Access Control Lists in Linux¶
Many router operating systems run on top of Linux. This means that in some instances, the router OS is an overlay for functionality that is in actuality implemented in Linux functions. FRR (Free Range Routing), for instance, only carries Control Plane functionality, while the Data-plane of the router is handled in the underlying Linux system. Access Control Lists (ACL) is a functionality that is implemented in the data-plane, as there is no automatic generation or logic operating the access control lists. Due to FRR missing functionality for generating or handling ACLs, we must implement the ACLs in the Linux Terminal of the router. In GNS3, the Linux terminal can be access by right-clicking the router and selecting "Auxillary Console". This should open a terminal/telnet window with a somewhat default-looking Linux terminal.
One caveat of using ACLs in the linux terminal in the TTM4240 lab (docker based) is that the configurations aren't default persistant. For the lab, persistance isn't necessary, as the tasks that require ACLs can be done, documented and don't need to persist for the rest of the lab.
To configure ACLs, we use the linux-tool "iptables". iptables has a rich amount of instructions, but for brevity sake, we've provided the following example commands:
FRR Commands¶
Setting default policies:
Blocking or accepting a source or destination (respectively) for packets incoming on a set interface (ethX):
iptables -A FORWARD -i ethX -s 10.0.0.0/8 -j DROP/ACCEPT
iptables -A FORWARD -i ethX -d 192.168.0.0 -j DROP/ACCEPT
ACLs can also be set to be active on outgoing interfaces, as well as a combination of input and output:
iptables -A FORWARD -o ethX -s 123.213.13.0/24 -d 111.222.121.0/24 -j DROP
iptables -A FORWARD -i eth0 -o eth1 -d 8.8.8.8 -j DROP
ACLs in IP-tables can also be used to block specific layer 4 ports:
Setting Defaults¶
If there are pre-existing iptables rules that may block setting you own iptable rules, you may have to flush pre-existing configurations and defining new defaults:
iptables -F
iptables -X
iptables -P INPUT DROP #Sets a default behaviour to drop packets going to the router.
iptables -P FORWARD ACCEPT #Sets a default allow on forwarding of packets (packets going through the router)
iptables -P OUTPUT ACCEPT #Sets a default allow for outgoing packets from the router.
VyOS Commands¶
Where packets are evaluated¶
VyOS has three base chains, and choosing the right one is most of the work:
| Chain | Traffic it sees |
|---|---|
input |
addressed to the router itself — including its loopback |
forward |
passing through the router |
output |
originated by the router |
An ACL that protects a network behind the router belongs in forward. An ACL that also
protects the router's own addresses needs input as well. If you only configure one of
them, half your traffic is still getting through.
Rule structure¶
set firewall ipv4 <chain> filter rule <number> action 'drop'
set firewall ipv4 <chain> filter rule <number> inbound-interface name '<interface>'
set firewall ipv4 <chain> filter rule <number> source address '<prefix>'
set firewall ipv4 <chain> filter rule <number> destination address '<prefix>'
All the conditions in one rule must match for the rule to apply. Rules are evaluated in ascending number order and the first match decides the packet's fate. Anything that matches no rule is accepted.
Useful actions: drop discards silently, reject sends an ICMP error back, accept permits.
Example¶
Drop traffic arriving on eth3 from 192.168.0.0/24 and headed for 100.1.0.0/24, both when
it passes through the router and when it is addressed to the router itself:
configure
set firewall ipv4 forward filter rule 10 action 'drop'
set firewall ipv4 forward filter rule 10 inbound-interface name 'eth3'
set firewall ipv4 forward filter rule 10 source address '192.168.0.0/24'
set firewall ipv4 forward filter rule 10 destination address '100.1.0.0/24'
set firewall ipv4 input filter rule 10 action 'drop'
set firewall ipv4 input filter rule 10 inbound-interface name 'eth3'
set firewall ipv4 input filter rule 10 source address '192.168.0.0/24'
set firewall ipv4 input filter rule 10 destination address '100.1.0.0/24'
commit
save
commit activates the rules. save writes them to disk.
Checking your work¶
Reference¶
VyOS 1.4 (sagitta) firewall documentation: https://docs.vyos.io/en/sagitta/configuration/firewall/ipv4.html