Go Telepresence
Telepresence Application | Telepresence

Cisco CBAC  The Poor Mans Firewall

Telepresence Today Telepresence Today Telepresence Today

DVE Telepresence | Digital Video Enterprises Telepresence Products Advertise your banner on over 300+ Telepresence related domains and over 7,000 Telepresence industry web pages here

Telepresence News and Events October, 2008

WOW! What an amazing month for the Telepresence Industry! First off, did anyone see the Cisco TelePresence Human Network commercials that are airing during this seasons NFL Football games? A great sign that public adoption of Telepresence is near.

In other news from the 24/7 Telepresence Breaking News reel at the Telepresence Forum, BT announced that they’ve launched their inter-company Telepresence solution, Proctor & Gamble implemented new Telepresence rooms, Polycom received a “Rising Star” for their innovations and Verizon Teamed with Cisco to offer new productivity enhancing services using Cisco’s collaboration portfolio. Did I mention this was just a few of the Telepresence highlights from this past week? Hundreds of Telepresence news articles hit the wire this last month, and if the past is any indication of the future, we’ll see those Telepresence news posts double by Spring 2009.

I also noticed that companies like Digital Video Enterprises, Telepresence Options and of course our Telepresence Forum were listed in the Open Directory Project at www.DMOZ.org. Pretty big news considering Telepresence didn’t exist, or even have a category just a month ago or so in the human edited ODP.

Our website traffic amongst our 345+ Telepresence related domains has tripled since early August, another indication that Telepresence is getting ready to explode onto Main Street. People are “hearing” of it, people are “researching” it, and once they’ve performed their due diligence, they’ll “see and feel” what the pioneers of the Telepresence industry have been saying. Telepresence is near; Telepresence is here.

Well that’s it for now Readers. We hope you stop by the Telepresence Forum to learn a little about what the differences between plain old video conferencing and Telepresence are. C'mon by, sign up (free by the way), watch a Telepresence video or two, and drop us a line or comment with your Telepresence thoughts and experiences.

Take care , hope to see you on the Forum!

Your Editor and Administrator - L II
"Ride on the Next Plane of Existence" TM

It's Free to Register at the Telepresence Forum Telepresence Forum - Free User Discussion Forum - Anything & Everything Telepresence


Telepresence Forum
Free user discussion forum for anything & everything telepresence related.  Learn about this new state-of-the-art immersive technology, view new product videos, and keep up to date on relevant 24/7 breaking telepresence news on the Telepresence Forum.

300+ Telepresence Industry Domain Names for Sale or Lease
300+ high-traffic, quality "telepresence" related domain names for sale or lease.  Developed websites included.  Single domain or multiple "bundled" options available from L II, Inc.

CBAC Overview The Cisco IOS Firewall Feature Set is a module that can be added to the existing IOS to provide firewall functionality without the need for hardware upgrades. There are two components to the Cisco IOS Firewall Feature Set in Intrusion Detection (which is an optional bolt-on) and Context-Based Access Control (CBAC). CBAC maintains a state table for all of the outbound connections on a Cisco router by inspecting tcp and udp connections at layer seven of the OSI model and populating the table accordingly. When return traffic is received on the external interface it is compared against the state table to see if the connection was originally established from within the internal network, and then either permitted or denied. Although basic this is a very effective mechanism to prevent unauthorized access to the internal network from external sources such as the internet.

CBAC Application-specific support

Cisco have also built in some additional functionality into CBAC in terms of application-specific inspection that enables the router to recognize and identify application specific data flows such as HTTP, SMTP, TFTP, and FTP. Understanding these applications and their data flows empowers the router to identify malformed packets or suspect application data flows and permit or deny accordingly. CBAC also provides the flexibility of downloading Java code from trusted sites, but it denying untrusted sites.

CBAC and Denial of Service (DOS) Attacks

Denial-Of-Service (DOS) attack protection is also in-built with real-time logging of alerts as well as pro-active responses to mitigate the threat. To do this CBAC can be configured to manage half-open TCP connections which are used in TCP SYN flood attacks to overload a targets resources resulting in a denial of service to legitimate users. To do this CBAC uses timeouts and thresholds, which are configurable, to determine how long state information for each connection should be kept for sessions and when to drop them. Note that UDP and ICMP require that an idle-timer limit is used to determine when a connection should be terminated. A very useful command to identify a DOS attack is ip inspect audit-trail which logs all DOS connections including source and destination IP address and TCP or UDP ports allowing you to pin-point the exact source and destination of the attack.

Configuring CBAC

There are five steps to configuring CBAC on a Cisco router in order for it to function correctly. These are as follows: 1. Choose an interface to which inspection will be applied. This can be an internal or external interface as CBAC is only concerned with the direction of the first packet initiating the connection which is identified when applying CBAC to an interface. 2. Configure an IP access list in the correct direction on the selected interface to allow traffic through for CBAC to inspect. 3. Configure global timeouts and thresholds for established connections or sessions. 4. Define an inspection rule specifying exactly which protocols will be inspected by CBAC. 5. Apply the inspection rule to the interface in the correct direction.

Nicholas Evra is a Senior IT Consultant for a Professional Services IT Organisation based in London, UK. As well as designing and developing network and security solutions for clients, Nicholas also regularly contributes technical tips and articles on Networkblue.net. Networkblue.net is a technical resource for novices and experts alike providing free articles and tips on numerous cisco topics such as Ciscos CBAC and other network security topics. For more visit http://www.networkblue.net and http://www.networkblue.net/cisco/security

Custom Search

To learn more about Telepresence, the revolutionary new style of immersive video conferencing; visit these websites:

Telepresence Today - Telepresence information and editor qualified headline news

On Telepresence - Information, videos and fact sheets "on Telepresence"

Telepresence 101 - All Telepresence, all the time. Telepresence 101

Telepresence.cc - Telepresence vs. Video Conferencing

Go Telepresence! - "Ride on the Next Plane of Existence" - Go Telepresence!

Telepresence Report - 24/7 breaking Telepresence related news and information



Bookmark Telepresence Forum


Privacy Policy | Copyright/Trademark Notification