11. ═α±≥≡εΘΩα ≡σαΩ÷ΦΦ ±Φ±≥σ∞√

┬ ²≥εΘ πδαΓσ ∩εΩαταφε, ΩαΩ φα±≥≡εΦ≥ⁿ αΓ≥ε∞α≥Φ≈σ±ΩΦσ ΣσΘ±≥ΓΦ  ±Φ±≥σ∞√ Σδ  τα≡αφσσ ε∩≡σΣσδσφφ√⌡ ±Φ≥≤α÷ΦΘ.

╫≥ε ≥αΩεσ ≡σαΩ÷Φ  ±Φ±≥σ∞√?

┬ ∞σµ±σ≥σΓε∞ ²Ω≡αφσ Aker ±≤∙σ±≥Γ≤σ≥ ∞σ⌡αφΦτ∞ , Ωε≥ε≡√Θ ∩ετΓεδ σ≥ ⌠ε≡∞Φ≡εΓα≥ⁿ αΓ≥ε∞α≥Φ≈σ±ΩΦσ ε≥Γσ≥√ Σδ  φσΩε≥ε≡√⌡ ±Φ≥≤α÷ΦΘ. └Γ≥ε∞α≥Φ≈σ±ΩΦσ ε≥Γσ≥√ φα±≥≡αΦΓα■≥±  αΣ∞ΦφΦ±≥≡α≥ε≡ε∞ Φτ φαßε≡α Γετ∞εµφ√⌡ ΣσΘ±≥ΓΦΘ, Ωε≥ε≡√σ ß≤Σ≤≥ Γ√∩εδφσφ√ Σδ  τα≡αφσσ ε∩Φ±αφφ√⌡ ±Φ≥≤α÷ΦΘ.

─δ  ≈σπε φ≤µφα ≡σαΩ÷Φ  ±Φ±≥σ∞√?

╤∞√±δ ≡σαΩ÷ΦΦ ±Φ±≥σ∞√ ταΩδ■≈ασ≥±  Γ ≥ε∞ ≈≥εß√ εßσ±∩σ≈Φ≥ⁿ ßεδσσ ≥σ±φεσ ΓταΦ∞εΣσΘ±≥ΓΦσ ∞σµΣ≤ ∞σµ±σ≥σΓ√∞ ²Ω≡αφε∞ Φ αΣ∞ΦφΦ±≥≡α≥ε≡ε∞. ┼σ Φ±∩εδⁿτεΓαφΦσ, φα∩≡Φ∞σ≡, Σσδασ≥ Γετ∞εµφ√∞ Γ√∩εδφσφΦσ ∩≡επ≡α∞∞√, Ωε≥ε≡α  Γ√τ√Γασ≥ αΣ∞ΦφΦ±≥≡α≥ε≡α, ΩεπΣα ∞σµ±σ≥σΓεΘ ²Ω≡αφ εßφα≡≤µΦΓασ≥ φα≈αΓ°≤■±  α≥αΩ≤. ▌≥ε ∩ετΓεδ σ≥ αΣ∞ΦφΦ±≥≡α≥ε≡≤ φσ∞σΣδσφφε ∩≡σΣ∩≡Φφ ≥ⁿ ²⌠⌠σΩ≥ΦΓφ√σ ΣσΘ±≥ΓΦ , Σαµσ σ±δΦ εφ Γ ≥ε≥ ∞ε∞σφ≥ φσ φαßδ■Σασ≥ τα ≡αßε≥εΘ ∞σµ±σ≥σΓεπε ²Ω≡αφα.

11.1 ╚±∩εδⁿτεΓαφΦσ π≡α⌠Φ≈σ±Ωεπε Φφ≥σ≡⌠σΘ±α

─δ  ∩εδ≤≈σφΦ  Σε±≥≤∩α Ω εΩφ≤ φα±≥≡εΘΩΦ ≡σαΩ÷ΦΦ ±Φ±≥σ∞√ φσεß⌡εΣΦ∞ε Γ√∩εδφΦ≥ⁿ ±δσΣ≤■∙Φσ ΣσΘ±≥ΓΦ :

╬Ωφε φα±≥≡εΘΩΦ ≡σαΩ÷ΦΦ

┼±δΦ ≤±≥αφεΓδσφα ²≥α ε∩÷Φ , ∩ε Γδ σ≥±  εΩφε, Ωε≥ε≡εσ ∩ετΓεδ σ≥ φα±≥≡αΦΓα≥ⁿ ΓΦΣ ≡σαΩ÷ΦΦ ±Φ±≥σ∞√. ─δ  ΩαµΣεπε ±εεß∙σφΦ  ±Φ±≥σ∞ ±ßε≡α ±≥α≥Φ±≥ΦΩΦ ΦδΦ ±εß√≥ΦΘ Φ Σδ  Γ±σ⌡ ∩αΩσ≥εΓ, φσ ≤ΣεΓδσ≥Γε≡ ■∙Φ⌡ φΦ εΣφε∞≤ Φτ ∩≡αΓΦδ, ∞εµφε ≤±≥αφεΓΦ≥ⁿ φσταΓΦ±Φ∞≤■ ≡σαΩ÷Φ■. ╬Ωφε Φ∞σσ≥ ±δσΣ≤■∙ΦΘ ⌠ε≡∞α≥:

─δ  Γ√ßε≡α ≥Φ∩α ≡σαΩ÷ΦΦ, Σδ  ≤Ωαταφφ√⌡ Γ εΩφσ ±εεß∙σφΦΘ, φαµ∞Φ≥σ δσΓεΘ ΩδαΓΦ°σΘ ∞√°Φ φα ε∩÷ΦΦ. ┼±δΦ ε∩÷Φ  ß≤Σσ≥ ≤±≥αφεΓδσφα, ≥ε ∩≡Φ ∩ε ΓδσφΦΦ ±εεß∙σφΦ  ∞σµ±σ≥σΓεΘ ²Ω≡αφ Γ√∩εδφΦ≥ ±εε≥Γσ≥±≥Γ≤■∙σσ ΣσΘ±≥ΓΦσ. ┬ετ∞εµφ√ ±δσΣ≤■∙Φσ ΣσΘ±≥ΓΦ :

╟φα≈σφΦ  Ωφε∩εΩ

╬Ωφε φα±≥≡εΘΩΦ ∩α≡α∞σ≥≡εΓ

╫≥εß√ ±Φ±≥σ∞α ∩≡Φ±≥≤∩Φδα Ω Γ√∩εδφσφΦ■ ΣσΘ±≥ΓΦΘ, φσεß⌡εΣΦ∞ε φα±≥≡εΦ≥ⁿ φσΩε≥ε≡√σ ∩α≡α∞σ≥≡√ (φα∩≡Φ∞σ≡, σ±δΦ ∞σµ±σ≥σΓεΘ ²Ω≡αφ ∩ε±√δασ≥ e-mail, φσεß⌡εΣΦ∞ε ε∩≡σΣσδΦ≥ⁿ e-mail αΣ≡σ±). ▌≥Φ ∩α≡α∞σ≥≡√ ∞εµφε ∞εΣΦ⌠Φ÷Φ≡εΓα≥ⁿ ≈σ≡στ εΩφε φα±≥≡εΘΩΦ ∩α≡α∞σ≥≡εΓ ≡σαΩ÷ΦΦ ±Φ±≥σ∞√.

╤εε≥Γσ≥±≥Γ≤■∙σσ εΩφε ε≥Ω≡εσ≥± , σ±δΦ φαµα≥ⁿ Ωφε∩Ω≤ Parameters Γ εΩφσ ±εεß∙σφΦΘ. ╬φε Φ∞σσ≥ ±δσΣ≤■∙ΦΘ ⌠ε≡∞α≥

╟φα≈σφΦ  ∩α≡α∞σ≥≡εΓ:

External Program: ▌≥ε≥ ∩α≡α∞σ≥≡ ε∩≡σΣσδ σ≥ Φ∞  Γ√∩εδφ σ∞εΘ ±Φ±≥σ∞εΘ ∩≡επ≡α∞∞√, ΩεπΣα ∩≡εΦτΓεΣΦ≥±  ΣσΘ±≥ΓΦσ ± ε∩÷ΦσΘ Program. ╤δσΣ≤σ≥ ΓΓσ±≥Φ ± ΩδαΓΦα≥≤≡√ ∩εδφεσ Φ∞  ∞α≡°≡≤≥α ∩≡επ≡α∞∞√. ═σεß⌡εΣΦ∞ε ≤≈σ±≥ⁿ , ≈≥ε ∩≡επ≡α∞∞α Φ Γ±σ Ωα≥αδεπΦ ∩ε ⌡εΣ≤ ∞α≡°≡≤≥α Σεδµφ√ Φ∞σ≥ⁿ ∩≡αΓε φα Γ√∩εδφσφΦσ Σδ  ∩εδⁿτεΓα≥σδ , ε≥ Φ∞σφΦ Ωε≥ε≡επε Γ√∩εδφ σ≥±  ∩≡επ≡α∞∞α (φα±≥≡εΘΩα ∩εδⁿτεΓα≥σδ  ∩≡εΓεΣΦ≥±  Γ ±δσΣ≤■∙σΘ ε∩÷ΦΦ).

╧≡επ≡α∞∞α ∩εδ≤≈ασ≥ Φτ Ωε∞αφΣφεΘ ±≥≡εΩΦ ±δσΣ≤■∙Φσ ∩α≡α∞σ≥≡√ (Γ ≤Ωαταφφε∞ ∩ε≡ ΣΩσ):

  1. ╚∞  Γ√∩εδφ σ∞εΘ ∩≡επ≡α∞∞√ (±≥αφΣα≡≥φ√Θ ∩α≡α∞σ≥≡ Σδ  ε∩σ≡α÷ΦεφφεΘ ±Φ±≥σ∞√ Unix).
  2. ╥Φ∩ ±εεß∙σφΦ  (1 - Σδ  ±≥α≥Φ±≥ΦΩΦ ΦδΦ 2 - Σδ  ±εß√≥Φ ).
  3. ╧≡Φε≡Φ≥σ≥ (7 - debug, 6 - information, 5 - notice, 4 - warning or 3 - error).
  4. ═ε∞σ≡ ±εεß∙σφΦ ,  Γδ ■∙σπε±  ∩≡Φ≈ΦφεΘ Γ√∩εδφσφΦ  ∩≡επ≡α∞∞√, ΦδΦ 0, ΩεπΣα φαΣε ≤Ωατα≥ⁿ, ≈≥ε ΦφΦ÷Φα≥ε≡ε∞ τα∩≤±Ωα ∩≡επ≡α∞∞√ εΩατ√Γασ≥±  ∩≡αΓΦδε).
  5. ASCII-÷σ∩ε≈Ωα ± ∩εδφ√∞ ≥σΩ±≥ε∞ ±εεß∙σφΦ  (²≥α ÷σ∩ε≈Ωα ∞εµσ≥ Φ∞σ≥ⁿ ±Φ∞Γεδ√ LF ( Ωεφσ÷ ±≥≡εΩΦ)).

╧εδⁿτεΓα≥σδⁿ: ▌≥ε≥ ∩α≡α∞σ≥≡ ε∩≡σΣσδ σ≥, ε≥ Φ∞σφΦ Ωεπε ß≤Σσ≥ Γ√∩εδφ ≥ⁿ±  ∩≡επ≡α∞∞α. ╧≡επ≡α∞∞α ß≤Σσ≥ εßδαΣα≥ⁿ ∩≡ΦΓΦδσπΦ ∞Φ ²≥επε ∩εδⁿτεΓα≥σδ .

╧α≡α∞σ≥≡√, ±Γ ταφφ√σ ± ε≥∩≡αΓΩεΘ SNMP ∩≡σ≡√ΓαφΦΘ

IP αΣ≡σ± SNMP ±σ≡Γσ≡α: ▌≥ε≥ ∩α≡α∞σ≥≡ ε∩≡σΣσδ σ≥ IP αΣ≡σ± SNMP ∞σφσΣµσ≡α, Ωε≥ε≡ε∞≤ ∞σµ±σ≥σΓεΘ ²Ω≡αφ Σεδµσφ ∩ε±√δα≥ⁿ ∩≡σ≡√ΓαφΦ 

SNMP ±εεß∙σ±≥Γε: ▌≥ε≥ ∩α≡α∞σ≥≡ ε∩Φ±√Γασ≥ Φ∞  SNMP ±εεß∙σ±≥Γα, Φ±∩εδⁿτ≤σ∞εσ Γ SMNP ∩≡σ≡√ΓαφΦΦ.

╧ε±δαφφ√σ SNMP ∩≡σ≡√ΓαφΦ  ß≤Σ≤≥ Φ∞σ≥ⁿ ε±φεΓφεΘ ≥Φ∩ 6 Φ ±∩σ÷Φαδⁿφ√σ ≥Φ∩√ 1 - Σδ  ≡σπΦ±≥≡α÷ΦΦ, Φ 2 - Σδ  ±εß√≥ΦΘ. ┬ Ωα≈σ±≥Γσ φε∞σ≡α ∩≡σΣ∩≡Φ ≥Φ  Φ±∩εδⁿτ≤σ≥±  2549, Ωε≥ε≡√Θ ß√δ φατφα≈σφ IANA Ωε∞∩αφΦΦ Aker Consultancy and Informatics.

╘αΘδ /etc/firewall/mibs/AKER-MIB.TXT ±εΣσ≡µΦ≥ Φφ⌠ε≡∞α÷Φ■ ε ±≥≡≤Ω≥≤≡σ MIB Aker Consultancy and Informatics. ▌≥ε≥ ⌠αΘδ τα∩Φ±αφ Γ φε≥α÷ΦΦ ASN.1.

╧α≡α∞σ≥≡√ Σδ  ε≥∩≡αΓΩΦ e-mail

E-mail αΣ≡σ±: ▌≥ε≥ ∩α≡α∞σ≥≡ ε∩Φ±√Γασ≥ αΣ≡σ± ∩εδⁿτεΓα≥σδ  ²δσΩ≥≡εφφεΘ ∩ε≈≥√, Ωε≥ε≡ε∞≤ ∩ε±√δασ≥±  e-mail ±εεß∙σφΦσ. ▌≥ε≥ ∩εδⁿτεΓα≥σδⁿ ∞εµσ≥ ß√≥ⁿ φσ∩ε±≡σΣ±≥Γσφφ√∞ ∩εδⁿτεΓα≥σδσ∞ ∞σµ±σ≥σΓεπε ²Ω≡αφα ΦδΦ φσ ∩≡ΦφαΣδσµα≥ⁿ Ω Φ⌡ ≈Φ±δ≤ (Γ ∩ε±δσΣφσ∞ ±δ≤≈ασ φαΣε ∩Φ±α≥ⁿ ∩εδφ√Θ αΣ≡σ±, φα∩≡Φ∞σ≡, user@aker.com.br).

┼±δΦ φσεß⌡εΣΦ∞ε ∩ε±δα≥ⁿ e-mail φσ±ΩεδⁿΩΦ∞ ∩εδⁿτεΓα≥σδ ∞, ∞εµφε ±ετΣα≥ⁿ ±∩Φ±εΩ Φ Φ∞  ±∩Φ±Ωα Γφσ±≥Φ Γ Σαφφεσ ∩εδσ.

11.2 ╚±∩εδⁿτεΓαφΦσ Φφ≥σ≡⌠σΘ±α Ωε∞αφΣφεΘ ±≥≡εΩΦ

╚φ≥σ≡⌠σΘ± Ωε∞αφΣφεΘ ±≥≡εΩΦ εßδαΣασ≥ ≥σ∞Φ µσ Γετ∞εµφε±≥ ∞Φ, ≈≥ε Φ π≡α⌠Φ≈σ±ΩΦΘ Φφ≥σ≡⌠σΘ±, Φ Γσ±ⁿ∞α φσ±δεµσφ Γ ∩≡Φ∞σφσφΦΦ.

╧≤≥ⁿ Ω ∩≡επ≡α∞∞σ: /etc/firewall/fwacao

╤Φφ≥αΩ±Φ±:

fwacao help
fwacao show
fwacao assign <number> [log] [mail] [trap] [program] [alert]
fwacao <program | user | community> [name]
fwacao ip [IP address]
fwacao email [address]
Program help:

Aker Firewall - Version 3.0
fwacao - Φφ≥σ≡⌠σΘ± Ωε∞αφΣφεΘ ±≥≡εΩΦ Σδ  φα±≥≡εΘΩΦ ≡σαΩ÷ΦΦ ±Φ±≥σ∞√
Usage: fwacao help
       fwacao show
       fwacao assign <number> [log] [mail] [trap] [program] [alert]
       fwacao <program | user  | community> [name]
       fwacao ip [IP address]
       fwacao e-mail [address]
       help      = ∩εΩατ√Γασ≥ Σαφφεσ ±εεß∙σφΦσ
       show      = ∩εΩατ√Γασ≥ ±∩Φ±εΩ ±εεß∙σφΦΘ Φ ≡σαΩ÷ΦΘ ±Φ±≥σ∞√
       assign    = φατφα≈ασ≥ ≡σαΩ÷Φ■ φα ΩεφΩ≡σ≥φεσ ±εεß∙σφΦσ
       program   = ε∩≡σΣσδ σ≥ Φ∞  Γ√∩εδφ σ∞εΘ ∩≡επ≡α∞∞√
       user      = ε∩≡σΣσδ σ≥ Φ∞  ∩εδⁿτεΓα≥σδ  Σδ  τα∩≤±Ωα ∩≡επ≡α∞∞√
       community = ε∩≡σΣσδ σ≥ Φ∞  SNMP ±εεß∙σ±≥Γα Σδ  πσφσ≡Φ≡≤σ∞επε ∩≡σ≡√ΓαφΦ 
       ip        = ε∩≡σΣσδ σ≥ IP αΣ≡σ± SNMP ±σ≡Γσ≡α, Ωε≥ε≡ε∞≤ ß≤Σσ≥ ε≥∩≡αΓδσφε ∩≡σ≡√ΓαφΦ 
       e-mail    = ε∩≡σΣσδ σ≥ Φ∞  ∩εδⁿτεΓα≥σδ , Ωε≥ε≡ε∞≤ ß≤Σσ≥ ε≥∩≡αΓδσφ e-mail
─δ  Ωε∞αφΣ√ assign:
       number    =φε∞σ≡ ±εεß∙σφΦ , Σδ  Ωε≥ε≡επε ε∩Φ±√Γασ≥±  ≡σαΩ÷Φ 
                   (φε∞σ≡ ΩαµΣεπε ±εεß∙σφΦ  ∩≡ΦΓεΣΦ≥±  Γ δσΓεΘ ΩεδεφΩσ
                    σ±δΦ ∩≡ε±∞α≥≡ΦΓα≥ⁿ ±∩Φ±εΩ ε∩÷ΦσΘ show)
       log       = ≡σπΦ±≥≡Φ≡εΓα≥ⁿ ΩαµΣεσ πσφσ≡Φ≡≤σ∞εσ ±εεß∙σφΦσ
       mail      = ∩ε±δα≥ⁿ e-mail Σδ  ΩαµΣεπε πσφσ≡Φ≡≤σ∞επε ±εεß∙σφΦ 
       trap      = ∩ε±δα≥ⁿ SNMP ∩≡σ≡√ΓαφΦσ Σδ  ΩαµΣεπε πσφσ≡Φ≡≤σ∞επε ±εεß∙σφΦ 
       program   = Γ√∩εδφΦ≥ⁿ ∩≡επ≡α∞∞≤ Σδ  ΩαµΣεπε πσφσ≡Φ≡≤σ∞επε ±εεß∙σφΦ 
       alert     = ε≥Ω≡√≥ⁿ εΩφε ∩≡σΣ≤∩≡σµΣσφΦΘ Σδ  ΩαµΣεπε πσφσ≡Φ≡≤σ∞επε ±εεß∙σφΦ 
╧≡Φ∞σ≡ 1: (═α±≥≡εΘΩα ∩α≡α∞σ≥≡εΓ Σδ  ε≥∩≡αΓΩΦ e-mail Φ Γ√∩εδφσφΦσ ∩≡επ≡α∞∞√)

#fwacao e-mail root
#fwacao program /etc/pager
#fwacao user nobody
╧≡Φ∞σ≡ 2: (╧≡ε±∞ε≥≡ Γ±σ⌡ ε∩Φ±αφΦΘ ≡σαΩ÷ΦΦ ±Φ±≥σ∞√)

#fwacao show
General Conditions:
00 - Packet did not match any rule
>>>> Log
Log messages:
01 - Possible fragmentation attack
>>>> Log Mail
02 - Source routed IP packet
>>>> Log
03 - Land attack
>>>> Log Mail Alert
04 - Connection is not present in the dynamic table
>>>>
05 - Packet was received from an invalid interface
>>>> Log
06 - Packet was received from an unknown interface
>>>> Log
07 - Possible FTP simulation attack
>>>> Log Mail Trap Program
    
(...)
84 - Error in the previous operation  
>>>> Log
85 - User without access right
>>>> Log
86 - Unrecognized packet
>>>> Log
Configuration parameters:
program   : /etc/pager
user      : nobody
e-mail    : root
community :
ip        :
┬φΦ∞αφΦσ: ╚τ-τα ßεδⁿ°επε ΩεδΦ≈σ±≥Γα ±εεß∙σφΦΘ Γ ∩≡Φ∞σ≡σ ß≤Σ≤≥ ∩≡ΦΓσΣσφ√ ≥εδⁿΩε ∩σ≡Γεσ Φ ∩ε±δσΣφσσ. ═α±≥ε ∙α  ∩≡επ≡α∞∞α Γ ∩≡ε÷σ±±σ Γ√∩εδφσφΦ  ∩εΩαµσ≥ Γ±σ ±εεß∙σφΦ .

╧≡Φ∞σ≡ 3: (╬∩Φ±αφΦσ ≡σαΩ÷ΦΦ φα ±εεß∙σφΦσ Packet did not match any rule Φ ∩≡ε±∞ε≥≡ ±εεß∙σφΦΘ)

#fwacao assign 0 log mail alert
#fwacao show
General Conditions:
00 - Packet did not match any rule
>>>> Log Mail Alert
Log messages:
01 - Possible fragmentation attack
>>>> Log Mail
02 - Source routed IP packet
>>>> Log
03 - Land attack
>>>> Log Mail Alert
04 - Connection is not present in the dynamic table
>>>>
05 - Packet was received from an invalid interface
>>>> Log
06 - Packet was received from an unknown interface
>>>> Log
07 - Possible FTP simulation attack
>>>> Log Mail Trap Program
    
(...)
84 - Error in the previous operation  
>>>> Log
85 - User without access right
>>>> Log
86 - Unrecognized packet
>>>> Log
Configuration parameters:
program   : /etc/pager
user      : nobody
e-mail    : root
community :
ip        :
╧≡Φ∞σ≡ 4: (╬≥∞σφα ≡σαΩ÷ΦΦ φα ±εεß∙σφΦσ Source routed IP packet)

#fwacao assign 2
#fwacao show
General Conditions:
00 - Packet did not match any rule
>>>> Log Mail Alert
Log messages:
01 - Possible fragmentation attack
>>>> Log Mail
02 - Source routed IP packet
>>>> 
03 - Land attack
>>>> Log Mail Alert
04 - Connection is not present in the dynamic table
>>>>
05 - Packet was received from an invalid interface
>>>> Log
06 - Packet was received from an unknown interface
>>>> Log
07 - Possible FTP simulation attack
>>>> Log Mail Trap Program
    
(...)
84 - Error in the previous operation  
>>>> Log
85 - User without access right
>>>> Log
86 - Unrecognized packet
>>>> Log
Configuration parameters:
program   : /etc/pager
user      : nobody
e-mail    : root
community :
ip        :

═αταΣ | ╤εΣσ≡µαφΦσ | ┬∩σ≡σΣ