Addressing Table
Objectives
In this lab, you will complete the following objectives:
- Part 1: Configure a Firewall to Restrict Traffic
- Part 2: Configure a VLAN to Segment Traffic
- Part 3: Test and Verify Connectivity to New Cell Zone
Background / Scenario
You are the network administrator for an automated industrial plant that manufactures precision components. The plant uses a mix of industrial protocols for communication between its different operational zones, which include cell zones, the Industrial Zone, and the Enterprise Zone. The network in the plant is segmented to ensure security and performance, with a Cisco ISA industrial firewall in each cell zone positioned between the cell zone networks (where Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), and the Industrial Zone (where Supervisory Control and Data Acquisition (SCADA) systems reside). In addition, a firewall in the IDMZ segments the Industrial Zone from the Enterprise Zone.
The plant has just expanded and added a separate cell zone, Cell Zone 3, for the rubber rolling process. This cell zone will need to be protected with a firewall configurated like the Cell Zone 1 and 2 firewalls.
Your task is to complete the configuration of the new ISA3000 firewall in Cell Zone 3 and the firewall in the IDMZ. You will allow specific traffic while ensuring that only permitted protocols can traverse the firewall, which will protect both the cell and industrial zones from unauthorized access.
Instructions
Part 1: Configure a Firewall to Restrict Traffic
Cell Zones 1 and 2 are already configured. Your task is to configure the firewall for Cell Zone 3.Step 1: Review existing Cell Zone 1 firewall configuration.
- Enter the Cell Zone 1 – Mixing Chamber cluster. Navigate to CellZone1FW. In the privileged EXEC mode, issue the show run command and begin output at the interface configuration. Press <enter> when prompted for a password.
- Review the configuration.
- Repeat the steps above to review the configuration on the firewall in Cell Zone 2.
CellZone1FW# show run | begin interface interface GigabitEthernet1/1 description connection to industrial zone nameif outside1 security-level 0 ip address 10.1.101.2 255.255.255.252 ! interface GigabitEthernet1/2 description connection to cell zone nameif inside1 security-level 100 ip address 10.1.1.1 255.255.255.0
Note that interfaces are designated as inside1 and outside1.
The Inside interface is typically connected to the trusted, internal network, such as a Cell Zone. It has a higher security level (commonly set to 100 in Cisco devices), meaning that traffic originating from this inside interface is considered more trusted. Traffic from the inside interface to the outside interface is usually allowed by default (though this can be restricted with policies) because it is moving from a trusted to an untrusted area.
The Outside interface is typically connected to a less trusted network like the Industrial or Enterprise Zone. It has a lower security level (commonly set to 0), indicating that traffic from this interface is considered untrusted. Traffic from the outside to the inside is not allowed by default, and firewall rules or policies must be created to explicitly permit it.
Step 2: Configure interfaces on the Cell Zone 3 firewall.
- Designate the GigabitEthernet1/1 as the outside interface that is connected to the Industrial Zone. Add an interface description to aid in documentation and troubleshooting. Set the security level of this interface to 0. Then add the IP address and enable the interface as needed.
- Repeat the process with interface GigabitEthernet1/2, which is the inside interface. Use the following information:
- Interface name: inside
- Description: connected to the cell zone
- Security level: 100
- IP address: 10.1.3.1
- Subnet mask: 255.255.255.0
CellZone3FW# config terminal CellZone3FW(config)# interface GigabitEthernet1/1 CellZone3FW(config-if)# nameif outside CellZone3FW(config-if)# description connected to industrial zone CellZone3FW(config-if)# security-level 0 CellZone3FW(config-if)# ip address 10.1.103.2 255.255.255.252 CellZone3FW(config-if)# no shutdown
Step 3: Configure static routes on Cell Zone 3 firewall.
The firewall in Cell Zone 3 will need to know how to send traffic to the other networks. This will be done through static routes.The syntax of a static route is route <interface> <destination network> <subnet mask> <next hop>
- Add a static route to the Industrial Zone network 10.1.100.0.
- Add a static route to the Enterprise Zone network 10.1.200.0.
- Add a static route to the Cell Zone 1 network 10.1.1.0.
- Add a static route to the Cell Zone 2 network 10.1.2.0.
CellZone3FW(config)# route outside 10.1.100.0 255.255.255.0 10.1.103.1
CellZone3FW(config)# route outside 10.1.200.0 255.255.255.0 10.1.103.1
CellZone3FW(config)# route outside 10.1.1.0 255.255.255.0 10.1.103.1
CellZone3FW(config)# route outside 10.1.2.0 255.255.255.0 10.1.103.1
Step 4: Configure access lists to control the traffic allowed into Cell Zone 3 from the Industrial Zone.
Cisco extended access control lists (ACLs) are a powerful feature used to control network traffic by specifying which packets are permitted or denied based on a variety of criteria. They consist of at least one access-control entry (ACE) which specifies an action (permit/deny) to apply to traffic the meets the criteria specified.
There are several types of ACLs. In this lab you will use extended ACLs. Extended ACLs provide granular control by allowing filtering based on the following parameters:
- Source and Destination IP Addresses: using host, network, and subnet addresses with masks to identify which hosts the access-list statement applies to.
- Protocol Types: IP, ICMP, TCP, UDP, etc.
- Port Numbers: TCP and UDP port numbers identify which specific protocols are subject to the list condition.
There also specific rules concerning the application of access lists to interfaces. Access lists are applied in either an inboard (in) or an outbound (out) direction on an interface.
- Inbound (in): Applies the ACL to traffic entering the interface. This is often used to filter traffic before it is processed by the device.
- Outbound (out): Applies the ACL to traffic leaving the interface. This is used to control traffic after it has been processed and routed.
- Note that you can apply an ACL in only one direction per interface at a time, meaning one ACL for inbound traffic and one for outbound traffic.
In addition, you can only apply one IP ACL per direction (inbound or outbound) per protocol (IPv4 or IPv6) on an interface. For example:
- IPv4: Only one ACL for inbound IPv4 traffic and one ACL for outbound IPv4 traffic.
- IPv6: Only one ACL for inbound IPv6 traffic and one ACL for outbound IPv6 traffic.
- If you attempt to apply multiple ACLs in the same direction for the same protocol, the most recent ACL will overwrite the previous one.
This is an example of an ACE from an ACL called outside1_access_in. All ACEs with the same name make up a single ACL.
access-list outside1_access_in permit tcp 10.1.100.0 255.255.255.0 any eq 502
This ACE can be interpreted as follows: In the extended access-list named outside1_access_in, permit TCP packets using the Modbus/TCP protocol (equals TCP port 502) from the 10.1.100.0 network with subnet mask 255.255.255.0 to any host. The syntax of an extended ACL is explained in the table below.
Later, this ACL will be associated with a firewall interface for packets that either leave or enter the interface.
When allowing traffic between two cell zones in an IACS network, the type of traffic allowed should be highly controlled based on the specific functions that need to be performed between the Cell Zones. Because each cell zone contains critical industrial control devices like PLCs, HMIs, and other OT systems, it is crucial to allow only the necessary communication for operational and safety purposes, while blocking any unnecessary or potentially harmful traffic.
Refer to the table below for information about the various protocols to be permitted.
You will configure ACEs on CellZone3FW to only allow Engineering Workstation (10.1.100.2) from Industrial Zone, Enterprise Zone, and the other specific cell zones to access the devices in Cell Zone 3.
- Configure an ACE to allow HTTPS. HTTPS will be allowed from the Engineering Workstation (10.1.100.2) in the Industrial Zone, Enterprise Zone, and the other cell zones. Note: In the CLI, use the up-arrow key to recall the last entered command. You can then edit the previous command to save time.
- Configure an ACE to allow SSH (TCP 22). SSH will be allowed from the Engineering Workstation in the Industrial Zone and the other cell zones.
- Configure an ACE to allow ICMP traffic from the Engineering Workstation in the Industrial Zone. Specify the ICMP protocol and refer to the IP address of the Engineering Workstation host as the source of the ICMP echo request.
- Configure an ACE to deny all other traffic that is not explicitly permitted by the statements above.
CellZone3FW(config)# access-list outside_access_in extended permit tcp host 10.1.100.2 any eq 443 CellZone3FW(config)# access-list outside_access_in extended permit tcp 10.1.200.0 255.255.255.0 any eq 443 CellZone3FW(config)# access-list outside_access_in extended permit tcp 10.1.1.0 255.255.255.0 any eq 443 CellZone3FW(config)# access-list outside_access_in extended permit tcp 10.1.2.0 255.255.255.0 any eq 443
CellZone3FW(config)# access-list outside_access_in extended permit tcp host 10.1.100.2 any eq 22 CellZone3FW(config)# access-list outside_access_in extended permit tcp 10.1.1.0 255.255.255.0 any eq 22 CellZone3FW(config)# access-list outside_access_in extended permit tcp 10.1.2.0 255.255.255.0 any eq 22
CellZone3FW(config)# access-list outside_access_in extended permit icmp host 10.1.100.2 any
CellZone3FW(config)# access-list outside_access_in extended deny ip any any
Step 5: Apply the ACL to a firewall interface.
The access lists should be applied to the GigabitEthernet 1/1 interface, which is connected to the Industrial Zone, in an in-bound direction. This will permit or deny traffic as it enters the firewall interface.CellZone3FW(config)# access-group outside_access_in in interface outside CellZone3FW(config)# end
Step 6: Configure an ACL for the return traffic from Cell Zone 3 to the Industrial Zone.
In this step, you will configure ACEs for the return traffic from the cell zone to the Industrial Zone on the inside interface. You will use the established option to specify traffic that is responses to TCP sessions that were started in Cell Zone 3.- Allow return traffic for HTTPS (TCP 443).
- Allow return traffic for SSH (TCP 22).
- Allow return ICMP echo responses for pings from the Engineer Workstation in the Industrial Zone.
- Deny all other traffic.
CellZone3FW(config)# access-list inside_access_in extended permit tcp any eq 443 any
CellZone3FW(config)# access-list inside_access_in extended permit tcp any eq 22 any
CellZone3FW(config)# access-list inside_access_in extended permit icmp any any
CellZone3FW(config)# access-list inside_access_in extended deny ip any any
Step 7: Apply the ACL to the firewall interface.
The access lists should be applied to the GigabitEthernet 1/1 interface that is connected to the Industrial Zone in an in-bound direction. This will permit or deny traffic as it enters the interface.Note: For a more comprehensive ACEs that include other TCP ports, enter the show access-list or show run commands on CellZone1FW and CellZone2FW.CellZone3FW(config)# access-group inside_access_in in interface inside CellZone3FW(config)# end
Step 8: Verify the configurations.
- You can view the ACE configurations using the show commands.
- Leave the CellZone3FW window open for the next step. As you test the access list in the next step, enter show access-list command to verify if the traffic is denied or permitted by the ACE as indicated by the hitcnt.
CellZone3FW# show access-list <output omitted> access-list outside_access_in; 9 elements; name hash: 0xc64b0dc2 access-list outside_access_in line 1 extended permit tcp host 10.1.100.2 any eq 443(hitcnt=0) 0xc56250e7 access-list outside_access_in line 2 extended permit tcp 10.1.200.0 255.255.255.0 any eq 443(hitcnt=0) 0x51759d6c access-list outside_access_in line 3 extended permit tcp 10.1.1.0 255.255.255.0 any eq 443(hitcnt=0) 0xdbe10d0c access-list outside_access_in line 4 extended permit tcp 10.1.2.0 255.255.255.0 any eq 443(hitcnt=0) 0x998a7829 access-list outside_access_in line 5 extended permit tcp host 10.1.100.2 any eq 22(hitcnt=0) 0xe1c7a146 access-list outside_access_in line 6 extended permit tcp 10.1.1.0 255.255.255.0 any eq 22(hitcnt=0) 0x1a60e473 access-list outside_access_in line 7 extended permit tcp 10.1.2.0 255.255.255.0 any eq 22(hitcnt=0) 0xae9688d0 access-list outside_access_in line 8 extended permit icmp host 10.1.100.2 any(hitcnt=0) 0x2ea2d704 access-list outside_access_in line 9 extended deny ip any any(hitcnt=0) 0x0d85a86e access-list inside_access_in; 4 elements; name hash: 0xce394db0 access-list inside_access_in line 1 extended permit tcp any eq 443 any(hitcnt=0) 0xa698a934 access-list inside_access_in line 2 extended permit tcp any eq 22 any(hitcnt=0) 0x66539acb access-list inside_access_in line 3 extended permit icmp any any(hitcnt=0) 0x00074960 access-list inside_access_in line 4 extended deny ip any any(hitcnt=0) 0x86ad2977
Part 2: Configure VLANs to Segment the Network
The Industrial Zone switch, Industrial_SW1, is already configured with connections to Cell Zones 1 and 2. You will need to configure the switch to connect to the newly added Cell Zone 3.
VLANs for Cell Z ones 1 and 2 are already configured. Your task is to configure the VLAN for Cell Zone 3.
Step 1: Review existing configuration on Industrial_SW1.
- Exit the Cell Zone 3 – Rolling Mill cluster as necessary.
- Enter the Industrial Zone cluster.
- Navigate to the Industrial_SW1 switch. Issue the show run command and begin output at the interface configuration section.
Note the VLAN interfaces for VLAN 10 and 20. These connect to cell zones 10 and 20 respectively. You will create on for cell zone 3 in the next step.
Industrial_SW1# show run | begin 1/3 interface GigabitEthernet1/3 description connected to Cell Zone 1 switchport access vlan 10 switchport mode access spanning-tree portfast ! interface GigabitEthernet1/4 description connected to Cell Zone 2 switchport access vlan 20 switchport mode access spanning-tree portfast <output omitted> interface GigabitEthernet1/6 description connection to IDMZ no switchport ip address 10.1.0.6 255.255.255.252 duplex auto speed auto ! interface GigabitEthernet1/7 description connection to industrial workstation switchport access vlan 100 switchport mode access spanning-tree portfast duplex full ! interface GigabitEthernet1/8 description connection to MRP Server switchport access vlan 100 switchport mode access spanning-tree portfast ! interface GigabitEthernet1/9 description connection to SCADA Server switchport access vlan 100 switchport mode access spanning-tree portfast <output omitted> interface Vlan10 description Cell Zone 1 Interface mac-address 0002.17d5.c901 ip address 10.1.101.1 255.255.255.252 ! interface Vlan20 description Cell Zone 2 Interface mac-address 0002.17d5.c902 ip address 10.1.102.1 255.255.255.252 ! interface Vlan100 mac-address 0002.17d5.c904 ip address 10.1.100.1 255.255.255.0
In the output, note that interfaces GigabitEthernet1/3 and GigabitEthernet1/4 are connected to cell zones 1 and 2 respectively. Also note the VLANs that each interface is assigned to and the IP addresses that are assigned to each of the VLAN interfaces.
Because Cell Zone 3 was just added to the plant floor, the interface and VLAN for this new cell zone are not yet added to the switch. You will add them in the next steps.
Step 2: Configuration Industrial_SW1 for connectivity to Cell Zone 3.
First, you will create the VLAN for Cell Zone 3 (VLAN30). You will then configure the interface that connects to Cell Zone 3 (GigabitEthernet 1/5) as a member of VLAN 30. Finally, you will configure the switched virtual interface (SVI) of VLAN 30 with an IP address so that packets can be routed to it from other VLANs and networks. (An SVI is a logical Layer 3 interface configured on a switch, allowing it to route traffic between VLANs)- Create VLAN 30. You will assign VLAN 30 to Cell Zone 3. This provides isolates Cell Zone 3 traffic from Cell Zone 1 and Cell Zone 2.
- Issue the following commands on G1/5 to put the interface into VLAN 30.
- Configure VLAN 30 with a description and an IP address.
- Issue the show vlan and show running-config commands to verify your configuration.
Industrial_SW1# configure terminal Industrial_SW1(config)# vlan 30 Industrial_SW1(config-vlan)# name Cell_Zone3_VLAN
Industrial_SW1(config)# interface GigabitEthernet1/5 Industrial_SW1(config-if)# description connected to Cell Zone 3 Industrial_SW1(config-if)# switchport access vlan 30 Industrial_SW1(config-if)# switchport mode access
Industrial_SW1(config-if)# interface Vlan 30 Industrial_SW1(config-if)# description Cell Zone 3 Interface Industrial_SW1(config-if)# ip address 10.1.103.1 255.255.255.252 Industrial_SW1(config-if)# exit
Part 3: Test and Verify Connectivity to Cell Zone
Step 1: Verify access to Cell Zone 3 devices from the Industrial Zone.
In this step, you will test access to the devices in Cell Zone 3 over ICMP by pinging from the Engineering Workstation in the Industrial Zone to the Cell Zone 3 Engineering Workstation and PLC. Permitting ICMP (Internet Control Message Protocol) from the Industrial Zone to the cell zones in an Industrial Automation and Control System (IACS) environment offers several benefits, especially for network monitoring, diagnostics, and ensuring operational stability.- Ping the workstation in Cell Zone 3 from the Industrial Zone Engineering Workstation. The ping should be successful because ICMP packets from the Industrial Zone workstation were permitted through the Cell Zone 3 firewall.
- Now ping Cell3_PLC at 10.1.3.11
- Now ping Cell3_SSHServer in Cell Zone 3 at 10.1.3.12 and the ping should be successful.
- To test SSH remote access, use the username admin and password cisco to connect to the Cell3_SSHServer. Note: The option -l is L for login_name, not the number 1.
- Ping Cell3_WebServer (10.1.3.254) from Engineering Workstation. It should successful.
- With a successful ping from Engineering Workstation, open a web browser and attempt to open the web page at 10.1.3.254 using HTTP and HTTPS protocols.
C:/> ping 10.1.3.10 Pinging 10.1.3.10 with 32 bytes of data: Reply from 10.1.3.10: bytes=32 time<1ms TTL=126 Reply from 10.1.3.10: bytes=32 time<1ms TTL=126 Reply from 10.1.3.10: bytes=32 time<1ms TTL=126 Reply from 10.1.3.10: bytes=32 time<1ms TTL=126The ping to the Cell3_WS should be successful.
C:/> ping 10.1.3.11 Pinging 10.1.3.11 with 32 bytes of data: Reply from 10.1.3.11: bytes=32 time<1ms TTL=126 Reply from 10.1.3.11: bytes=32 time<1ms TTL=126 Reply from 10.1.3.11: bytes=32 time<1ms TTL=126 Reply from 10.1.3.11: bytes=32 time<1ms TTL=126The ping to Cell3_PLC should be successful.
C:/> ssh -l admin 10.1.3.12 Password: Cell3_SSHServer>The ping and SSH access to the Cell3_SSHServer should be successful.
Step 2: Test access to Cell Zone 3 devices from a Rogue device.
Recall that the firewall configurations you created on the ISA 3000 firewall in Cell Zone 3 only allows ICMP packets from the industrial zone Engineering Workstation (IP address 10.1.100.2). A Rogue Device in the Industrial Zone should not be able to access devices in Cell Zone 3. Test this by sending a ping to the Cell Zone 3 Workstation and PLC.- Attempt to ping the Cell3_WS in Cell Zone 3 from the Rogue Device in the Industrial Zone.
- Now ping the Cell3_PLC in Cell Zone 3.
- Ping the Cell3_SSHServer and Cell3_WebServer in Cell Zone 3 from the Rogue Device in the Industrial Zone.
C:/> ping 10.1.3.10 Pinging 10.1.3.10 with 32 bytes of data: Request timed out. Request timed out. Request timed out. Request timed out. Ping statistics for 10.1.3.10: Packets: Sent = 4, Received = 0, Lost = 4 (100% loss)The ping to the Cell3_WS workstation should fail.
C:/> ping 10.1.3.11 Pinging 10.1.3.10 with 32 bytes of data: Request timed out. Request timed out. Request timed out. Request timed out. Ping statistics for 10.1.3.11: Packets: Sent = 4, Received = 0, Lost = 4 (100% loss)
Command List with Comments
ISA CellZone3FW
!-------------------------------------------------- ! Commands for completing Part 1, Step 2 ! These commands can be copied and pasted into the Cell Zone 3 firewall !-------------------------------------------------- configure terminal interface g1/1 nameif outside description connected to industrial zone security-level 0 ip address 10.1.103.2 255.255.255.252 no shutdown interface g1/2 nameif inside description connected to the cell zone security-level 100 ip address 10.1.3.1 255.255.255.0 no shutdown !-------------------------------------------------- ! Commands for completing Part 1, Step 3 ! These commands can be copied and pasted into the Cell Zone 3 firewall !-------------------------------------------------- route outside 10.1.100.0 255.255.255.0 10.1.103.1 route outside 10.1.200.0 255.255.255.0 10.1.103.1 route outside 10.1.1.0 255.255.255.0 10.1.103.1 route outside 10.1.2.0 255.255.255.0 10.1.103.1 !-------------------------------------------------- ! Commands for completing Part 1, Steps 4 and 5 ! These commands can be copied and pasted into the Cell Zone 3 firewall !-------------------------------------------------- ! allow HTTPS (TCP 443) from specified zones and Engineering Workstation access-list outside_access_in extended permit tcp host 10.1.100.2 any eq 443 access-list outside_access_in extended permit tcp 10.1.200.0 255.255.255.0 any eq 443 access-list outside_access_in extended permit tcp 10.1.1.0 255.255.255.0 any eq 443 access-list outside_access_in extended permit tcp 10.1.2.0 255.255.255.0 any eq 443 ! allow SSH (TCP 22) from specified zones and Engineering Workstation access-list outside_access_in extended permit tcp host 10.1.100.2 any eq 22 access-list outside_access_in extended permit tcp 10.1.1.0 255.255.255.0 any eq 22 access-list outside_access_in extended permit tcp 10.1.2.0 255.255.255.0 any eq 22 ! allow ICMP traffic from Engineering Workstation (host 10.1.100.2) access-list outside_access_in extended permit icmp host 10.1.100.2 any ! deny all other traffic access-list outside_access_in extended deny ip any any ! apply the access-list to the interface access-group outside_access_in in interface outside !--------------------------------------------------------- ! Commands for completing Part 1, Steps 6 and 7 ! These commands can be copied and pasted into the Cell Zone 3 firewall !--------------------------------------------------------- ! allow return traffic for HTTPS (TCP 443) access-list inside_access_in extended permit tcp any eq 443 any ! allow return traffic for SSH (TCP 22) access-list inside_access_in extended permit tcp any eq 22 any ! allow return ICMP echo responses for pings from the Engineer Workstation in the Industrial Zone access-list inside_access_in extended permit icmp any any ! deny all other traffic access-list inside_access_in extended deny ip any any ! apply the access-list to the interface access-group inside_access_in in interface inside exit
Switch Industrial_SW1
configure terminal vlan 30 name Cell_Zone3_VLAN interface GigabitEthernet1/5 description connected to Cell Zone 3 switchport access vlan 30 switchport mode access interface Vlan 30 description Cell Zone 3 Interface ip address 10.1.103.1 255.255.255.252 end