Section 6.0: IOS Firewall Configuration (8 points)

6.1. Context-Based Access Control (CBAC) (4 points)

  1. Configure the firewall on R5 for all traffic going to the Internet. Configure the ingress ACL on the Internet link to protect from RFC1918.

  2. Modify settings such that TCP and UDP idle-time are 30 minutes and 15 seconds, respectively.

  3. Configure the firewall to start deleting TCP/UDP half-open sessions at 1000, and continue to delete until the connection drops to 800 sessions.

6.2. Proxy Authentication (4 points)

  1. Configure R6 for proxy authentication for users in VLAN-14 to a web server behind PIX.

  2. Configure inbound ACL on R6 VLAN-6 interface (Ethernet1/0) to download per-user auth-proxy ACL from the AAA server.

  3. Configure R8 with HTTP service to act ...

Get CCIE Security Practice Labs now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.