Nipper


Cisco Firewall Security Report

of the

HatSecurity.com-PIX-demo1 Cisco Firewall


Contents

1. About This Report
    1.1. Organisation
    1.2. Conventions
2. Security Audit
    2.1. Introduction
    2.2. Software Version
    2.3. Dictionary-based Password / Key
    2.4. Weak Password / Key
    2.5. Simple Network Management Protocol
    2.6. Access Control Lists
    2.7. Conclusions
3. Device Configuration
    3.1. Introduction
    3.2. General
    3.3. Services
    3.4. Simple Network Management Protocol
    3.5. Interfaces
    3.6. Access Control List
    3.7. Protocol Inspection
    3.8. Object Groups
    3.9. IP Address Name Mappings
4. Appendix
    4.1. Abbreviations
    4.2. Common Ports
    4.3. Logging Severity Levels
    4.4. Time Zones
    4.5. Nipper Details


1. About This Report

1.1. Organisation

This Cisco Private Internet Exchange (PIX) Firewall HatSecurity.com-PIX-demo1 report was produced by Nipper on Wednesday 2nd July 2008. The report contains the following sections:
 

1.2. Conventions

This report makes use of the text conventions outlined in Table 1.
 
Table 1: Report text conventions
Convention Description
command
This text style represents the Cisco PIX Firewall command text that has to be entered literally.
string
This text style represents the Cisco PIX Firewall command text that the you have to enter.
[ ]
Used to enclose a Cisco PIX Firewall command option.
{ }
Used to enclose a Cisco PIX Firewall command requirement.
|
Divides command option or requirement choices.
 

2. Security Audit

2.1. Introduction

Nipper performed a security audit of the Cisco PIX Firewall HatSecurity.com-PIX-demo1 on Wednesday 2nd July 2008. This section details the findings of the security audit together with the impact and recommendations.
 

2.2. Software Version

Observation: It is critically important that software be regularly maintained with patches and upgrades in order to help mitigate the risk of an attacker exploiting a known software vulnerability. Furthermore, additional security features and other functionality are normally added or extended with each software revision.
 
Nipper determined that the Cisco PIX Firewall HatSecurity.com-PIX-demo1 was running the out of date software PIX version 6.3(3).
 
Nipper identified a potential vulnerability in PIX version 6.3(3) which is described in various vulnerability databases as "Multiple remote denial of service" (CVE reference CVE-2007-0962 and Bugtraq ID 22561).It is worth noting that Nipper used the version number detailed in the device configuration to identify the potential vulnerabilities, and patches may have already been applied. Additionally, a specific device configuration may be required in order for the device to become vulnerable.
 
Impact: The vulnerability outlined above could allow an attacker to perform a Denial of Service (DoS) attack.
 
Ease: Exploit code is widely available on the Internet for known Cisco PIX Firewall vulnerabilities.
 
Recommendation: Nipper strongly recommends that the software be updated and patched to the latest software version. Furthermore, Nipper recommends that the current patch policy be reviewed.
 

2.3. Dictionary-based Password / Key

Observation: Attackers will often have dictionaries of words that contain names, places, default passwords and other common passwords. If a password or key is likely to be contained within an attacker's dictionary, they could gain access to the system.
 
The passwords and keys of the device HatSecurity.com-PIX-demo1 were tested against a small dictionary and one password / key was identified. The read-only Simple Network Management Protocol (SNMP) community string was public.
 
Impact: An attacker who was able to identify a password or key would be able to gain a level of access to the device, based on what service the password / key was used for.
 
Ease: Tools are available on the Internet that can perform dictionary-based password guessing against a number of network services.
 
Recommendation: Nipper strongly recommends that the password identified be immediately changed to something that is more difficult to guess. Nipper recommends that passwords be made up of at least eight characters in length and contain either uppercase or lowercase characters and numbers.
 

2.4. Weak Password / Key

Observation: Strong passwords tend to contain a number of different types of character, such as uppercase and lowercase letters, numbers and punctuation characters. Weaker passwords tend not to contain a mixture of character types. Additionally, weaker passwords tend to be short in length.
 
Nipper identified one password / key that did not meet the minimum password complexity requirements. The read-only SNMP community string was public.
 
Impact: If an attacker were able to gain a password or key, either through dictionary-based guessing techniques or by a brute-force method, the attacker could gain a level of access to HatSecurity.com-PIX-demo1.
 
Ease: A number of dictionary-based password guessing and password brute-force tools are available on the Internet.
 
Recommendation: Nipper strongly recommends that the weak password be immediately changed to one that is stronger. Nipper recommends that passwords be made up of at least eight characters in length and contain either uppercase or lowercase characters and numbers.
 

2.5. Simple Network Management Protocol

Observation: Cisco PIX Firewall devices support only SNMP protocol versions 1 and 2c. Nipper determined that SNMP was configured on HatSecurity.com-PIX-demo1.
 
Impact: Due to the unencrypted nature of SNMP protocol versions 1 and 2c, an attacker who was able to monitor network traffic could capture device configuration settings, including authentication details.
 
Ease: Network packet monitoring and capture tools are widely available on the Internet and SNMP tools are included as standard with some operating systems.
 
Observation: On Cisco PIX Firewall devices, SNMP version 3 with auth and priv authentication cannot be configured. Therefore, Nipper recommends that, if not required, SNMP be disabled. SNMP access to HatSecurity.com-PIX-demo1 can be disabled with the following command:
 
no snmp-server enable

 

2.6. Access Control Lists

Observation: Access Control List (ACL) are sequential lists of allow and deny Access Control Entries (ACE) that specify whether network traffic should be allowed or dropped. ACLs are used to restrict access to services and network devices, preventing access to services and devices that should not be accessible.
 
Nipper identified 244 security-related issues with the configured ACL, these are listed in Table 2.
 
Table 2: Insecure Access Control Entries
ACL Line Description
outside_access_in9Allows access from a network source to dialup / 255.255.255.0.
Allows access from dialup / 255.255.252.0 to a network destination.
Allows access from dialup / 255.255.252.0 to any destination service.
outside_access_in10Allows access from a network source to intranet.
outside_access_in11Allows access from any source to idl.
outside_access_in12Allows access from any source to HASimc01.
outside_access_in13Allows access from any source to HASimc02.
outside_access_in14Allows access from any source to HASimc04.
outside_access_in15Allows access from any source to 22.118.128.154.
outside_access_in16Allows access from any source to WAS.
outside_access_in17Allows access from a network source to cache.
outside_access_in18Allows access from any source to 22.118.128.66.
outside_access_in19Allows access from any source to 22.118.128.66.
outside_access_in20Allows access from any source to 22.118.128.67.
outside_access_in21Allows access from any source to 22.118.128.67.
outside_access_in22Allows access from a network source to 22.118.128.32 / 255.255.255.240.
Allows access from dialup / 255.255.255.240 to a network destination.
Allows access from dialup / 255.255.255.240 to any destination service.
outside_access_in23Allows access from any source to internet.
outside_access_in24Allows access from any source to edirectory1.
outside_access_in25Allows access from a network source to pptp.
outside_access_in26Allows access from a network source to pptp.
Allows access from Dailup_user / 255.255.254.0 to any destination service.
outside_access_in27Allows access from a network source to pptp2.
Allows access from Dailup_user / 255.255.254.0 to any destination service.
outside_access_in28Allows access from a network source to pptp2.
outside_access_in30Allows access from any source to ebill.
outside_access_in31Allows access from a network source to inetlog02.
outside_access_in32Allows access from a network source to 22.118.128.78.
outside_access_in33Allows access from a network source to 22.118.128.78.
outside_access_in34Allows access from a network source to 22.118.128.77.
outside_access_in35Allows access from a network source to 22.118.128.77.
outside_access_in36Allows access from a network source to inetlog02.
outside_access_in40Allows access from any source to 22.118.128.20.
outside_access_in41Allows access from any source to 22.118.128.25.
outside_access_in42Allows access from any source to 22.118.128.20.
outside_access_in43Allows access from any source to 22.118.128.25.
outside_access_in44Allows access from any source to 22.118.128.19.
Allows access from any address to any destination service.
outside_access_in45Allows access from any source to 22.118.128.21.
Allows access from any address to any destination service.
outside_access_in46Allows access from any source to 22.118.128.19.
Allows access from any address to any destination service.
outside_access_in47Allows access from any source to 22.118.128.21.
Allows access from any address to any destination service.
outside_access_in48Allows access from 22.118.128.20 to any destination.
outside_access_in49Allows access from 22.118.128.25 to any destination.
outside_access_in50Allows access from 22.118.128.20 to any destination.
outside_access_in51Allows access from 22.118.128.25 to any destination.
outside_access_in53Allows access from any source to 22.118.128.152.
outside_access_in54Allows access from any source to 22.118.128.152.
outside_access_in56Allows access from any source to 22.118.128.73.
outside_access_in57Allows access from any source to symantec1.
outside_access_in60Allows access from any source to 22.118.128.95.
outside_access_in67Allows access from 22.138.47.100 to any destination service.
outside_access_in68Allows access from 22.138.47.100 to any destination service.
outside_access_in69Allows access from 22.118.136.198 to any destination service.
outside_access_in70Allows access from 22.118.136.198 to any destination service.
outside_access_in71Allows access from 22.26.63.45 to any destination service.
outside_access_in72Allows access from 22.26.63.45 to any destination service.
outside_access_in78Allows access from a network source to inetlog02.
outside_access_in86Allows access from any source to 22.118.128.92.
outside_access_in87Allows access from any source to 22.118.128.92.
outside_access_in88Allows access from any source to ebill.
outside_access_in89Allows access from any source to ebill.
outside_access_in90Allows access from any source to 22.118.128.110.
outside_access_in91Allows access from any source to 22.118.128.110.
outside_access_in92Allows access from any source to 22.118.128.91.
outside_access_in93Allows access from any source to 22.118.128.91.
outside_access_in94Allows access from scr2160_d to any destination service.
outside_access_in95Allows access from scr2160_d to any destination service.
outside_access_in97Allows access from 22.118.136.54 to any destination service.
outside_access_in98Allows access from 22.118.136.54 to any destination service.
outside_access_in99Allows access from 22.118.136.198 to any destination service.
outside_access_in100Allows access from 22.118.136.198 to any destination service.
outside_access_in101Allows access from 22.118.133.140 to any destination service.
outside_access_in102Allows access from 22.118.133.140 to any destination service.
outside_access_in103Allows access from 22.118.133.133 to any destination service.
outside_access_in104Allows access from 22.118.133.133 to any destination service.
outside_access_in105Allows access from ABCNetP to any destination service.
outside_access_in106Allows access from ABCNetP to any destination service.
outside_access_in107Allows access from 22.118.133.137 to any destination service.
outside_access_in108Allows access from 22.118.133.137 to any destination service.
outside_access_in113Allows access from any source to cache1-out.
outside_access_in114Allows access from any source to cache2-out.
outside_access_in116Allows access from scr2160 to any destination service.
outside_access_in118Allows access from 22.118.128.226 to any destination service.
outside_access_in119Allows access from 22.118.128.225 to any destination service.
outside_access_in121Allows access from any source to 22.118.128.24.
outside_access_in122Allows access from any source to 22.118.128.24.
outside_access_in123Allows access from any source to exchange.
outside_access_in126Allows access from any source to 22.118.128.110.
outside_access_in137Allows access from any source to Ayma.
outside_access_in138Allows access from intranet to any destination.
outside_access_in139Allows access from intranet to any destination.
outside_access_in140Allows access from any source to 22.118.128.116.
outside_access_in143Allows access from any source to intranet.
outside_access_in144Allows access from any source to intranet.
outside_access_in145Allows access from any source to 22.118.128.26.
outside_access_in148Allows access from any source to 22.118.128.101.
Allows access from any address to any destination service.
outside_access_in149Allows access from any source to 22.118.128.101.
Allows access from any address to any destination service.
outside_access_in150Allows access from any source to 22.118.128.101.
outside_access_in155Allows access from any source to 22.118.128.102.
Allows access from any address to any destination service.
outside_access_in156Allows access from 22.118.128.102 to any destination.
Allows access from 22.118.128.102 to any destination service.
inside_access_in1Allows access from any source to any address.
Allows access from any address to any destination.
Allows access from any address to any destination service.
inside_access_in2Allows access from DNS2 to any destination.
inside_access_in3Allows access from DNS2 to any destination.
inside_access_in4Allows access from DNS1 to any destination.
inside_access_in5Allows access from DNS1 to any destination.
inside_access_in6Allows access from WAS to any destination.
Allows access from WAS to any destination service.
inside_access_in7Allows access from WAP to any destination.
Allows access from WAP to any destination service.
inside_access_in8Allows access from 22.118.128.66 to any destination.
inside_access_in10Allows access from 22.118.128.66 to any destination.
inside_access_in11Allows access from 22.118.128.67 to any destination.
inside_access_in12Allows access from 22.118.128.67 to any destination.
inside_access_in13Allows access from HASimc01 to any destination.
inside_access_in14Allows access from HASimc02 to any destination.
inside_access_in15Allows access from HASimc04 to any destination.
inside_access_in16Allows access from 22.118.128.154 to any destination.
inside_access_in19Allows access from wireless-BB to any destination.
Allows access from wireless-BB to any destination service.
inside_access_in20Allows access from pptp to any destination.
inside_access_in21Allows access from pptp to any destination.
Allows access from pptp to any destination service.
inside_access_in22Allows access from pptp2 to any destination.
inside_access_in23Allows access from pptp2 to any destination.
Allows access from pptp2 to any destination service.
inside_access_in24Allows access from inetlog02 to any destination.
Allows access from inetlog02 to any destination service.
inside_access_in25Allows access from cache2-out to any destination.
inside_access_in26Allows access from cache1-out to any destination.
inside_access_in27Allows access from cache1-out to any destination.
inside_access_in28Allows access from cache2-out to any destination.
inside_access_in31Allows access from Ahme to any destination service.
inside_access_in32Allows access from any source to 22.118.128.20.
inside_access_in33Allows access from any source to 22.118.128.20.
inside_access_in34Allows access from any source to 22.118.128.25.
inside_access_in35Allows access from any source to 22.118.128.25.
inside_access_in36Allows access from 22.118.128.20 to any destination.
inside_access_in37Allows access from 22.118.128.25 to any destination.
inside_access_in38Allows access from 22.118.128.25 to any destination.
inside_access_in39Allows access from 22.118.128.20 to any destination.
inside_access_in47Allows access from 22.118.128.76 to any destination.
inside_access_in48Allows access from 22.118.128.76 to any destination.
inside_access_in49Allows access from 22.118.128.76 to any destination.
inside_access_in50Allows access from 22.118.128.73 to any destination.
inside_access_in51Allows access from symantec1 to any destination.
inside_access_in60Allows access from 22.118.128.68 to any destination service.
inside_access_in61Allows access from cache1-out to any destination service.
inside_access_in62Allows access from 22.118.128.68 to any destination service.
inside_access_in63Allows access from cache1-out to any destination service.
inside_access_in68Allows access from 22.118.128.158 to any destination service.
inside_access_in83Allows access from 22.118.128.162 to any destination service.
inside_access_in86Allows access from 22.118.128.162 to any destination service.
inside_access_in100Allows access from 22.118.128.164 to any destination service.
inside_access_in101Allows access from 22.118.128.164 to any destination service.
inside_access_in102Allows access from 22.118.128.91 to any destination.
inside_access_in103Allows access from 22.118.128.91 to any destination.
inside_access_in105Allows access from 22.118.128.164 to any destination service.
inside_access_in106Allows access from 22.118.128.164 to any destination service.
inside_access_in107Allows access from cache1-out to any destination.
inside_access_in108Allows access from cache2-out to any destination.
inside_access_in109Allows access from cache1-out to any destination.
inside_access_in110Allows access from cache2-out to any destination.
inside_access_in111Allows access from cache1-out to any destination.
inside_access_in112Allows access from cache2-out to any destination.
inside_access_in113Allows access from cache1-out to any destination.
inside_access_in114Allows access from cache2-out to any destination.
inside_access_in115Allows access from cache1-out to any destination.
inside_access_in116Allows access from cache2-out to any destination.
inside_access_in117Allows access from cache1-out to any destination.
inside_access_in118Allows access from cache1-out to any destination.
inside_access_in119Allows access from cache1-out to any destination.
inside_access_in120Allows access from cache2-out to any destination.
inside_access_in121Allows access from cache2-out to any destination.
inside_access_in122Allows access from cache2-out to any destination.
inside_access_in126Allows access from 22.118.128.170 to any destination.
inside_access_in127Allows access from 22.118.128.163 to any destination.
inside_access_in128Allows access from 22.118.128.163 to any destination.
inside_access_in130Allows access from 22.118.128.164 to any destination service.
inside_access_in131Allows access from 22.118.128.164 to any destination service.
inside_access_in132Allows access from 22.118.128.164 to any destination service.
inside_access_in136Allows access from a network source to 22.118.128.22.
Allows access from 172.20.10.8 / 255.255.255.252 to any destination service.
inside_access_in137Allows access from a network source to 22.118.128.21.
Allows access from 172.20.10.8 / 255.255.255.252 to any destination service.
inside_access_in138Allows access from a network source to 22.118.128.22.
inside_access_in139Allows access from a network source to 22.118.128.22.
inside_access_in140Allows access from a network source to 22.118.128.21.
inside_access_in141Allows access from a network source to 22.118.128.21.
inside_access_in151Allows access from cache1-out to any destination.
inside_access_in152Allows access from cache2-out to any destination.
inside_access_in157Allows access from a network source to escr-4463_d.
inside_access_in158Allows access from a network source to escr-4463_d.
inside_access_in159Allows access from escr-4463_d to any destination.
inside_access_in160Allows access from escr-4463_d to any destination.
inside_access_in169Allows access from 10.33.18.160 to a network destination.
inside_access_in177Allows access from escr5723_s to a network destination.
inside_access_in180Allows access from any source to 22.118.128.110.
inside_access_in182Allows access from any source to 22.118.128.110.
inside_access_in183Allows access from 10.32.8.90 to any destination.
Allows access from 10.32.8.90 to any destination service.
inside_access_in184Allows access from 10.32.8.94 to any destination.
Allows access from 10.32.8.94 to any destination service.
inside_access_in193Allows access from escr8063_d to any destination service.
inside_access_in194Allows access from escr8063_d to any destination service.
inside_access_in195Allows access from escr8063_s to any destination service.
inside_access_in196Allows access from escr8063_s to any destination service.
inside_access_in197Allows access from a network source to 22.118.128.24.
inside_access_in198Allows access from 22.118.128.102 to any destination.
inside_access_in199Allows access from 22.118.128.102 to any destination.
inside_access_in200Allows access from a network source to 22.118.128.24.
inside_access_in201Allows access from 10.245.1.5 to any destination service.
inside_access_in220Allows access from Ayma to any destination.
inside_access_in225Allows access from 172.20.239.7 to any destination.
inside_access_in226Allows access from 172.20.239.7 to any destination.
inside_access_in227Allows access from any source to 172.20.239.7.
inside_access_in228Allows access from any source to intranet.
inside_access_in229Allows access from any source to intranet.
inside_access_in230Allows access from a network source to 22.118.154.29.
inside_access_in231Allows access from any source to 172.20.239.7.
inside_access_in238Allows access from 22.118.128.101 to any destination.
Allows access from 22.118.128.101 to any destination service.
inside_access_in239Allows access from 22.118.128.101 to any destination.
Allows access from 22.118.128.101 to any destination service.
inside_access_in240Allows access from intranet to any destination.
inside_access_in241Allows access from 22.118.128.101 to any destination.
inside_access_in242Allows access from intranet to any destination.
inside_access_in244Allows access from any source to 22.118.128.102.
Allows access from any address to any destination service.
inside_access_in245Allows access from 22.118.128.102 to any destination.
Allows access from 22.118.128.102 to any destination service.
inside_access_in250Allows access from 22.118.128.186 to any destination service.
inside_access_in251Allows access from 10.32.9.210 to any destination service.
inside_access_in252Allows access from escr9332_s to any destination.
inside_access_in253Allows access from 193.110.54.70 to any destination service.
 
Impact: If ACEs are not sufficiently restrictive, an attacker may be able to access services or network devices that should not be accessible. Furthermore, an attacker who had compromised a device could install a backdoor which could listen on a network port that was not filtered.
 
Ease: N/A
 
Recommendation: Nipper recommends that the ACLs be reviewed and, where possible, modified to ensure that: However, in certain circumstances, such as a public web server, a more relaxed configuration may be required to allow any host to access specific hosts and services.
 

2.7. Conclusions

Nipper performed a security audit of the Cisco PIX Firewall device HatSecurity.com-PIX-demo1 on Wednesday 2nd July 2008 and identified five security-related issues. Nipper determined that:
 

3. Device Configuration

3.1. Introduction

This section details the configuration settings of the Cisco PIX Firewall device HatSecurity.com-PIX-demo1.
 

3.2. General

Table 3: General device settings
Description Setting
HostnameHatSecurity.com-PIX-demo1
Domain NameHatSecurity.com
PIX Version6.3(3)
Transparent FirewallNo
Flood GuardEnabled
 

3.3. Services

Table 4: Device services
Service Status
SNMP ServerEnabled
HTTPS ServerDisabled
 

3.4. Simple Network Management Protocol

SNMP is used to assist network administrators in monitoring and managing a wide variety of network devices. There are three main versions of SNMP in use. Versions 1 and 2 of SNMP are both secured with a community string and authenticate and transmit network packets without any form of encryption. SNMP version 3 provides several levels of authentication and encryption. The most basic level provides a similar protection to that of the earlier protocol versions. However, SNMP version 3 can be configured to provide encrypted authentication (auth) and secured further with support for encrypted data communications (priv). However, Cisco PIX Firewall currently only support SNMP versions 1 and 2.
 
Table 5: General SNMP service configuration
Description Setting
SNMP ServerEnabled
UDP Port161
Community Stringpublic
Contact
Location
 
Table 6: SNMP traps
Type Trap
snmpauthentication
snmplinkup
snmplinkdown
snmpcoldstart
 

3.5. Interfaces

Table 7: Interfaces
Interface Name Shutdown IP Address Net Mask Security uRPF In ACL Out ACL
gb-ethernet0intf2Yes10No
gb-ethernet1intf3Yes15No
ethernet0outsideNo0No
ethernet1insideNo100No
ethernet2intf4Yes20No
ethernet3intf5Yes25No
ethernet4CWS_DMZNo50No
ethernet5managementNo50No
 

3.6. Access Control List

A Cisco ACL is a sequential list of apply or deny ACEs that a Cisco device will apply to network traffic. The Cisco device will check network traffic against the ACL and the first ACE match will determine whether the packet is accepted or rejected. If the Cisco device does not have an ACE that applies then the packet is denied.
 
Newer versions of Cisco firewall devices have two different types of ACL, standard and extended. Standard ACL are typically used to secure Open Shortest Path First (OSPF) routes, whilst extended ACL are used for all other network filtering.
 
Table 8: General ACL settings
Description Setting
Alert Interval300 seconds
Maximum Deny Flows4096
 
Table 9: ACL outside_access_in
Line Permission Protocol Source Source Port Destination Destination Port
------ Temporary Rules ------
------ END of Temporary Rules ------
1DenyudpAnyAnyAnynameserver
2DenytcpAnyAnyAny42
3DenytcpAnyAnyAny5554
4DenytcpAnyAnyAny9996
5DenyudpAny4000AnyAny
6Denyip22.118.100.78AnyAnyAny
7DenyudpAnyAnyAny1434
8DenytcpAnyAnyAny6129
9Permiticmpdialup / 255.255.252.0Anydialup / 255.255.255.0Any
10PermittcpDailup_user / 255.255.254.0Anyintranetwww
11PermittcpAnyAnyidlwww
12PermittcpAnyAnyHASimc01smtp
13PermittcpAnyAnyHASimc02smtp
14PermittcpAnyAnyHASimc04smtp
15PermittcpAnyAny22.118.128.154smtp
16PermittcpAnyAnyWASftp
17PermittcpDailup_user / 255.255.254.0Anycache8080
18PermittcpAnyAny22.118.128.66domain
19PermitudpAnyAny22.118.128.66domain
20PermittcpAnyAny22.118.128.67domain
21PermitudpAnyAny22.118.128.67domain
22Permiticmpdialup / 255.255.255.240Any22.118.128.32 / 255.255.255.240Any
23PermittcpAnyAnyinternetwww
24PermittcpAnyAnyedirectory1www
25PermittcpDailup_user / 255.255.254.0Anypptppptp
26PermitgreDailup_user / 255.255.254.0AnypptpAny
27PermitgreDailup_user / 255.255.254.0Anypptp2Any
28PermittcpDailup_user / 255.255.254.0Anypptp2pptp
29PermittcpABCNetAnyintranetwww
30PermittcpAnyAnyebillwww
31Permitudpdialup / 255.255.255.0Anyinetlog02snmp
32Permittcpdialup / 255.255.252.0Any22.118.128.78domain
33Permitudpdialup / 255.255.252.0Any22.118.128.78domain
34Permittcpdialup / 255.255.252.0Any22.118.128.77domain
35Permitudpdialup / 255.255.252.0Any22.118.128.77domain
36Permitudpdialup / 255.255.255.0Anyinetlog02snmptrap
37Permittcpescr4466_sAnyescr4466_d1645 - 1646
38Permitudpescr4466_sAnyescr4466_dradius - radius-acct
39Permitudp22.118.128.225Any22.118.128.67radius-acct
40PermittcpAnyAny22.118.128.20www
41PermittcpAnyAny22.118.128.25www
42PermittcpAnyAny22.118.128.20https
43PermittcpAnyAny22.118.128.25https
44PermiticmpAnyAny22.118.128.19Any
45PermiticmpAnyAny22.118.128.21Any
46PermiticmpAnyAny22.118.128.19Any
47PermiticmpAnyAny22.118.128.21Any
48Permittcp22.118.128.20AnyAnywww
49Permittcp22.118.128.25AnyAnywww
50Permittcp22.118.128.20AnyAnyhttps
51Permittcp22.118.128.25AnyAnyhttps
52PermittcpABCNetAnyBSC8080
53PermittcpAnyAny22.118.128.152www
54PermittcpAnyAny22.118.128.152https
55Permitudp22.118.128.225Any22.118.128.67radius
56PermittcpAnyAny22.118.128.73smtp
57PermittcpAnyAnysymantec1smtp
58Permittcp171.68.227.106Anycisco-tactelnet
59Permittcp22.118.128.225Anycisco-tactelnet
60PermittcpAnyAny22.118.128.95www
61PermittcpipassAny22.118.128.158577
62Permitudpscr792_sAny22.118.128.66radius
63Permitudpscr792_sAny22.118.128.67radius
64Permittcp172.30.14.130Anycache8080 - 8081
65Permittcp172.20.19.2Anycache8080 - 8081
66Permittcp195.149.45.5Any22.118.128.68telnet
67Permiticmp22.138.47.100Any22.118.128.68Any
68Permiticmp22.138.47.100Anycache1-outAny
69Permitip22.118.136.198Any22.118.128.68Any
70Permitip22.118.136.198Anycache1-outAny
71Permitip22.26.63.45Any22.118.128.68Any
72Permitip22.26.63.45Anycache1-outAny
73Permitudp22.118.128.225Any22.118.128.66radius - radius-acct
74Permitudp22.118.128.225Any22.118.128.67radius - radius-acct
75Permittcp64.104.205.63Anycisco-tactelnet
76PermittcpebillAny172.20.238.77sqlnet
77PermitudpebillAny172.20.238.771521
78Permitudp22.118.128.224 / 255.255.255.240Anyinetlog02syslog
79Permittcp22.247.15.77Any22.118.128.169ssh
80Permittcp22.247.15.77Any22.118.128.168ssh
81Permitudp22.118.128.226Any22.118.128.66radius
82Permitudp22.118.128.226Any22.118.128.66radius-acct
83Denyip22.234.153.202AnyAnyAny
84Permitudp22.118.128.226Any22.118.128.67radius
85Permitudp22.118.128.226Any22.118.128.67radius-acct
86PermittcpAnyAny22.118.128.9281
87PermittcpAnyAny22.118.128.92449
88PermittcpAnyAnyebill81
89PermittcpAnyAnyebill449
90PermittcpAnyAny22.118.128.110https
91PermittcpAnyAny22.118.128.110www
92PermittcpAnyAny22.118.128.91www
93PermittcpAnyAny22.118.128.91https
94Permiticmpscr2160_dAny22.118.128.164Any
95Permiticmpscr2160_dAny22.118.128.164Any
96Denyip26.136.173.161AnyAnyAny
97Permiticmp22.118.136.54Any22.118.128.164Any
98Permiticmp22.118.136.54Any22.118.128.164Any
99Permiticmp22.118.136.198Any22.118.128.164Any
100Permiticmp22.118.136.198Any22.118.128.164Any
101Permiticmp22.118.133.140Any22.118.128.164Any
102Permiticmp22.118.133.140Any22.118.128.164Any
103Permiticmp22.118.133.133Any22.118.128.164Any
104Permiticmp22.118.133.133Any22.118.128.164Any
105PermiticmpABCNetPAny22.118.128.164Any
106PermiticmpABCNetPAny22.118.128.164Any
107Permiticmp22.118.133.137Any22.118.128.164Any
108Permiticmp22.118.133.137Any22.118.128.164Any
109Permittcp22.247.15.77Any22.118.128.168telnet
110Permittcp22.247.15.77Any22.118.128.168ftp
111Permittcp22.247.15.77Any22.118.128.169telnet
112Permittcp22.247.15.77Any22.118.128.169ftp
113PermitudpAnyAnycache1-out6970 - 7170
114PermitudpAnyAnycache2-out6970 - 7170
115Permittcpscr05-01-1685_sAnyscr05-01-1685_dscr05-01-1685_p
116Permiticmpscr2160Any22.118.128.164Any
117Permitudp22.118.128.226Any22.118.128.1852055
118Permitip22.118.128.226Any22.118.128.185Any
119Permitip22.118.128.225Any22.118.128.185Any
120Permittcp22.135.137.194Any22.135.137.194ftp-data
121PermitudpAnyAny22.118.128.24www
122PermittcpAnyAny22.118.128.24www
123PermittcpAnyAnyexchangehttps
124Permittcpescr-4466_s1Anyescr-4466_d1645 - 1646
125Permitudpescr-4466_s1Anyescr-4466_dradius - radius-acct
126PermittcpAnyAny22.118.128.11011001
127Permittcp172.20.10.10Anyescr7069_descr7069_p
128Permitudp172.20.10.10Anyescr7069_descr7069_p1
129Permittcpsymantec3Anyescr7069_descr7069_p
130Permitudpsymantec3Anyescr7069_descr7069_p1
131Permittcpescr7069_dAny172.20.10.10escr7069_p
132Permitudpescr7069_dAny172.20.10.10escr7069_p1
133Permittcp22.118.128.189Any22.118.133.92ftp
134Permittcpescr7069_dAnysymantec3escr7069_p
135Permitudpescr7069_dAnysymantec3escr7069_p1
136Permittcp22.118.128.188Any22.118.154.29www
137PermittcpAnyAnyAymahttps
138PermittcpintranetAnyAnyescr8793_p1
139PermitudpintranetAnyAnyescr8793_p3
140PermittcpAnyAny22.118.128.116https
141Permittcp22.118.129.253Anysymantec31645 - 1656
142Permittcp22.118.129.253Anysymantec41645 - 1656
143PermitudpAnyAnyintranetescr8931_p2
144PermittcpAnyAnyintranetescr8931_p1
145PermittcpAnyAny22.118.128.26https
146Permitudpescr8942_dAny10.33.16.12636
147Permittcpescr8942_dAny10.33.16.12ldaps
148PermitudpAnyAny22.118.128.101Any
149PermittcpAnyAny22.118.128.101Any
150PermittcpAnyAny22.118.128.101smtp
151Permitudp10.33.16.12Anyescr8942_d636
152Permittcp10.33.16.12Anyescr8942_d63
153Permittcpescr8784_sAnyescr8784_dldaps
154Permitudpescr8784_sAnyescr8784_d636
155PermitipAnyAny22.118.128.102Any
156Permitip22.118.128.102AnyAnyAny
157DenyipAnyAnyAnyAny
 
Table 10: ACL inside_access_in
Line Permission Protocol Source Source Port Destination Destination Port
------ Temporary Rules ------
------ END of Temporary Rules ------
1PermiticmpAnyAnyAnyAny
2PermitudpDNS2AnyAnydomain
3PermittcpDNS2AnyAnydomain
4PermittcpDNS1AnyAnydomain
5PermitudpDNS1AnyAnydomain
6PermitipWASAnyAnyAny
7PermitipWAPAnyAnyAny
8Permittcp22.118.128.66AnyAnydomain
9Permittcp22.118.128.145AnyABCNetP8080
10Permitudp22.118.128.66AnyAnydomain
11Permittcp22.118.128.67AnyAnydomain
12Permitudp22.118.128.67AnyAnydomain
13PermittcpHASimc01AnyAnysmtp
14PermittcpHASimc02AnyAnysmtp
15PermittcpHASimc04AnyAnysmtp
16Permittcp22.118.128.154AnyAnysmtp
17Permittcp22.118.128.145Any22.118.133.1408080
18Permittcp22.118.128.143AnyABCNetP8080
19Permitipwireless-BBAnyAnyAny
20PermittcppptpAnyAnypptp
21PermitgrepptpAnyAnyAny
22Permittcppptp2AnyAnypptp
23Permitgrepptp2AnyAnyAny
24Permitipinetlog02AnyAnyAny
25Permittcpcache2-outAnyAny8080
26Permittcpcache1-outAnyAny8080
27Permittcpcache1-outAnyAnyftp
28Permittcpcache2-outAnyAnyftp
29PermittcpIntGroupHostAnyftp-eng.ciscoftp
30Permittcp22.118.128.139Anyftp-eng.ciscoftp
31PermitipAhmeAny22.118.128.225Any
32PermittcpAnyAny22.118.128.20www
33PermittcpAnyAny22.118.128.20https
34PermittcpAnyAny22.118.128.25https
35PermittcpAnyAny22.118.128.25www
36Permittcp22.118.128.20AnyAnyhttps
37Permittcp22.118.128.25AnyAnyhttps
38Permittcp22.118.128.25AnyAnywww
39Permittcp22.118.128.20AnyAnywww
40Permittcp22.118.128.136Anyftp.sun.co.ukftp
41Permittcp22.118.128.136Anyftp.hostnet.czftp
42Permittcp22.118.128.149Anyftp.sun.co.ukftp
43Permittcp22.118.128.149Anyftp.hostnet.czftp
44Permittcp22.118.128.151Anyftp.sun.co.ukftp
45Permittcp22.118.128.151Anyftp.hostnet.czftp
46Permittcp22.118.128.153AnyCisco_FTPftp
47Permittcp22.118.128.76AnyAnyftp
48Permittcp22.118.128.76AnyAny8080
49Permittcp22.118.128.76AnyAnywww
50Permittcp22.118.128.73AnyAnysmtp
51Permittcpsymantec1AnyAnysmtp
52Permittcp22.118.128.155Any195.229.49.177https
53Permittcp22.118.128.155Any195.229.49.1778080
54Permittcp22.118.128.193Any22.12.169.13564020 - 64021
55Permittcp22.118.128.194Any22.12.169.13564020 - 64021
56Permittcp22.118.128.157Any62.149.71.137ftp
57Permittcp22.118.128.157Any192.100.121.128080
58Permittcp22.118.128.157Any192.100.121.12citrix-ica
59Permitudp22.118.128.157Any192.100.121.121604
60Permiticmp22.118.128.68Any22.138.47.100Any
61Permiticmpcache1-outAny22.138.47.100Any
62Permitudp22.118.128.68Any22.138.47.100Any
63Permitudpcache1-outAny22.138.47.100Any
64PermittcpIntGroupHostAny192.168.219.53https
65PermittcpIntGroupHostAny192.135.250.12https
66PermittcpIntGroupHostAny64.103.36.134https
67PermittcpIntGroupHostAny192.135.250.12ftp
68Permitip22.118.128.158Any13.86.133.55Any
69Permittcp10.32.88.210Any22.162.134.909009
70Permittcp22.118.128.100Any22.138.47.1008080
71Permittcp22.118.128.155Any192.229.49.1778080
72Permittcp22.118.128.155Any192.229.49.177https
73Permittcp8.2.250.250Any22.118.128.68telnet
74Permitudp8.2.250.250Any22.118.128.6823
75Permittcp8.2.250.250Any22.118.128.688081
76Permitudp8.2.250.250Any22.118.128.688081
77Permittcp8.2.250.250Any22.118.128.69telnet
78Permitudp8.2.250.250Any22.118.128.6923
79Permittcp8.2.250.250Any22.118.128.698081
80Permitudp8.2.250.250Any22.118.128.698081
81Permittcp172.20.238.77Anyebillsqlnet
82Permitudp172.20.238.77Anyebill1521
83Permitesp22.118.128.162AnySCR1588-87_dAny
84Permitudp22.118.128.162AnySCR1588-87_disakmp
85Permitudp22.118.128.162AnySCR1588-87_d10000
86Permitip22.118.128.162Any192.245.235.140Any
87Permittcp22.118.128.165Any192.6.126.144https
88Permittcp22.118.128.166Any62.149.71.137ftp
89Permittcp22.118.128.143Any64.94.50.84ftp
90Permittcp22.118.128.164Any192.170.19.51ftp
91Denyip10.32.15.235AnyAnyAny
92Permittcp22.118.128.226Any22.118.128.661645
93Permittcp22.118.128.226Any22.118.128.661646
94Permittcp22.118.128.226Any22.118.128.671646
95Permittcp22.118.128.226Any22.118.128.671645
96Permittcp22.118.128.163Any22.118.133.1338080
97Permittcp22.118.128.163Any22.118.133.1378080
98Permittcp22.118.128.163AnyABCNetP8080
99Permittcp22.118.128.163Any22.118.133.1408080
100Permiticmp22.118.128.164Anyscr2160_dAny
101Permiticmp22.118.128.164Anyscr2160_dAny
102Permittcp22.118.128.91AnyAnywww
103Permittcp22.118.128.91AnyAnyhttps
104Permittcp22.118.128.108Any207.46.197.119www
105Permiticmp22.118.128.164Anyscr2160_dAny
106Permiticmp22.118.128.164Anyscr2160_dAny
107Permitudpcache1-outAnyAny2000 - 2001
108Permitudpcache2-outAnyAny2000 - 2001
109Permitudpcache1-outAnyAny5005
110Permitudpcache2-outAnyAny5005
111Permitudpcache1-outAnyAny5000
112Permitudpcache2-outAnyAny5000
113Permitudpcache1-outAnyAny1755
114Permitudpcache2-outAnyAny1755
115Permitudpcache1-outAnyAny1024
116Permitudpcache2-outAnyAny1024
117Permittcpcache1-outAnyAnywww
118Permittcpcache1-outAnyAny1755
119Permittcpcache1-outAnyAny554
120Permittcpcache2-outAnyAny554
121Permittcpcache2-outAnyAny1755
122Permittcpcache2-outAnyAnywww
123Permittcpscr05-01-1581_sAny22.118.128.91scr05-01-1581_p
124Permittcp22.118.128.182Any22.119.64.11ftp
125Permittcp22.118.128.182Any22.93.192.102ftp
126Permittcp22.118.128.170AnyAny9008 - 9009
127Permittcp22.118.128.163AnyAny9008
128Permittcp22.118.128.163AnyAny9009
129Permittcp22.118.128.163Anyescr1214_d9006
130Permiticmp22.118.128.164Anyscr2160Any
131Permiticmp22.118.128.164Anyscr2160Any
132Permiticmp22.118.128.164Anyscr2160Any
133Permitudp22.118.128.164Anyscr2160snmp - snmptrap
134Permitudp22.118.128.164Anyscr21601050 - 1075
135Permitudp22.118.128.185Any22.118.128.226snmp
136Permiticmp172.20.10.8 / 255.255.255.252Any22.118.128.22Any
137Permiticmp172.20.10.8 / 255.255.255.252Any22.118.128.21Any
138Permittcp172.20.10.8 / 255.255.255.252Any22.118.128.22161 - 162
139Permittcp172.20.10.8 / 255.255.255.252Any22.118.128.22telnet
140Permittcp172.20.10.8 / 255.255.255.252Any22.118.128.21telnet
141Permittcp172.20.10.8 / 255.255.255.252Any22.118.128.21161 - 162
142Permitudpescr2129_sAnyescr2129_dsnmp
143Permitudp22.118.128.164Any22.118.128.21snmp
144Permittcpescr2689_sAnyescr2689_dhttps
145Permitudp22.118.128.164Any22.118.128.22snmp
146Permittcpescr2812_sAnyescr2812_descr2812_p
147Permittcpescr2812_dAnyescr2812_sescr2812_p
148Permittcp22.118.133.156Any22.93.192.22ftp
149Permittcp22.118.128.156Any22.93.192.22ftp
150Permittcpescr-3243_sAny22.118.128.24www
151Permittcpcache1-outAnyAnyhttps
152Permittcpcache2-outAnyAnyhttps
153Permittcp22.118.128.159Any12.151.162.110https
154Permittcp22.118.128.167Any12.151.162.110https
155Permittcp22.118.128.176Any12.151.162.110https
156Permittcp12.151.162.110Any22.118.128.15955012
157Permittcpescr-4463_sAnyescr-4463_ddomain
158Permitudpescr-4463_sAnyescr-4463_ddomain
159Permittcpescr-4463_dAnyAnydomain
160Permitudpescr-4463_dAnyAnydomain
161Permittcpescr-4466_sAnyescr-4466_d2002 - 2010
162Permittcpescr-4466_s1Anyescr-4466_d1645 - 1646
163Permitudpescr-4466_s1Anyescr-4466_dradius - radius-acct
164Permitudpescr-4466_sAnyescr-4466_d2002 - 2010
165Permitudpescr-4466_dAnyescr-4466_d1389
166Permittcpescr-4466_dAnyescr-4466_d1ldap
167Permittcpescr4979_sAny12.151.162.162https
168Permittcpescr4979_sAny12.151.162.110https
169Permittcp10.33.18.160Any22.118.128.64 / 255.255.255.192escr5723_p
170Permittcpescr5723_sAnycache2-outftp
171Permittcpescr5723_sAnycache1-outftp
172Permittcp22.118.128.96Any22.135.137.194ftp
173Permittcpescr5723_sAnycache2-outssh
174Permittcpescr5723_sAnycache1-outtelnet
175Permittcpescr5723_sAnycache1-out8080
176Permittcpescr6337_sAny172.20.39.1957777
177Permittcpescr5723_sAny22.118.128.64 / 255.255.255.192escr5723_p
178Permittcpescr7540_sAnyescr7540_descr7540_p
179Permittcp22.118.129.23Any62.149.71.1ftp-data - ftp
180PermittcpAnyAny22.118.128.11011001
181Permittcpescr6970_sAny62.149.71.55escr6970_p
182PermitudpAnyAny22.118.128.11011001
183Permitip10.32.8.90AnyAnyAny
184Permitip10.32.8.94AnyAnyAny
185Permittcpsymantec3Anyescr7069_descr7069_p
186Permitudpsymantec3Anyescr7069_descr7069_p1
187Permittcp22.32.88.210Anyescr7197_descr7197_p
188Permittcpescr7765_sAnyescr7765_descr7765_p
189Permittcp22.118.128.83Any10.162.14.200escr7880_p
190Permittcp22.118.128.84Any10.162.14.200escr7880_p
191PermittcpwebmailAny10.162.14.200escr7880_p
192Permittcp22.118.128.187Any13.130.50.2535151
193Permiticmpescr8063_dAnyescr8063_sAny
194Permiticmpescr8063_dAnyescr8063_sAny
195Permiticmpescr8063_sAnyescr8063_dAny
196Permiticmpescr8063_sAnyescr8063_dAny
197Permitudp172.0.0.0 / 255.0.0.0Any22.118.128.24www
198Permitudp22.118.128.102AnyAnyescr8271_p
199Permittcp22.118.128.102AnyAnyescr8271_p
200Permittcp172.0.0.0 / 255.0.0.0Any22.118.128.24www
201Permiticmp10.245.1.5Any22.118.128.102Any
202Permittcp10.32.2.71Any22.118.128.102161
203Permittcp10.32.2.71Any22.118.128.102162
204Permittcp10.32.2.72Any22.118.128.102161
205Permittcp10.32.2.72Any22.118.128.102162
206Permittcp172.20.12.13Any22.118.128.102www
207Permittcp172.20.12.13Any22.118.128.10210198
208Permittcp172.20.12.13Any22.118.128.10210319
209Permittcp22.118.128.102Any10.32.0.71161
210Permittcp22.118.128.102Any10.32.0.71162
211Permittcp22.118.128.102Any10.32.0.72161
212Permittcp22.118.128.102Any10.32.0.72162
213Permittcp22.118.128.102Any172.20.12.13www
214Permittcp22.118.128.102Any172.20.12.1310198
215Permittcp22.118.128.102Any172.20.12.1310319
216Permittcp12.151.162.162Any22.118.129.4155011 - 55012
217Permittcp12.151.162.162Anyescr8241_d55011 - 55012
218Permittcpescr8384_sAny172.20.39.1957777
219Permittcp22.118.128.188Any22.118.154.29www
220PermittcpAymaAnyAnyhttps
221Permittcp10.255.255.67AnyAyma57001
222Permittcp10.255.255.69AnyAyma57001
223Permittcpsymantec3Any22.118.129.2531645 - 1656
224Permittcpsymantec4Any22.118.129.2531645 - 1656
225Permittcp172.20.239.7AnyAnyescr8764_p
226Permitudp172.20.239.7AnyAnyescr8764_p1
227PermitudpAnyAny172.20.239.7escr8764_p1
228PermitudpAnyAnyintranetescr8793_p3
229PermittcpAnyAnyintranetescr8793_p1
230Permittcpescr8740_sAny22.118.154.29www
231PermittcpAnyAny172.20.239.7escr8764_p
232Permittcp10.33.7.223Any13.130.50.2535151
233Permittcpescr8784_sAnyescr8784_d626
234Permitudpescr8784_sAnyescr8784_d626
235Permittcpescr8855_sAnysymantec45555
236Permitudpescr8855_sAnysymantec45555
237Permitudpescr8784_sAnyescr8784_d636
238Permitudp22.118.128.101AnyAnyAny
239Permittcp22.118.128.101AnyAnyAny
240PermitudpintranetAnyAnyescr8931_p2
241Permittcp22.118.128.101AnyAnysmtp
242PermittcpintranetAnyAnyescr8931_p1
243Permittcpescr8784_sAnyescr8784_dldaps
244PermitipAnyAny22.118.128.102Any
245Permitip22.118.128.102AnyAnyAny
246Permitudpsymantec4Anyescr9020_d5555
247Permittcp22.118.128.186Any193.110.54.7047
248Permittcp22.118.128.186Any193.110.54.70pptp
249Permittcpsymantec4Anyescr9020_d5555
250Permitip22.118.128.186Any193.110.54.70Any
251Permitgre10.32.9.210Any193.110.54.70Any
252Permittcpescr9332_sAnyAnywww
253Permitgre193.110.54.70Any10.32.9.210Any
254DenyipAnyAnyAnyAny
 

3.7. Protocol Inspection

Cisco firewall devices are capable of inspecting protocol traffic such as Domain Name System (DNS), HTTP and Simple Mail Transfer Protocol (SMTP). This allows traffic to be filtered based on the protocol and can prevent a number of attacks. For example, the SMTP filter can prevent certain SMTP commands from being executed.
 
Table 11: Protocols inspected
Protocol Inspect Option
dnsYes maximum-length 512
ftpYes 21
h323Yes h225 1720
h323Yes ras 1718-1719
httpYes 80
ilsYes 389
pptpYes 1723
rshYes 514
rtspYes 554
sipYes 5060
sipYes udp 5060
skinnyYes 2000
smtpYes 25
sqlnetYes 1521
tftpYes 69
 

3.8. Object Groups

Cisco object groups can be used to group items such as IP addresses, services and protocols. Object groups can be used with any Cisco security appliance command and the command will be effective for all members of the group, this can significantly simplify the devices configuration. Furthermore, object groups can be members or other object groups. There are different types of object group:
 
Table 12: Service object group Internet-MIS
Object Type Object
Port500
Portwww
Port51
Port50
Port443
 
Table 13: Network object group ipass
Object Type Object
Host26.239.102.125
Host26.239.111.125
Host26.239.108.125
Host26.239.110.125
Host26.239.105.125
Host26.239.104.125
Host26.239.101.125
Host26.239.99.125
Host26.239.98.125
Host26.239.109.125
Host26.239.103.125
Host26.239.107.125
Host8.22.202.21
 
Table 14: Network object group scr792_s
Object Type Object
Host7.66.127.242
Host7.68.127.242
Host7.70.127.242
Host7.66.127.243
Host7.68.127.243
Host7.73.127.243
 
Table 15: Network object group SCR1588-87_d
Object Type Object
Host192.245.235.140
Host192.245.235.141
Host192.245.235.142
Host13.190.149.130
Host13.190.149.131
Host13.190.149.132
 
Table 16: Network object group tada_d
Object Type Object
Host22.162.134.90
Host22.162.130.91
Host22.162.150.90
 
Table 17: Network object group scr2160_d
Object Type Object
Host22.118.136.198
Host22.118.133.137
HostABCNetP
Host22.118.133.140
Host22.118.133.133
Host22.118.136.54
 
Table 18: Service object group scr2160_p
Object Type Object
Port0
Port8
Port17
Port18
 
Table 19: Network object group scr1444_d
Object Type Object
Host13.192.128.141
Host13.132.59.15
 
Table 20: Network object group scr05-01-1685_d
Object Type Object
Host10.100.1.220
Host10.102.1.223
Host10.104.1.223
Host10.106.1.224
Host10.108.1.4
Host10.110.1.222
Host10.112.1.222
Host10.114.1.222
Host10.160.11.220
Host10.162.1.223
Host10.164.1.222
Host10.166.1.224
Host10.168.1.222
Host10.32.193.110
Host10.32.2.100
Host10.32.2.103
Host10.32.2.107
Host10.32.2.108
Host10.32.2.110
Host10.32.2.112
Host10.34.18.223
Host10.36.1.222
Host10.38.1.221
Host10.45.2.223
Host10.45.20.225
Host10.46.1.220
Host10.96.77.12
Host10.98.1.222
Host172.20.237.22
 
Table 21: Network object group scr05-01-1685_s
Object Type Object
Host22.118.128.110
Host22.118.128.111
Host22.118.128.112
 
Table 22: Service object group scr05-01-1685_p
Object Type Object
Port135
Port1024 - 65535
 
Table 23: Network object group scr05-01-1581_s
Object Type Object
Host10.32.219.30
Host10.32.219.62
 
Table 24: Service object group scr05-01-1581_p
Object Type Object
Portwww
Port8080
 
Table 25: Network object group scr2160
Object Type Object
Host22.118.128.235
Host22.118.128.236
Host22.118.128.4
Host22.118.128.5
Host22.118.128.232
Host22.118.128.225
Host22.118.128.226
 
Table 26: Network object group exchange
Object Type Object
Host22.118.128.83
Host22.118.128.84
Hostwebmail
 
Table 27: Network object group escr2129_s
Object Type Object
Host172.20.10.54
Host172.20.4.80
 
Table 28: Network object group escr2129_d
Object Type Object
Host22.118.128.21
Host22.118.128.22
Host22.118.128.225
Host22.118.128.226
 
Table 29: Network object group escr2689_s
Object Type Object
Hostcache2-out
Hostcache1-out
 
<
Table 30: Network object group escr2689_d
Object Type Object
Host22.118.133.80
Host