cell Zone 2 Interface
     mac-address 0002.17d5.c902
     ip address 10.1.102.1 255.255.255.252
    !
    interface Vlan100
     mac-address 0002.17d5.c904
     ip address 10.1.100.1 255.255.255.0

    In the output, note that interfaces GigabitEthernet1/3 and GigabitEthernet1/4 are connected to cell zones 1 and 2 respectively. Also note the VLANs that each interface is assigned to and the IP addresses that are assigned to each of the VLAN interfaces.

    Because Cell Zone 3 was just added to the plant floor, the interface and VLAN for this new cell zone are not yet added to the switch. You will add them in the next steps.

Step 2: Configuration Industrial_SW1 for connectivity to Cell Zone 3.

First, you will create the VLAN for Cell Zone 3 (VLAN30). You will then configure the interface that connects to Cell Zone 3 (GigabitEthernet 1/5) as a member of VLAN 30. Finally, you will configure the switched virtual interface (SVI) of VLAN 30 with an IP address so that packets can be routed to it from other VLANs and networks. (An SVI is a logical Layer 3 interface configured on a switch, allowing it to route traffic between VLANs)
  1. Create VLAN 30.
  2. You will assign VLAN 30 to Cell Zone 3. This provides isolates Cell Zone 3 traffic from Cell Zone 1 and Cell Zone 2.
    Industrial_SW1# configure terminal
    Industrial_SW1(config)# vlan 30
    Industrial_SW1(config-vlan)# name Cell_Zone3_VLAN
  3. Issue the following commands on G1/5 to put the interface into VLAN 30.
  4. Industrial_SW1(config)# interface GigabitEthernet1/5
    Industrial_SW1(config-if)# description connected to Cell Zone 3
    Industrial_SW1(config-if)# switchport access vlan 30
    Industrial_SW1(config-if)# switchport mode access
  5. Configure VLAN 30 with a description and an IP address.
  6. Industrial_SW1(config-if)# interface Vlan 30
    Industrial_SW1(config-if)# description Cell Zone 3 Interface
    Industrial_SW1(config-if)# ip address 10.1.103.1 255.255.255.252
    Industrial_SW1(config-if)# exit
  7. Issue the show vlan and show running-config commands to verify your configuration.

Part 3: Test and Verify Connectivity to Cell Zone

Step 1: Verify access to Cell Zone 3 devices from the Industrial Zone.

In this step, you will test access to the devices in Cell Zone 3 over ICMP by pinging from the Engineering Workstation in the Industrial Zone to the Cell Zone 3 Engineering Workstation and PLC. Permitting ICMP (Internet Control Message Protocol) from the Industrial Zone to the cell zones in an Industrial Automation and Control System (IACS) environment offers several benefits, especially for network monitoring, diagnostics, and ensuring operational stability.
  1. Ping the workstation in Cell Zone 3 from the Industrial Zone Engineering Workstation. The ping should be successful because ICMP packets from the Industrial Zone workstation were permitted through the Cell Zone 3 firewall.
  2. C:/> ping 10.1.3.10
    
    Pinging 10.1.3.10 with 32 bytes of data:
    
    Reply from 10.1.3.10: bytes=32 time<1ms TTL=126
    Reply from 10.1.3.10: bytes=32 time<1ms TTL=126
    Reply from 10.1.3.10: bytes=32 time<1ms TTL=126
    Reply from 10.1.3.10: bytes=32 time<1ms TTL=126
    The ping to the Cell3_WS should be successful.
  3. Now ping Cell3_PLC at 10.1.3.11
  4. C:/> ping 10.1.3.11
    
    Pinging 10.1.3.11 with 32 bytes of data:
    
    Reply from 10.1.3.11: bytes=32 time<1ms TTL=126
    Reply from 10.1.3.11: bytes=32 time<1ms TTL=126
    Reply from 10.1.3.11: bytes=32 time<1ms TTL=126
    Reply from 10.1.3.11: bytes=32 time<1ms TTL=126
    The ping to Cell3_PLC should be successful.
  5. Now ping Cell3_SSHServer in Cell Zone 3 at 10.1.3.12 and the ping should be successful.
  6. To test SSH remote access, use the username admin and password cisco to connect to the Cell3_SSHServer. Note: The option -l is L for login_name, not the number 1.
  7. C:/> ssh -l admin 10.1.3.12
    
    Password: 
    
    
    
    Cell3_SSHServer>
    The ping and SSH access to the Cell3_SSHServer should be successful.
  8. Ping Cell3_WebServer (10.1.3.254) from Engineering Workstation. It should successful.
  9. With a successful ping from Engineering Workstation, open a web browser and attempt to open the web page at 10.1.3.254 using HTTP and HTTPS protocols.
Were both protocols successful? Explain.
Answer Area
The use of the protocol HTTPS (TCP port 443) was successful. However, HTTP (TCP port 80) was denied by the firewall.

Step 2: Test access to Cell Zone 3 devices from a Rogue device.

Recall that the firewall configurations you created on the ISA 3000 firewall in Cell Zone 3 only allows ICMP packets from the industrial zone Engineering Workstation (IP address 10.1.100.2). A Rogue Device in the Industrial Zone should not be able to access devices in Cell Zone 3. Test this by sending a ping to the Cell Zone 3 Workstation and PLC.
  1. Attempt to ping the Cell3_WS in Cell Zone 3 from the Rogue Device in the Industrial Zone.
  2. C:/> ping 10.1.3.10
    
    Pinging 10.1.3.10 with 32 bytes of data:
    
    Request timed out.
    Request timed out.
    Request timed out.
    Request timed out.
    
    Ping statistics for 10.1.3.10:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss)
    The ping to the Cell3_WS workstation should fail.
  3. Now ping the Cell3_PLC in Cell Zone 3.
  4. C:/> ping 10.1.3.11
    
    Pinging 10.1.3.10 with 32 bytes of data:
    
    Request timed out.
    Request timed out.
    Request timed out.
    Request timed out.
    
    Ping statistics for 10.1.3.11:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss)
  5. Ping the Cell3_SSHServer and Cell3_WebServer in Cell Zone 3 from the Rogue Device in the Industrial Zone.
Why did these pings fail?
Answer Area
Because ICMP echo request messages were only approved from the Industrial Zone workstation.

Command List with Comments

ISA CellZone3FW

!--------------------------------------------------
! Commands for completing Part 1, Step 2
! These commands can be copied and pasted into the Cell Zone 3 firewall
!--------------------------------------------------
configure terminal
interface g1/1
 nameif outside
 description connected to industrial zone
 security-level 0
 ip address 10.1.103.2 255.255.255.252
 no shutdown
interface g1/2
 nameif inside
 description connected to the cell zone
 security-level 100
 ip address 10.1.3.1 255.255.255.0
 no shutdown
!--------------------------------------------------
! Commands for completing Part 1, Step 3
! These commands can be copied and pasted into the Cell Zone 3 firewall
!--------------------------------------------------
route outside 10.1.100.0 255.255.255.0 10.1.103.1
route outside 10.1.200.0 255.255.255.0 10.1.103.1
route outside 10.1.1.0 255.255.255.0 10.1.103.1
route outside 10.1.2.0 255.255.255.0 10.1.103.1
!--------------------------------------------------
! Commands for completing Part 1, Steps 4 and 5
! These commands can be copied and pasted into the Cell Zone 3 firewall
!--------------------------------------------------
! allow HTTPS (TCP 443) from specified zones and Engineering Workstation
access-list outside_access_in extended permit tcp host 10.1.100.2 any eq 443
access-list outside_access_in extended permit tcp 10.1.200.0 255.255.255.0 any eq 443
access-list outside_access_in extended permit tcp 10.1.1.0 255.255.255.0 any eq 443
access-list outside_access_in extended permit tcp 10.1.2.0 255.255.255.0 any eq 443
! allow SSH (TCP 22) from specified zones and Engineering Workstation
access-list outside_access_in extended permit tcp host 10.1.100.2 any eq 22
access-list outside_access_in extended permit tcp 10.1.1.0 255.255.255.0 any eq 22
access-list outside_access_in extended permit tcp 10.1.2.0 255.255.255.0 any eq 22
! allow ICMP traffic from Engineering Workstation (host 10.1.100.2)
access-list outside_access_in extended permit icmp host 10.1.100.2 any
! deny all other traffic
access-list outside_access_in extended deny ip any any
! apply the access-list to the interface
access-group outside_access_in in interface outside
!---------------------------------------------------------
! Commands for completing Part 1, Steps 6 and 7
! These commands can be copied and pasted into the Cell Zone 3 firewall
!---------------------------------------------------------
! allow return traffic for HTTPS (TCP 443)
access-list inside_access_in extended permit tcp any eq 443 any 
! allow return traffic for SSH (TCP 22)
access-list inside_access_in extended permit tcp any eq 22 any 
! allow return ICMP echo responses for pings from the Engineer Workstation in the Industrial Zone
access-list inside_access_in extended permit icmp any any
! deny all other traffic
access-list inside_access_in extended deny ip any any
! apply the access-list to the interface
access-group inside_access_in in interface inside
exit

Switch Industrial_SW1

configure terminal
vlan 30
 name Cell_Zone3_VLAN
interface GigabitEthernet1/5
 description connected to Cell Zone 3
 switchport access vlan 30
 switchport mode access
interface Vlan 30
 description Cell Zone 3 Interface
 ip address 10.1.103.1 255.255.255.252
end

Complete IP Address Tables

Enterprise Zone

Device

Interface

IP Address

Subnet

Notes

Enterprise_SW1

G1/0/24

10.1.0.1

10.1.0.0 /30

Connection to IDMZ

G1/0/1

10.1.254.2

10.1.254.0 /24

Connection to Enterprise Rtr1

G1/0/2

10.1.200.2

10.1.200.0 /24

Connection to Historian Server

G1/0/3

10.1.200.3

10.1.200.0 /24

Connection to Logging Server

VLAN 200

10.1.200.1

10.1.200.0 /24

VLAN for Enterprise Zone Hosts

Enterprise_Rtr1

G0/0/0

192.168.1.1

192.168.1.0 /24

Connects to VPN Client

G0/0/1

10.1.254.1

10.1.254.0 /24

Connects to Enterprise_SW1

Historian

Fa0

10.1.200.2

10.1.200.0 /24

Logging Server

Fa0

10.1.200.3

10.1.200.0 /24

VPN Client

Fa

192.168.1.2

192.168.1.0 /24

IDMZ

Device

Interface

IP Address

Subnet

Notes

IDMZ_FW

G1/1

10.1.0.2

10.1.0.0 /30

Connection to Enterprise Zone

G1/2

10.1.0.5

10.1.0.4 /30

Connection to Industrial Zone

Industrial Zone

Device

Interface

IP Address

Subnet

Notes

Industrial_SW1

G1/3

N/A

Connection to Cell Zone 1 (VLAN10)

G1/4

N/A

Connection to Cell Zone 2 (VLAN20)

G1/5

N/A

Connection to Cell Zone 3 (VLAN30)

G1/6

10.1.0.6

10.1.0.4 /30

Connects to IDMZ

G1/7 (VLAN100)

N/A

Connects to Industrial Workstation

G1/8 (VLAN100)

N/A

Connects to MRP Server

G1/9 (VLAN100)

N/A

Connects to SCADA Server

G1/10 (VLAN100)

N/A

Connects to rogue device

VLAN10

10.1.101.1

10.1.101.0 /30

Connection to Cell Zone 1 (VLAN10)

VLAN20

10.1.102.1

10.1.102.0 /30

Connection to Cell Zone 2 (VLAN20)

VLAN30

10.1.103.1

10.1.103.0 /30

Connection to Cell Zone 3 (VLAN30)

VLAN100

10.1.100.1

10.1.100.0 /24

VLAN for Industrial Zone Hosts

Engineering Workstation

Fa0

10.1.100.2

10.1.100.0 /24

SCADA Server

Fa0

10.1.100.3

10.1.100.0 /24

MRP Server

Fa0

10.1.100.4

10.1.100.0 /24

Rogue Device

Fa0

10.1.100.5

10.1.100.0 /24

Cell Zones

Cell Zone 1 - Mixing Chamber

Device

Interface

IP Address

Subnet

Notes

CellZone1FW

G1/1

10.1.101.2

10.1.101.0/30

Connection to Industrial Zone

G1/1

10.1.1.1

10.1.1.0 /24

Internal Cell Zone 1 Network

Cell1_PLC

G0

10.1.1.11

10.1.1.0 /24

PLC

Cell1_WS

G0

10.1.1.10

10.1.1.0 /24

Work Station

Cell Zone 2 - Heating Chamber

Device

Interface

IP Address

Subnet

Notes

CellZone2FW

G1/1

10.1.102.2

10.1.102.0 /30

Connection to Industrial Zone

G1/2

10.1.2.1

10.1.2.0 /24

Internal Cell Zone 2 Network

Cell2_PLC

G0

10.1.2.11

10.1.2.0 /24

PLC

Cell2_WS

G0

10.1.2.10

10.1.2.0 /24

Work Station

Cell Zone 3 - Rolling Mill

Device

Interface

IP Address

Subnet

Notes

CellZone3FW

G1/1

10.1.103.2

10.1.103.0 /30

Connection to Industrial Zone

G1/2

10.1.3.1

10.1.3.0 /24

Internal Cell Zone 3 Network

Cell3_WebServer

G0

10.1.3.254

10.1.3.0 /24 Web Server

Cell3_SSHServer

VLAN 1

10.1.3.12

10.1.3.0 /24

Device allows SSH remote access

Cell3_PLC

G0

10.1.3.11

10.1.3.0 /24

PLC

Cell3_WS

G0

10.1.3.10

10.1.3.0 /24

Work Station


© 2024 - 2025 Cisco and/or its affiliates. All rights reserved. Cisco Public