Techerest

Cisco Zone-Based Firewall (ZBF): Zone, Zone Pair และ Stateful Inspection

Cisco Zone-Based Firewall หรือ ZBF เป็นแนวทางสร้าง Stateful Firewall Policy โดยแบ่ง Network Interface ออกเป็น Security Zone แล้วกำหนดว่า Traffic ระหว่าง Zone ใด สามารถผ่านได้ และต้องถูก Inspect, Pass หรือ Drop อย่างไร

บทความนี้จะต่อยอดจากความรู้เรื่อง ACL, NAT และ Stateful Firewall เข้าสู่การสร้าง Firewall Policy บน Cisco Router ด้วย Zone, Zone Pair, Class Map, Policy Map และ Service Policy พร้อม Lab สำหรับ LAN ออก Internet และแนวทาง Troubleshooting อย่างเป็นระบบ

ภาค 1: พื้นฐาน Cisco Zone-Based Firewall

Cisco Zone-Based Firewall คืออะไร?

Zone-Based Firewall (ZBF) เป็น Firewall Framework บน Cisco IOS/IOS XE บาง Platform ที่ใช้แนวคิด Security Zone แทนการพิจารณา Interface แบบแยกส่วนเพียงอย่างเดียว

ตัวอย่าง:

LAN
 |
 v
INSIDE Zone
 |
 |
 v
+----------------+
| Cisco Router   |
|      ZBF       |
+----------------+
 |
 |
 v
OUTSIDE Zone
 |
 v
Internet

แทนที่จะคิดเพียงว่า Traffic เข้าทาง Interface ไหน และออกทาง Interface ไหน เราสามารถกำหนด Security Policy ในรูป:

INSIDE
   |
   | Security Policy
   v
OUTSIDE

ทำไมต้องใช้ Zone-Based Firewall?

Network องค์กรมักไม่ได้มีเพียง LAN และ Internet แต่สามารถมีหลาย Security Segment เช่น:

                INTERNET
                    |
                    |
                OUTSIDE
                    |
                    v
              +-----------+
              |   Router  |
              |    ZBF    |
              +-----------+
               /    |    \
              /     |     \
             v      v      v
          INSIDE   DMZ    GUEST

แต่ละ Zone อาจต้องมี Security Policy แตกต่างกัน

ตัวอย่าง:

Source Destination Policy ตัวอย่าง
INSIDE OUTSIDE อนุญาต Web/DNS ตาม Policy
OUTSIDE INSIDE ไม่อนุญาต Connection ใหม่โดยทั่วไป
OUTSIDE DMZ อนุญาตเฉพาะ Public Services ที่จำเป็น
GUEST INSIDE Drop
GUEST OUTSIDE อนุญาต Internet ตาม Policy

นี่คือแนวคิด Zone Segmentation ซึ่งช่วยให้ Security Policy สัมพันธ์กับบทบาทของ Network ได้ชัดเจนขึ้น

ภาค 2: Zone และ Zone Pair

Security Zone คืออะไร?

Zone คือ Logical Security Group ที่ใช้จัดกลุ่ม Interface ซึ่งมีบทบาทหรือระดับความเชื่อถือ ใกล้เคียงกัน

ตัวอย่างสร้าง Zone:

zone security INSIDE
zone security OUTSIDE

จากนั้นนำ Interface เข้า Zone:

interface GigabitEthernet0/0
 zone-member security INSIDE

interface GigabitEthernet0/1
 zone-member security OUTSIDE

Topology:

192.168.10.0/24

      |
      |
    Gi0/0
      |
  [INSIDE]
      |
      v
+-------------+
| Cisco Router|
+-------------+
      |
  [OUTSIDE]
      |
    Gi0/1
      |
      v
     ISP
เมื่อ Interface ถูกนำเข้า Security Zone พฤติกรรม Traffic ระหว่าง Zone จะเปลี่ยนตาม ZBF Policy ดังนั้นการ Deploy บน Production ต้องวาง Policy และ Rollback Plan ก่อนเปลี่ยน Zone Membership เพื่อหลีกเลี่ยงการตัด Traffic ที่ใช้งานอยู่

Traffic ภายใน Zone เดียวกัน

Interface ที่เป็นสมาชิก ของ Zone เดียวกัน โดยหลักสามารถสื่อสารกันได้ โดยไม่ต้องสร้าง Zone Pair ระหว่าง Zone เดียวกัน

Gi0/0
  |
  +--- INSIDE
  |
Router
  |
  +--- INSIDE
  |
Gi0/2

แต่ Routing, ACL และ Feature อื่น ยังสามารถมีผลต่อ Traffic ได้ตาม Configuration

Zone Pair คืออะไร?

การมี Zone เพียงอย่างเดียว ยังไม่เพียงพอ หากต้องการกำหนด Policy ระหว่างสอง Zone

ต้องสร้าง Zone Pair เพื่อระบุ:

SOURCE ZONE
     |
     v
DESTINATION ZONE

ตัวอย่าง:

zone-pair security INSIDE-TO-OUTSIDE source INSIDE destination OUTSIDE

ความหมาย:

INSIDE
   |
   |
   v
OUTSIDE

Zone Pair นี้ควบคุม Traffic ที่เริ่มจาก INSIDE และมุ่งไป OUTSIDE

Zone Pair มีทิศทาง

นี่เป็นแนวคิดสำคัญของ ZBF:

INSIDE -> OUTSIDE

is not the same as

OUTSIDE -> INSIDE

ตัวอย่าง:

zone-pair security INSIDE-TO-OUTSIDE
 source INSIDE
 destination OUTSIDE

ไม่ได้หมายความว่า มี Policy สำหรับ Connection ใหม่ที่เริ่มจาก OUTSIDE ไป INSIDE โดยอัตโนมัติ

หาก Traffic จาก INSIDE ถูก inspect Stateful Firewall สามารถติดตาม Session และอนุญาต Return Traffic ที่สัมพันธ์กับ Session นั้น ตาม State ที่สร้างไว้ โดยไม่จำเป็นต้องสร้าง Reverse Zone Pair เพียงเพื่อ Return Traffic ของ Session ที่ถูก Inspect

ภาค 3: Inspect, Pass และ Drop

ZBF มี Action อะไรบ้าง?

Action หลักที่ควรเข้าใจคือ:

Action ความหมายเชิงแนวคิด Stateful
Inspect อนุญาต Traffic และสร้าง/ติดตาม Session State ใช่
Pass อนุญาต Traffic ผ่านโดยไม่สร้าง Inspection State แบบ Inspect ไม่เหมือน Inspect
Drop ทิ้ง Traffic ไม่เกี่ยวข้อง

Inspect

ตัวอย่าง:

INSIDE
192.168.10.10
      |
      | HTTPS
      v
     ZBF
      |
      | inspect
      v
   INTERNET

เมื่อ Traffic Match Policy ที่กำหนด Action เป็น inspect Firewall สามารถสร้าง State สำหรับ Session นั้น

เมื่อ Response กลับมา:

Internet Server
      |
      | Return Traffic
      v
     ZBF
      |
      | Existing State
      v
INSIDE Client

Pass

pass ใช้อนุญาต Traffic ให้ผ่าน Zone Pair แต่ไม่ได้ให้ Stateful Inspection ในลักษณะเดียวกับ inspect

Traffic
   |
   v
  PASS
   |
   v
Allowed through

No inspect state

ดังนั้น Return Traffic อาจต้องมี Policy รองรับในทิศทางกลับ ตาม Design

Drop

drop ใช้ปฏิเสธ Traffic

Traffic
   |
   v
 DROP
   |
   X

ในบาง Configuration สามารถเปิด Logging สำหรับ Traffic ที่ถูก Drop เพื่อช่วย Troubleshooting ได้

ภาค 4: Class Map, Policy Map และ Service Policy

Class Map คืออะไร?

Class Map ใช้กำหนดว่า Traffic ประเภทใด จะเข้า Class

ตัวอย่าง:

class-map type inspect match-any CM-INTERNET
 match protocol http
 match protocol https
 match protocol dns

แนวคิด:

Incoming Traffic
      |
      v
Class Map
      |
      +-- HTTP?
      |
      +-- HTTPS?
      |
      +-- DNS?

match-any หมายถึง Match อย่างน้อยหนึ่งเงื่อนไข ใน Class Map

match-any กับ match-all

ประเภท แนวคิด
match-any Match อย่างน้อยหนึ่งเงื่อนไข
match-all ต้อง Match ทุกเงื่อนไขตาม Logic ของ Class
ชนิดของ Match Statement ที่รองรับอาจแตกต่างกัน ตาม Cisco Platform, IOS/IOS XE Release และ Firewall Feature Set ควรตรวจ Command Reference ของอุปกรณ์จริงก่อน Deploy

Policy Map คืออะไร?

Policy Map กำหนดว่า เมื่อ Traffic Match Class แล้ว ต้องทำอะไร

ตัวอย่าง:

policy-map type inspect PM-INTERNET
 class type inspect CM-INTERNET
  inspect
 class class-default
  drop

Flow:

Traffic
   |
   v
CM-INTERNET match?
   |
  YES
   |
   v
INSPECT


Traffic not matched
   |
   v
class-default
   |
   v
DROP

Service Policy ทำหน้าที่อะไร?

หลังสร้าง Class Map และ Policy Map แล้ว ต้องนำ Policy Map ไปผูกกับ Zone Pair

ตัวอย่าง:

zone-pair security INSIDE-TO-OUTSIDE
 source INSIDE
 destination OUTSIDE
 service-policy type inspect PM-INTERNET

โครงสร้าง:

Zone Pair
   |
   v
Service Policy
   |
   v
Policy Map
   |
   v
Class Map
   |
   v
Match Traffic
   |
   v
Inspect / Pass / Drop

โครงสร้าง ZBF ทั้งระบบ

INTERFACES
    |
    v
SECURITY ZONES
    |
    v
ZONE PAIR
    |
    v
SERVICE POLICY
    |
    v
POLICY MAP
    |
    v
CLASS MAP
    |
    v
TRAFFIC MATCH
    |
    v
INSPECT / PASS / DROP

หากเข้าใจ Chain นี้ จะช่วยให้การ Configure และ Troubleshoot ZBF ง่ายขึ้นมาก

ภาค 5: Cisco Zone-Based Firewall Lab

Lab: LAN ออก Internet ผ่าน ZBF

Topology:

PC-A
192.168.10.10
      |
      |
     SW1
      |
      |
    Gi0/0
 192.168.10.1
      |
   [INSIDE]
      |
+-------------+
|     R1      |
|     ZBF     |
+-------------+
      |
   [OUTSIDE]
      |
    Gi0/1
 203.0.113.2
      |
      |
     ISP
 203.0.113.1

เป้าหมาย:

  • LAN อยู่ใน INSIDE Zone
  • WAN อยู่ใน OUTSIDE Zone
  • อนุญาต HTTP, HTTPS และ DNS จาก INSIDE ไป OUTSIDE
  • ใช้ Stateful Inspection
  • Traffic อื่นใน Policy นี้ถูก Drop
  • ใช้ PAT สำหรับ Private IPv4

Step 1 — Configure Interfaces

interface GigabitEthernet0/0
 description LAN
 ip address 192.168.10.1 255.255.255.0
 ip nat inside
 no shutdown

interface GigabitEthernet0/1
 description WAN
 ip address 203.0.113.2 255.255.255.252
 ip nat outside
 no shutdown

Step 2 — Default Route

ip route 0.0.0.0 0.0.0.0 203.0.113.1

Step 3 — Configure PAT

access-list 10 permit 192.168.10.0 0.0.0.255

ip nat inside source list 10 interface GigabitEthernet0/1 overload

Step 4 — Create Security Zones

zone security INSIDE
zone security OUTSIDE

Step 5 — Create Class Map

class-map type inspect match-any CM-INTERNET
 match protocol http
 match protocol https
 match protocol dns

Class นี้ใช้ระบุ Application/Protocol ที่ต้องการ Inspect ตามความสามารถของ Platform

Step 6 — Create Policy Map

policy-map type inspect PM-INTERNET
 class type inspect CM-INTERNET
  inspect
 class class-default
  drop

Step 7 — Create Zone Pair

zone-pair security INSIDE-TO-OUTSIDE
 source INSIDE
 destination OUTSIDE
 service-policy type inspect PM-INTERNET

Step 8 — Assign Interfaces to Zones

interface GigabitEthernet0/0
 zone-member security INSIDE

interface GigabitEthernet0/1
 zone-member security OUTSIDE
บน Production Router ควรเตรียม Class Map, Policy Map และ Zone Pair ให้พร้อมก่อนนำ Interface เข้า Zone รวมถึงตรวจ Management Access และเตรียม Rollback Plan เพราะการเปลี่ยน Zone Membership อาจกระทบ Traffic ทันที

Configuration รวมของ Lab

interface GigabitEthernet0/0
 description LAN
 ip address 192.168.10.1 255.255.255.0
 ip nat inside
 zone-member security INSIDE
 no shutdown

interface GigabitEthernet0/1
 description WAN
 ip address 203.0.113.2 255.255.255.252
 ip nat outside
 zone-member security OUTSIDE
 no shutdown

ip route 0.0.0.0 0.0.0.0 203.0.113.1

access-list 10 permit 192.168.10.0 0.0.0.255
ip nat inside source list 10 interface GigabitEthernet0/1 overload

zone security INSIDE
zone security OUTSIDE

class-map type inspect match-any CM-INTERNET
 match protocol http
 match protocol https
 match protocol dns

policy-map type inspect PM-INTERNET
 class type inspect CM-INTERNET
  inspect
 class class-default
  drop

zone-pair security INSIDE-TO-OUTSIDE
 source INSIDE
 destination OUTSIDE
 service-policy type inspect PM-INTERNET
ตัวอย่างนี้ใช้เพื่ออธิบาย Architecture ของ ZBF Syntax และ Protocol Inspection Support อาจแตกต่างตาม Cisco Platform และ IOS/IOS XE Release จึงควรตรวจ Feature Support ก่อนนำ Configuration ไปใช้จริง

เมื่อ Client เปิด HTTPS เกิดอะไรขึ้น?

Client:

192.168.10.10:51000

Destination:

198.51.100.20:443

Flow เชิงแนวคิด:

PC-A
 |
 | HTTPS
 v
INSIDE Zone
 |
 v
Zone Pair
INSIDE -> OUTSIDE
 |
 v
Class Map
 |
 | HTTPS matched
 v
Policy Map
 |
 | INSPECT
 v
Firewall State
 |
 v
NAT / PAT
 |
 v
OUTSIDE
 |
 v
Internet
Diagram นี้ใช้เพื่ออธิบายความสัมพันธ์ ระหว่าง Feature เท่านั้น ไม่ควรใช้เป็นเอกสารยืนยัน Packet Processing Order ภายใน Router เพราะ NAT, ZBF, Routing และ Feature อื่น อาจมีลำดับการประมวลผลเฉพาะ Platform

เมื่อ HTTPS Response กลับมา

Internet Server
       |
       | Response
       v
OUTSIDE
       |
       v
ZBF Stateful Inspection
       |
       | Existing session?
       |
      YES
       |
       v
INSIDE
       |
       v
PC-A

นี่คือความแตกต่างสำคัญ ระหว่าง inspect กับ Packet Filtering แบบ Stateless

ภาค 6: ZBF กับ NAT/PAT

ZBF ทำงานร่วมกับ NAT อย่างไร?

ZBF และ NAT ทำหน้าที่คนละด้าน

ZBF
 |
 +-- Security Policy
 +-- Stateful Inspection


NAT / PAT
 |
 +-- Address Translation
 +-- Port Translation

ตัวอย่าง:

192.168.10.10:51000
       |
       | Security Policy
       v
      ZBF
       |
       | Translation
       v
      PAT
       |
       v
203.0.113.2:30001

ทั้งสอง Feature สามารถอยู่บน Router เดียวกันได้ แต่ไม่ควรตีความว่า ZBF แทน NAT หรือ NAT แทน ZBF

ถ้ามี INSIDE → OUTSIDE Zone Pair แล้ว Internet เข้า LAN ได้หรือไม่?

สำหรับ Connection ใหม่ ที่เริ่มจาก OUTSIDE:

OUTSIDE
   |
   | New connection
   v
INSIDE

Zone Pair INSIDE-TO-OUTSIDE ไม่ได้เป็น Policy สำหรับ Connection ใหม่ในทิศทางนี้

หากมี Requirement ให้ Outside เริ่ม Connection เข้ามา ต้องออกแบบ Reverse Direction Policy อย่างชัดเจน

โดยทั่วไปไม่ควร Publish Internal LAN Host สู่ Internet โดยตรง หากมี Public Service ควรพิจารณา DMZ, Firewall Policy, NAT, Server Hardening, Patch Management และ Monitoring ตามความเหมาะสม

ภาค 7: ZBF กับ DMZ

ออกแบบ DMZ ด้วย Zone

Topology:

                    INTERNET
                        |
                    OUTSIDE
                        |
                        v
                 +-------------+
                 | Cisco Router|
                 |     ZBF     |
                 +-------------+
                   /         \
                  /           \
                 v             v
             INSIDE           DMZ
                |              |
             Users         Web Server

เราสามารถออกแบบ Policy เช่น:

Source Zone Destination Zone ตัวอย่าง Policy
INSIDE OUTSIDE Inspect Web/DNS
INSIDE DMZ อนุญาตเฉพาะ Services ที่จำเป็น
OUTSIDE DMZ อนุญาต Public Service ที่กำหนด
OUTSIDE INSIDE Drop Connection ใหม่ตาม Policy
DMZ INSIDE จำกัดอย่างเข้มงวด

แต่ละ Direction สามารถใช้ Zone Pair และ Policy Map ของตนเอง

เพิ่ม Guest Zone

                 OUTSIDE
                    |
                    |
               +---------+
               |   ZBF   |
               +---------+
                /   |   \
               /    |    \
              v     v     v
          INSIDE   DMZ   GUEST

Policy ตัวอย่าง:

INSIDE -> OUTSIDE = Inspect
GUEST  -> OUTSIDE = Inspect limited services
GUEST  -> INSIDE  = Drop
OUTSIDE -> INSIDE = No unsolicited access
OUTSIDE -> DMZ    = Only required public services

แนวคิดนี้ทำให้ Network Segmentation และ Security Policy อ่านได้ชัดเจนขึ้น

ภาค 8: Self Zone

Self Zone คืออะไร?

ZBF มีแนวคิด Self Zone สำหรับ Traffic ที่มี Router เองเป็น Source หรือ Destination

ตัวอย่าง Traffic:

SSH -> Router
SNMP -> Router
Routing Protocol -> Router
ICMP -> Router
DNS generated by Router
NTP generated by Router

แนวคิด:

Network Zone
     |
     v
   Router
     ^
     |
   SELF
Self Zone Policy ต้องออกแบบอย่างระมัดระวัง เพราะอาจกระทบ Management Plane, Routing Protocol, Monitoring, NTP, DNS และบริการที่ Router ต้องใช้หรือรับโดยตรง

ก่อนแก้ Self Zone ควรระบุ Management และ Control Plane Traffic ที่จำเป็นให้ครบถ้วน

ภาค 9: ตรวจสอบ Cisco ZBF

ตรวจ Zone

show zone security

ใช้ตรวจ Security Zone และข้อมูลสมาชิก ตาม Output ที่ Platform รองรับ

ตรวจ Zone Pair

show zone-pair security

ตรวจ Source Zone, Destination Zone และ Policy ที่ผูกไว้

ตรวจ Class Map

show class-map type inspect

ตรวจ Policy Map

show policy-map type inspect

ตรวจ Firewall Policy Statistics

show policy-map type inspect zone-pair

Output สามารถช่วยตรวจ Traffic Match, Inspect, Drop และ Counters ตาม Platform/Software ที่ใช้งาน

ตรวจ Session

บน Platform/Release ที่รองรับ สามารถใช้ คำสั่ง Inspection Session ที่เกี่ยวข้อง เช่น:

show policy-map type inspect zone-pair
show platform hardware qfp active feature firewall drop
คำสั่งระดับ Platform เช่น QFP ใช้ได้เฉพาะอุปกรณ์/Architecture ที่รองรับ และ Syntax สามารถเปลี่ยนตาม IOS XE Release จึงไม่ควรใช้เป็นคำสั่ง Universal สำหรับ Cisco Router ทุกรุ่น

ตรวจ NAT ร่วมด้วย

show ip nat translations
show ip nat statistics

ตรวจ Routing:

show ip route
show ip route 0.0.0.0

ตรวจ Interface:

show ip interface brief

ภาค 10: ZBF Troubleshooting

Troubleshooting Workflow

Client Configuration
       |
       v
Interface UP?
       |
       v
Routing correct?
       |
       v
NAT correct?
       |
       v
Zone Membership?
       |
       v
Zone Pair exists?
       |
       v
Correct direction?
       |
       v
Service Policy attached?
       |
       v
Class Map matches?
       |
       v
Inspect / Pass / Drop?
       |
       v
Session created?
       |
       v
Return Path?
       |
       v
DNS / Application?

ปัญหา 1 — Interface อยู่ผิด Zone

ตรวจ:

show zone security
show running-config interface GigabitEthernet0/0
show running-config interface GigabitEthernet0/1

Topology ต้องสัมพันธ์กับ:

LAN
 |
INSIDE
 |
Router
 |
OUTSIDE
 |
WAN

ปัญหา 2 — Zone Pair กลับทิศ

ต้องการ:

INSIDE -> OUTSIDE

แต่สร้าง:

OUTSIDE -> INSIDE

Policy จะไม่ถูกใช้ กับ Traffic Direction ที่ตั้งใจ

ตรวจ:

show zone-pair security

ปัญหา 3 — Class Map ไม่ Match

หาก Policy อนุญาตเฉพาะ:

HTTP
HTTPS
DNS

แต่ทดสอบด้วย Protocol ที่ไม่ได้อยู่ใน Class:

Traffic
   |
   v
No class match
   |
   v
class-default
   |
   v
DROP

ดังนั้นการใช้ Ping เพียงอย่างเดียว ไม่สามารถสรุปได้ว่า ZBF Configuration ทั้งหมดเสีย หาก ICMP ไม่ได้ถูกอนุญาต ใน Policy ตั้งแต่แรก

ปัญหา 4 — NAT ผิด แต่คิดว่า ZBF ผิด

หาก ZBF Inspect สำเร็จ แต่ NAT ไม่ทำงาน:

ZBF
 |
 +-- Match = YES
 +-- Inspect = YES

NAT
 |
 +-- Translation = NO

Result:
Internet connectivity may fail

ตรวจ:

show ip nat translations
show ip nat statistics
show access-lists

ปัญหา 5 — ไม่มี Default Route

แม้ ZBF และ NAT ถูกต้อง:

ZBF = OK
NAT = OK
Route = Missing

      |
      v

FAIL

ตรวจ:

show ip route 0.0.0.0

ปัญหา 6 — ใช้ Pass แล้วคาดหวัง Return State

pass ไม่เท่ากับ inspect

PASS
 |
 +-- Allow traffic
 |
 +-- No inspect state


INSPECT
 |
 +-- Allow traffic
 |
 +-- Stateful inspection

หากต้องการ Stateful Return Traffic ควรเลือก Action ให้ตรงกับ Security Design

ปัญหา 7 — เปลี่ยน Zone แล้ว Remote Management หลุด

หาก Router ถูกบริหารผ่าน Network ที่กำลังเปลี่ยน Security Policy อาจกระทบ Management Traffic

ก่อน Change ควรตรวจ:

  • SSH
  • HTTPS Management
  • SNMP
  • NTP
  • Syslog
  • AAA/RADIUS/TACACS+
  • Routing Protocol
  • Monitoring System
  • Out-of-Band Management
การ Configure Firewall ผ่าน Remote Session โดยไม่มี Console, Out-of-Band Access หรือ Rollback Mechanism มีความเสี่ยงทำให้ Administrator ล็อกตัวเองออกจาก Router

ภาค 11: ZBF Best Practices

1. กำหนด Zone ตาม Security Role

ตัวอย่าง:

INSIDE
OUTSIDE
DMZ
GUEST
MANAGEMENT

หลีกเลี่ยงการสร้าง Zone จำนวนมากโดยไม่มี Security Requirement ที่ชัดเจน เพราะจะเพิ่มจำนวน Zone Pairs และ Complexity

2. เขียน Traffic Matrix ก่อน Configure

Source Destination Service Action
INSIDE OUTSIDE HTTPS Inspect
INSIDE OUTSIDE DNS Inspect
GUEST INSIDE Any Drop
OUTSIDE DMZ HTTPS ตาม Public Service Policy

3. ใช้ Least Privilege

ไม่ควรเริ่มด้วย:

Allow everything

หาก Requirement ระบุได้ว่า:

Users need:
HTTPS
DNS

Policy ควรเริ่มจาก Services ที่จำเป็น แล้วเพิ่มตาม Requirement ที่ผ่านการพิจารณา

4. เปิด Logging อย่างเหมาะสม

Logging ช่วย Troubleshooting และ Security Monitoring แต่การ Log Traffic ปริมาณมาก อาจสร้าง Load และข้อมูลจำนวนมาก

จึงควรกำหนด:

  • สิ่งที่ต้อง Log
  • Log Severity
  • Syslog Destination
  • Retention
  • Monitoring / Alerting

5. ตรวจ Counters ก่อนแก้ Configuration

ก่อนเปลี่ยน Policy ควรตรวจว่า Traffic Match Class ใดจริง

show policy-map type inspect zone-pair

หาก Counter ไม่เพิ่ม ปัญหาอาจอยู่ที่:

  • Wrong Zone Pair
  • Wrong Direction
  • Wrong Class Match
  • Routing
  • Traffic ไม่ผ่าน Router นี้

6. เปลี่ยนทีละส่วน

Production Workflow:

Capture baseline
      |
      v
Document current state
      |
      v
Prepare rollback
      |
      v
Apply one change
      |
      v
Verify
      |
      v
Monitor
      |
      v
Continue

หลีกเลี่ยงการแก้ Routing, NAT และ Firewall หลายส่วนพร้อมกัน เพราะทำให้หา Root Cause ได้ยาก

Cisco ZBF Command Cheat Sheet

Command หน้าที่
zone security NAME สร้าง Security Zone
zone-member security NAME นำ Interface เข้า Zone
class-map type inspect ... สร้าง Traffic Classification
match protocol ... Match Protocol/Application ที่รองรับ
policy-map type inspect ... สร้าง Inspection Policy
inspect Stateful Inspection
pass อนุญาตโดยไม่ Inspect แบบ Stateful
drop Drop Traffic
zone-pair security ... สร้าง Source-to-Destination Zone Pair
service-policy type inspect ... ผูก Policy Map กับ Zone Pair
show zone security ตรวจ Zone
show zone-pair security ตรวจ Zone Pair
show policy-map type inspect zone-pair ตรวจ Policy และ Counters
show ip nat translations ตรวจ NAT Translation
show ip route ตรวจ Routing

คำถามที่พบบ่อย — FAQ

ZBF ย่อมาจากอะไร?

ZBF ย่อมาจาก Zone-Based Firewall เป็น Firewall Framework ที่จัด Interface เข้า Security Zone และสร้าง Policy สำหรับ Traffic ระหว่าง Zone

Zone กับ VLAN เหมือนกันหรือไม่?

ไม่เหมือนกัน VLAN เป็นกลไก Layer 2 Segmentation ส่วน ZBF Zone เป็น Logical Security Group สำหรับ Firewall Policy

Zone Pair คืออะไร?

Zone Pair ระบุทิศทาง จาก Source Zone ไป Destination Zone เพื่อใช้ Service Policy กับ Traffic Direction นั้น

INSIDE → OUTSIDE กับ OUTSIDE → INSIDE เหมือนกันหรือไม่?

ไม่เหมือนกัน Zone Pair มีทิศทาง ดังนั้น Policy สำหรับ INSIDE ไป OUTSIDE ไม่ได้กลายเป็น Policy สำหรับ Connection ใหม่ จาก OUTSIDE ไป INSIDE โดยอัตโนมัติ

ทำไม Return Traffic ของ Inspect ไม่ต้องสร้าง Reverse Zone Pair?

เพราะ Action inspect สร้างและติดตาม Session State ทำให้ Return Traffic ที่สัมพันธ์กับ Session สามารถถูกประมวลผล ตาม Stateful Inspection

Inspect กับ Pass ต่างกันอย่างไร?

Inspect ใช้ Stateful Inspection และติดตาม Session ส่วน Pass อนุญาต Traffic โดยไม่สร้าง Inspection State แบบเดียวกับ Inspect

ZBF แทน NAT ได้หรือไม่?

ไม่ได้ ZBF จัดการ Firewall Policy และ Stateful Inspection ส่วน NAT/PAT ทำ Address Translation ทั้งสอง Feature สามารถทำงานร่วมกันได้

ZBF แทน Routing ได้หรือไม่?

ไม่ได้ แม้ Firewall Policy จะอนุญาต Traffic Router ยังต้องมี Route ไป Destination และ Return Path ต้องถูกต้อง

Ping ไม่ผ่านแปลว่า ZBF เสียหรือไม่?

ไม่เสมอไป หาก Policy ไม่ได้อนุญาต หรือ Inspect ICMP Ping สามารถถูก Drop ขณะที่ HTTPS หรือ DNS ยังทำงานตาม Policy ได้

Interface ใน Zone เดียวกันต้องมี Zone Pair หรือไม่?

โดยหลัก Traffic ระหว่าง Interface ที่เป็นสมาชิก Zone เดียวกัน สามารถสื่อสารกันได้ โดยไม่ต้องสร้าง Zone Pair ระหว่าง Zone เดียวกัน แต่ Feature อื่น เช่น ACL และ Routing ยังสามารถมีผลได้

Self Zone สำคัญอย่างไร?

Self Zone เกี่ยวข้องกับ Traffic ที่ Router เป็น Source หรือ Destination เช่น SSH, SNMP, NTP และ Control/Management Traffic จึงต้องออกแบบอย่างระมัดระวัง

ควรสร้าง Zone ก่อนหรือ Policy ก่อน?

ในการวางแผนควรกำหนด Traffic Matrix และ Policy ให้ชัดเจนก่อน และใน Production ควรเตรียม Configuration กับ Rollback Plan ก่อนนำ Interface เข้า Security Zone

บทสรุป

Cisco Zone-Based Firewall เปลี่ยนแนวคิดจากการมอง Firewall Policy ตาม Interface เพียงอย่างเดียว มาเป็นการจัด Network ตาม Security Zone

Interface
   |
   v
Security Zone
   |
   v
Zone Pair
   |
   v
Service Policy
   |
   v
Policy Map
   |
   v
Class Map
   |
   v
Inspect / Pass / Drop

หัวใจสำคัญคือ Zone Pair มีทิศทาง

INSIDE -> OUTSIDE
       !=
OUTSIDE -> INSIDE

และ Action inspect ช่วยสร้าง Stateful Inspection:

INSIDE
   |
   | New Session
   v
 ZBF
   |
   | INSPECT
   v
OUTSIDE

   ^
   |
   | Valid Return Traffic
   |
Session State

แต่ ZBF ไม่ได้ทำให้ องค์ประกอบ Network อื่น หมดความสำคัญ

VLAN
  +
IP Addressing
  +
Routing
  +
ACL
  +
NAT / PAT
  +
ZBF
  +
DNS
  +
Monitoring
  =
Functional Secure Network

สำหรับ Network ที่ซับซ้อนขึ้น สามารถขยายจาก:

INSIDE
   |
   v
OUTSIDE

เป็น:

             OUTSIDE
                |
          +-----+-----+
          |     ZBF   |
          +-----+-----+
             /  |  \
            /   |   \
           v    v    v
       INSIDE  DMZ  GUEST

บทความถัดไปควรต่อด้วย Cisco Zone-Based Firewall Advanced: DMZ, Guest Zone, Self Zone และ Multi-Zone Policy เพื่อเรียนรู้การออกแบบ Firewall มากกว่า 2 Zone ก่อนเข้าสู่หัวข้อ VPN และ Network Edge Security ในลำดับต่อไป

Share this
Facebook Share X
TECHEREST COMMUNITY

Share your thoughts here

Join the conversation and share your perspective on this article.

Comments will load when you reach this section.