Breaking News
Loading...
Showing posts with label Networking. Show all posts
Showing posts with label Networking. Show all posts

Sunday, 13 December 2015

Attack, Scan, Detect & Protect on LAN: Download WinArpAttacker

Scan, Attack, Detect & Protect on LAN: Download WinArpAttacker


WinArpAttacker is a program that can scan,attack,detect and protect computers on local area network.

The features as following:






1.1 Scan

-. It can scan and show the active hosts on the LAN within a very short time (~2-3 seconds).

It has two scan mode, one is normal scanning, the other is antisniff scanning. The later is to find who is sniffing on the lan.

-. It can save and load computer list file.

-. It can scan the Lan regularly for new computer list.

-. It can update the computer list in passive mode using sniffing technology, that is, it can update the computer list from the sender's address of arp request packets without scanning the lan.

-. It can perform advanced scanning when you open advanced scanning dialg on menu.

-. It can scan a B class ip range in advanced scan dialg.

-. It can scan acthost listed in event listview.

1.2 Attack

-. It can pull and collect all the packets on the LAN.

-. It can perform six attacking actions as following:

(1) Arp Flood - Send ip conflict packets to target computers as fast as possible, if you send too much, the target computers will down. :-(

(2) BanGateway - Tell the gateway a wrong mac address of target computers, so the targets can't receive packet from the internet. This attack is to forbid the targets access the internet.

(3) IPConflict - Like Arp Flood, send ip conflict packets to target computers regularly, maybe the users can't work because of regular ip conflict message. what's more, the targets can't access the lan.

(4) SniffGateway - Spoof the targets and the gateway, you can use sniffer to collect packets between them.

(5) SniffHosts - Spoof among two or above targets, you can use sniffer to collect packets among all of them. (dangerous!!!!)

(6) SniffLan - Just like SniffGateway, the difference is that SniffLan sends broadcast arp packets to tell all computers on the lan that this host is just the gateway, So you can sniff all the data between all hosts with the gateway.(dangerous!!!!!!!!!!!!!!)

-. While spoofing ARP tables, it can act as another gateway (or ip-forwarder) without other users' recognition on the LAN.

-. It can collect and forward packets through WinArpAttacker's ipforward function, you had best check disable system ipforward function because WinArpAttacker can do well.

-. All data sniffed by spoofing and forwarded by WinArpAttacker ipforward function will be counted, as you can see on main interface.

-. As your wish, the arp table is recovered automatically in a little time (about 5 seconds). Your also can select not to recover.

1.3 Detect

-. What is the most important function, it can detect almost all attacking actions metioned as above as well as host status. the event WinArpAttacker can detect is listed as following:

SrcMac_Mismath - Host sent an arp packet, its src_mac doesn't match,so the packet will be ignored.

DstMac_Mismath - Host recv an arp packet, its dst_mac doesn't match,so the packet will be ignored.

Arp_Scan - Host is scanning the lan by arp request for a hosts list.

Arp_Antisniff_Scan - Host is scanning the lan for sniffing host,thus the scanner can know who is sniffing.

Host_Online - Host is online now.

Host_Modify_IP - Host modified its ip to or added a new IP.

Host_Modify_MAC - Host modified its mac address.

New_Host - New gost was found.

Host_Add_IP - Host added a new ip address.

Multi_IP_Host - Host has multi-ip addresses.

Multi_Mac_Host - Host has multi-mac addresses.

Attack_Flood - Host sends a lot of arp packets to another host ,so the target computer maybe slow down.

Attack_Spoof - Host sends special arp packets to sniff the data two targets , so the victims' data exposed.

Attack_Spoof_Lan - Host lets all host on the lan believe that it's just a gateway, so the intruder can sniff all hosts' data to the real gateway.

Attack_Spoof_Ban_Access - Host told host that host has a inexist mac,so the targets can't communicate with each other.

Attack_Spoof_Ban_Access_GW - Host told host that the gateway has a inexist mac, so the target can't access the internet through the gateway.

Attack_Spoof_Ban_Access_Lan - Host broadcast host's mac as a inexist mac, so the target can't communicate with all hosts on the lan.

Attack_IP_Conflict - Host found another host has same ip as its, so the target would be disturbed by ip conflict messages.

Local_Arp_Entry_Change - now WinArpAttacker can watch local arp entry, when a host's mac address in local arp table is changed, WinArpAttacker can report.

Local_Arp_Entry_Add - When a mac address of a host is added to local arp table, WinArpAttacker can report.

-. It can explain each event which WinArpAttacker detected.

-. It can save events to file.


Monday, 12 October 2015

TestinsideCCNA640-802 v12


TestinsideCCNA640-802 v12


TestinsideCCNA640-802 v12: Download here:
http://rapidshare.com/#!download|167tl3|66726333|TestInside_CCNA640-802_v12.rar|5295

Free Speed Test

Cisco Systems' Private VLANs

  Cisco Systems' Private VLANs:

Scalable Security in a Multi-Client Environment

Abstract

This document describes a mechanism to achieve device isolation
through the application of special Layer 2 forwarding constraints.
Such a mechanism allows end devices to share the same IP subnet while
being Layer 2 isolated, which in turn allows network designers to
employ larger subnets and so reduce the address management overhead.

Some of the numerous deployment scenarios of the aforementioned
mechanism (which range from data center designs to Ethernet-to-the-
home-basement networks) are mentioned in the following text to
exemplify the mechanism's possible usages; however, this document is
not intended to cover all such deployment scenarios nor delve into
their details.

Status of This Memo

This document is not an Internet Standards Track specification; it is
published for informational purposes.

This is a contribution to the RFC Series, independently of any other
RFC stream. The RFC Editor has chosen to publish this document at
its discretion and makes no statement about its value for
implementation or deployment. Documents approved for publication by
the RFC Editor are not a candidate for any level of Internet
Standard; see Section 2 of RFC 5741.

Information about the current status of this document, any errata,
and how to provide feedback on it may be obtained at
http://www.rfc-editor.org/info/rfc5517.


Copyright Notice

Copyright (c) 2010 IETF Trust and the persons identified as the
document authors. All rights reserved.

This document is subject to BCP 78 and the IETF Trust's Legal
Provisions Relating to IETF Documents
(http://trustee.ietf.org/license-info) in effect on the date of
publication of this document. Please review these documents
carefully, as they describe your rights and restrictions with respect
to this document.

Table of Contents

1. Introduction ....................................................2
1.1. Security Concerns with Sharing a VLAN ......................3
1.2. The Traditional Solution and Its Related Problems ..........3
2. Private VLANs Architecture ......................................4
2.1. VLAN Pairings and Their Port-Related Characteristics .......7
3. Extending Private VLANs across Switches .........................9
4. A More Flexible IP Addressing Scheme ............................9
5. Routing Considerations .........................................10
6. Security Considerations ........................................10
7. Acknowledgements ...............................................11
8. References .....................................................11
8.1. Normative References ......................................11
8.2. Informative References ....................................11

1. Introduction

In an Ethernet switch, a VLAN is a broadcast domain in which hosts
can establish direct communication with one another at Layer 2. If
untrusted devices are introduced into a VLAN, security issues may
arise because trusted and untrusted devices end up sharing the same
broadcast domain.

The traditional solution to this kind of problem is to assign a
separate VLAN to each user concerned about Layer 2 security issues.
However, the IEEE 802.1Q standard [802.1Q] specifies that the VLAN ID
field in an Ethernet frame is 12 bits wide. That allows for a
theoretical maximum of 4094 VLANs in an Ethernet network (VLAN
numbers 0 and 4095 are reserved). If the network administrator
assigns one VLAN per user, then that equates to a maximum of 4094
users that can be supported. The private VLANs technology described
in this memo addresses this scalability problem by offering more
granular and more flexible Layer 2 segregation, as explained in the
following sections.


1.1. Security Concerns with Sharing a VLAN

Companies who have Internet presence can either host their servers in
their own premises or, alternatively, they can locate their servers
at the Internet Service Provider's premises. A typical ISP would
have a server farm that offers web-hosting functionality for a number
of customers. Co-locating the servers in a server farm offers ease
of management but, at the same time, may raise security concerns.

Let us assume that the ISP puts all the servers in one big VLAN.
Servers residing in the same VLAN can listen to Layer 2 broadcasts
from other servers. Once a server learns the Media Access Control
(MAC) address associated to the IP address of another computer in the
same VLAN, it can establish direct Layer 2 communication with that
device without having to go through a Layer 3 gateway/firewall. If,
for example, an attacker gets access to one of the servers, he or she
can use that compromised host to launch an attack on other servers in
the server farm. To protect themselves from malicious attacks, ISP
customers want their machines to be isolated from other machines in
the same server farm.

The security concerns become even more apparent in metropolitan area
networks. Metropolitan Service Providers may want to provide Layer 2
Ethernet access to homes, rental communities, businesses, etc. In
this scenario, the subscriber next door could very well be a
malicious network user.

It is therefore very important to offer Layer 2 traffic isolation
among customers. Customer A would not want his Layer 2 frames being
broadcast to customer B, who happens to be in the same VLAN. Also,
customer A would not want customer B to bypass a router or a firewall
and establish direct Layer 2 communication with him/her.

1.2. The Traditional Solution and Its Related Problems

The traditional solution would be to assign a separate VLAN to each
customer. That way, each user would be assured of Layer 2 isolation
from devices belonging to other users.

However, with the VLAN-per-customer model, if an ISP wanted to offer
web-hosting services to, say, 4000 customers, it would consume 4000
VLANs. Theoretically, the maximum number of VLANs that an 802.1Q-
compliant networking device can support is 4094. In reality, many
devices support a much smaller number of active VLANs. Even if all
devices supported all 4094 VLANs, there would still be a scalability
problem when the 4095th customer signed up.


A second problem with assigning a separate VLAN per customer is
management of IP addresses. Since each VLAN requires a separate
subnet, there can be potential wastage of IP addresses in each
subnet. This issue has been described by RFC 3069 [RFC3069] and will
not be discussed in detail in this document.

2. Private VLANs Architecture

The private VLANs architecture is similar to but more elaborate than
the aggregated VLAN model proposed in RFC 3069. The concepts of
'super VLAN' and 'sub VLAN' used in that RFC are functionally similar
to the concepts of 'primary VLAN' and 'secondary VLAN' used in this
document.

On the other hand, the private VLANs technology differs from the
mechanism described in [RFC4562] because instead of using a MAC-
address-based 'forced forwarding' scheme it uses a VLAN-based one.

A regular VLAN is a single broadcast domain. The private VLANs
technology partitions a larger VLAN broadcast domain into smaller
sub-domains. So far, two kinds of special sub-domains specific to
the private VLANs technology have been defined: an 'isolated' sub-
domain and a 'community' sub-domain. Each sub-domain is defined by
assigning a proper designation to a group of switch ports.

Within a private VLAN domain, three separate port designations exist.
Each port designation has its own unique set of rules, which regulate
a connected endpoint's ability to communicate with other connected
endpoints within the same private VLAN domain. The three port
designations are promiscuous, isolated, and community.

An endpoint connected to a promiscuous port has the ability to
communicate with any endpoint within the private VLAN. Multiple
promiscuous ports may be defined within a single private VLAN domain.
In most networks, Layer 3 default gateways or network management
stations are commonly connected to promiscuous ports.

Isolated ports are typically used for those endpoints that only
require access to a limited number of outgoing interfaces on a
private-VLAN-enabled device. An endpoint connected to an isolated
port will only possess the ability to communicate with those
endpoints connected to promiscuous ports. Endpoints connected to
adjacent isolated ports cannot communicate with one another. For
example, within a web-hosting environment, isolated ports can be used
to connect hosts that require access only to default gateways.

A community port is a port that is part of a private VLAN community,
which is a grouping of ports connected to devices belonging to the



same entity (for example, a group of hosts of the same ISP customer
or a pool of servers in a data center). Within a community,
endpoints can communicate with one another and can also communicate
with any configured promiscuous port. Endpoints belonging to one
community cannot instead communicate with endpoints belonging to a
different community or with endpoints connected to isolated ports.

The aforementioned three port designations directly correspond to
three different VLAN types (primary, isolated, and community) with
well-defined, port-related characteristics, which are described in
detail in Section 2.1 below.

Figure 1 below illustrates the private VLAN model from a switch port
classification perspective.

-----------
| R |
-----------
|
|
|
----------------------------------------
| p1 |
| |
=====| t1 |
| switch |
| |
| |
|i1 i2 c1 c2 |
----------------------------------------
| | | |
| | | |
| | | |
A B C D

A, B - Isolated devices
C, D - Community devices
R - Router (or other L4-L7 device)
i1, i2 - Isolated switch ports
c1, c2 - Community switch ports
p1 - Promiscuous switch port
t1 - Inter-switch link port (a VLAN-aware port)

Figure 1. Private VLAN classification of switch ports

With reference to Figure 1, each of the port types is described
below.



Isolated ports: An isolated port, e.g., i1 or i2, cannot talk to any
other port in the private VLAN domain except for promiscuous ports
(e.g., p1). If a customer device needs to have access only to a
gateway router, then it should be attached to an isolated port.

Community ports: A community port, e.g., c1 or c2, is part of a group
of ports. The ports within a community can have Layer 2
communications with one another and can also talk to any
promiscuous port. If an ISP customer has, say, 2 devices that
he/she wants to be isolated from other customers' devices but to
be able to communicate among themselves, then community ports
should be used.

Promiscuous ports: As the name suggests, a promiscuous port (p1) can
talk to all other types of ports. A promiscuous port can talk to
isolated ports as well as community ports and vice versa. Layer 3
gateways, DHCP servers, and other 'trusted' devices that need to
communicate with the customer endpoints are typically connected
via promiscuous ports.

Please note that isolated, community, and promiscuous ports can
either be access ports or hybrid/trunk ports (according to the
terminology presented in Annex D of the IEEE 802.1Q specification, up
to its 2004 revision).

The table below summarizes the communication privileges between the
different private VLAN port types.

---------------------------------------------------------------
| | isolat-| promis-| commu-| commu-| interswitch |
| | ted | cuous | nity1 | nity2 | link port |
---------------------------------------------------------------
| isolated | deny | permit | deny | deny | permit |
---------------------------------------------------------------
| promiscuous | permit | permit | permit| permit| permit |
---------------------------------------------------------------
| community1 | deny | permit | permit| deny | permit |
---------------------------------------------------------------
| community2 | deny | permit | deny | permit| permit |
---------------------------------------------------------------
| interswitch | | | | | |
| link port | deny(*)| permit | permit| permit| permit |
---------------------------------------------------------------

Table 1

(*) Please note that this asymmetric behavior is for traffic
traversing inter-switch link ports over an isolated VLAN only.



Traffic from an inter-switch link port to an isolated port will
be denied if it is in the isolated VLAN. Traffic from an inter-
switch link port to an isolated port will be permitted if it is
in the primary VLAN (see below for the different VLAN
characteristics).

N.B.: An inter-switch link port is simply a regular port that
connects two switches (and that happens to carry two or more
VLANs).

2.1. VLAN Pairings and Their Port-Related Characteristics

In practice, the Layer 2 communication constraints described in the
table above can be enforced by creating sub-domains within the same
VLAN domain. However, a sub-domain within a VLAN domain cannot be
easily implemented with only one VLAN ID. Instead, a mechanism of
pairing VLAN IDs can be used to achieve this notion. Specifically,
sub-domains can be represented by pairs of VLAN numbers:

Vp is the primary VLAN ID ------
Vs is the secondary VLAN ID | Vp |
------
where Vs can be: / \
- Vi (an isolated VLAN) / \
- Vc (a community VLAN) / \
------ ------
| Vi | | Vc |
------ ------


Figure 2. A private VLAN domain can be
implemented with one or more VLAN ID pairs.

A private VLAN domain is built with at least one pair of VLAN IDs:
one (and only one) primary VLAN ID (Vp) plus one or more secondary
VLAN IDs (Vs). Secondary VLANs can be of two types: isolated VLANs
(Vi) or community VLANs (Vc).

A primary VLAN is the unique and common VLAN identifier of the whole
private VLAN domain and of all its VLAN ID pairs.

An isolated VLAN is a secondary VLAN whose distinctive characteristic
is that all hosts connected to its ports are isolated at Layer 2.
Therefore, its primary quality is that it allows a design based on
private VLANs to use a total of only two VLAN identifiers (i.e., a
single private VLAN pairing) to provide port isolation and serve any
number of end users (vs. a traditional design in which one separate
plain VLAN ID would be assigned to each port).



A community VLAN is a secondary VLAN that is associated to a group of
ports that connect to a certain "community" of end devices with
mutual trust relationships.

While only one isolated VLAN is allowed in a private VLAN domain,
there can be multiple distinct community VLANs.

Please note that this VLAN pairing scheme simply requires that all
traffic transported within primary and secondary VLANs be tagged
according to the IEEE 802.1Q standard (see for example [802.1Q],
Section B.1.3), with at most a single standard VLAN tag. No special
double-tagging is necessary due to the 1:1 correspondence between a
secondary VLAN and its associated primary VLAN.

(Also note that this document makes use of the "traditional" VLAN
terminology, whereas the IEEE 802.1ag standard [802.1ag] amends key
sections of IEEE 802.1Q-2005 to make the distinction between "VLANs"
and "VLAN IDs" so that every "VLAN" can be assigned one or more VLAN
IDs, similarly to the pairing scheme described in this document.)

The ports in a private VLAN domain derive their special
characteristics (as described in Section 2) from the VLAN pairing(s)
they are configured with. In particular, a promiscuous port is a
port that can communicate with all other private VLAN port types via
the primary VLAN and any associated secondary VLANs, whereas isolated
or community ports can communicate over their respective secondary
VLANs only.

For example, with reference to Figure 1, a router R connected to the
promiscuous port can have Layer 2 communication with a device A
connected to an isolated port and also with a device C connected to a
community port. Devices C and D can also have Layer 2 communication
between themselves since they are part of the same community VLAN.
However, devices A and B cannot communicate at Layer 2 due to the
special port segregation property of the isolated VLAN. Also,
devices A and C cannot communicate at Layer 2 since they belong to
different secondary VLANs.

The impact of these enforced forwarding restrictions is two-fold.
Firstly, service providers can assign multiple customers to the same
isolated VLAN, thereby conserving VLAN IDs. Secondly, end users can
be assured that their Layer 2 traffic cannot be sniffed by other end
users sharing the same isolated VLAN or connected to a different
secondary VLAN.


3. Extending Private VLANs across Switches

Some switch vendors have attempted to provide a port isolation
feature within a VLAN by implementing special logic at the port
level. However, when implemented at the port level, the isolation
behavior is restricted to a single switch.

When a VLAN spans multiple switches, there is no standard mechanism
to propagate port-level isolation information to other switches and,
consequently, the isolation behavior fails in other switches.

In this document, the proposal is to implement the port isolation
information implicitly at the VLAN level. A particular VLAN ID can
be configured to be the isolated VLAN. All switches in the network
would give special "isolated VLAN" treatment to frames tagged with
this particular VLAN ID. Thereby, the isolated VLAN behavior can be
maintained consistently across all switches in a Layer 2 network.

In general, isolated, community, and primary VLANs can all span
multiple switches, just like regular VLANs. Inter-switch link ports
need not be aware of the special VLAN type and will carry frames
tagged with these VLANs just like they do any other frames.

One of the objectives of the private VLANs architecture is to ensure
that traffic from an isolated port in one switch does not reach
another isolated or community port in a different switch even after
traversing an inter-switch link. By implicitly embedding the
isolation information at the VLAN level and by transporting it along
with the packet, it is possible to maintain a consistent behavior
throughout the network. Therefore, the mechanism discussed in
Section 2, which will restrict Layer 2 communication between two
isolated ports in the same switch, will also restrict Layer 2
communication between two isolated ports in two different switches.

4. A More Flexible IP Addressing Scheme

The common practice of deploying multiple VLANs in a network for
security reasons and of allocating a subnet to each VLAN has led to a
certain number of inefficiencies in network designs, such as the
suboptimal utilization of the IP addressing space (as exemplified in
the introduction of RFC 3069 [RFC3069]). Moreover, each subnet
requires addresses to be set aside for internetworking purposes (a
subnetwork address, a directed broadcast address, default gateway
address(es), etc.). So a high number of used VLANs traditionally
translates into a significant number of special addresses to be
consumed.


On the other hand, in a private VLAN domain, all members can share a
common address space that is part of a single subnet associated to
the primary VLAN. An end device can be assigned an IP address
statically or by using a DHCP server connected to a promiscuous port.
Since IP addresses are no longer allocated on a smaller subnet basis
but are assigned from a larger address pool shared by all members in
the private VLAN domain, address allocation becomes much more
efficient: fewer addresses are consumed for internetworking purposes,
while most of the address space is allotted to end devices, leaving
ample flexibility in the way available addresses are (re-)assigned.

5. Routing Considerations

The entire private VLANs architecture confines secondary VLANs within
the 2nd layer of the OSI model. With reference to Figure 2, the
secondary VLANs are internal to a private VLAN domain. Layer 3
entities are not directly aware of their existence: to them it
appears as if all the end devices are part of the primary VLAN.

With reference to Figure 1, the isolation behavior between devices A
and B is at the Layer 2 level only. Devices A and B can still
communicate at the Layer 3 level via the router R. Since A and B are
part of the same subnet, the router assumes that they should be able
to talk directly to each other. That however is prevented by the
isolated VLAN's specific behavior. So, in order to enable A and B to
communicate via the router, a proxy-ARP-like functionality needs to
be supported on the router interface.

With regard to the specific version of the IP protocol in use, all
routing considerations apply to both IPv4 and IPv6 for the case of
unicast traffic. On the other hand, due to their complexity,
considerations about multicast bridging and routing within a private
VLAN domain transcend the scope of this introductory document, and
are therefore omitted.

6. Security Considerations

In a heterogeneous Layer 2 network that is built with switches from
multiple vendors, the private VLAN feature should be supported and
configured on all the switches. If a switch S in that network does
not support this feature, then there may be undesired forwarding of
packets, including permanent flooding of Layer 2 unicast frames.
That is because switch S is not aware of the association between
primary and secondary VLANs and consequently cannot apply the
segregation rules and constraints characteristic of the private VLANs
architecture (an example of one such constraint is explained in
[802.1Q], Section B.1.3). This impact is limited to traffic within
the private VLAN domain and will not affect the regular Layer 2
forwarding behavior on other VLANs.

If the private VLAN feature is properly deployed, it can be used at
Layer 2 to segregate individual users or groups of users from each
other: this segregation allows a network designer to more effectively
constrain Layer 2 forwarding so as to, for instance, block or contain
unwanted inter-device communication like port scans or Address
Resolution Protocol (ARP) poisoning attacks.

7. Acknowledgements

Many people have contributed to the private VLANs architecture. We
would particularly like to thank, in alphabetical order, Senthil
Arunachalam, Jason Chen, Tom Edsall, Michael Fine, Herman Hou, Kannan
Kothandaraman, Milind Kulkarni, Heng-Hsin Liao, Tom Nosella, Prasanna
Parthasarathy, Ramesh Santhanakrishnan, Mukundan Sudarsan, Charley
Wen, and Zhong Xu for their significant contributions.

8. References

8.1. Normative References

[802.1Q] Institute of Electrical and Electronics Engineers,
"Virtual Bridged Local Area Networks", IEEE Standard
802.1Q, 2005 Edition, May 2006.

[802.1ag] Institute of Electrical and Electronics Engineers,
"Connectivity Fault Management", IEEE Standard 802.1ag,
2007 Edition, December 2007.

8.2. Informative References

[RFC3069] McPherson, D. and B. Dykes, "VLAN Aggregation for
Efficient IP Address Allocation", RFC 3069, February 2001.

[RFC4562] Melsen, T. and S. Blake, "MAC-Forced Forwarding: A Method
for Subscriber Separation on an Ethernet Access Network",
RFC 4562, June 2006.

Securing Your Home Network

Securing Your Home Network

Most people who use computers these days have had to deal with a security issue of some kind – whether they are aware of it or not. Everyone has been infected by one of the many worms or viruses floating around the Internet, or have had someone use your password. Most home computer users are victims of attacks that they have no idea about.

For example, certain programs called ‘spyware' come packaged into seemingly friendly programs you download, this spyware can do any one of a number of things, though most often they send your personal information (such as name and email address) and information about what sites you visit to certain companies.

These in turn will sell your personal information to the spammers and email marketers who will proceed to clog your inbox with junk that they think you might be interested in. To explain how this works, you download a program – say a video player – from the Internet and install it. In the background it installs some spyware. Now you start surfing to car sites, soon you can expect your email inbox to be full of spam offering you great deals on used cars etc.

A lot of people work on the principle that their home computer contains nothing interesting enough for an attacker, what they don't realise is that while an attacker may not target your system specifically, it is very common for them to use programs that will scan vast ranges of the Internet looking for vulnerable systems, if yours happens to be one, it will be automatically taken over and placed at the attackers command. From here he can do a variety of things, like using your computer to attack other sites on the Internet or capturing all your passwords.

Worms and email viruses work the same way, they infect one machine, and then spread by trying to email themselves to everyone in your guest book, or turning your machine into a scanning system to find other targets. They may even contain a malicious payload that can destroy your files, or even worse – email your private documents to everyone you know (this was the case with a worm a few years ago).

Given that the things we use the computer for these days such as online shopping for books or music, electronic banking etc, these threats have a more serious implication than most people realise. You may not have anything worthwhile on your computer, but what if an attacker is able to steal your credit card information when you are buying a book from Amazon.com, or steal the password to your online banking account ?

Luckily the steps you have to take to secure your own PC are fairly simple and can be accomplished by non-technical users given the right guidance. If you follow the guidelines we have given here, you will be safe from most forms of Internet based threats. So here are a few steps you can take.

Email Security

A lot of viruses these days, such as the recent MyDoom virus, spread by emailing themselves to people as an attachment, the email can appear to come from anywhere.. most often it will appear to come from a friend, or an address like admin@yahoo.com if you use a yahoo account. The email will try and convince you to download and run the attachment which may appear to be a harmless JPG image or SCR screensaver. In fact, the attachment is a malicious program (known as malware), and once opened, can do any of the nasty things we've listed above. Here are the rules you should follow when checking your email.

1. Has the email come from someone you know ? If so, were you expecting the email and its attachment ? If not, try and confirm with the person over the phone or some other medium.
2. Does the message make sense ? If you receive an email from your computer illiterate parents saying ‘download this new screensaver', you can be quite sure something is fishy.
3. Does the email appear to come from someone in authority ? If the email comes from what appears to be the administrator of your email service, you should double check with them. No email service will ever ask you to reveal your password, or threaten to terminate your account unless you download the instructions in the attachment. If you are unsure, always contact their tech-support personnel before opening any attachment.

If you've followed the above steps, and you still think you need to download the attachment, make sure you scan it before downloading. Most popular email services like Hotmail and Yahoo offer you the facility of scanning the attachment, use this feature ! Once you've downloaded it, it never hurts to scan it with your own anti-virus software which you should have installed (we will talk about this in the next tip). Only after you are completely certain this attachment is safe, should you download it. If it is a program (ending in .exe, or something like .jpg.exe), then you should be extra careful. Remember that anti-virus scanners must be up to date to be able to catch new viruses, and even then, you may encounter a virus before the anti-virus companies have been able to analyse it.

Install An Anti-virus Software

90% of the threats you will face as a home user will come not from hardcore cyber criminals, but from automatic spreading viruses known as worms. The best way to guard against virus threats is to download a good anti-virus scanner. Two of the best ones are Norton AntiVirus and McAfee . Remember that the anti-virus needs to have its scanning database (known as virus definitions) regularly updated. You should try and update the definitions once a week. The longer you put it off for, the larger the new definitions package will be, and the more viruses your system will be vulnerable to. All the virus scanners offer some form of automatic update system so that you don't have to remember to keep updating the definitions yourself. Use this feature.

Disable Windows File Sharing

Most people know that Windows allows you to share files with other people on your network. This is called “Windows File Sharing”, and is what you make use of whenever you open network neighborhood. What most people don't know is that even if you don't specifically choose folders to share, Windows automatically shares your entire hard-disk with anyone who knows your system's Administrator account password. Not just will it share the hard-disk, it will allow the person full read and write access to the disk. To disable file sharing in Windows XP, go through the following steps:

1. Go to the Start menu and select the Control Panel.
2. In the Control Panel window, double-click on Network Connections.
3. Right-click on the icon for your network connection in the window that appears. You can do this for all your network connections (e.g. VSNL, LAN etc)
4. From the menu which appears, choose Properties (use the left mouse button to make your selection).
5. Under This connection uses the following items, highlight File and Printer Sharing for Microsoft Networks.
6. Click Uninstall.
7. When you are asked if you are sure you want to uninstall File and Printer Sharing for Microsoft Networks, click Yes.
8. Click OK or Close to close the Local Area Connection Properties window.

It is also important to understand that most people just press enter when prompted to choose an Administrator password during the install. This is a very bad idea, as it means that anyone can log into your system as an administrator (full access) without supplying a password. Thus you should try and choose a strong password for the administrator account and any other account that you may create on the system if you share it with other people. Read the tip on choosing strong passwords later on.

Update the Operating System

From time to time, people discover bugs or vulnerabilities in operating systems. These vulnerabilities often allow an attacker to exploit something built into your operating system and take it over. To give you a simple example, a vulnerability may be found in MSN Messenger and an attacker can exploit it to gain control of your system. Whenever such a vulnerability is found, the operating system vendors release what are known as ‘patches' which will fix the problem.

If you make sure your system is up to date with the latest patches, an attacker will not be able to exploit one of these vulnerabilities. To update windows, you have to run the ‘Windows update' service, either by clicking ‘Start >> Programs >> Windows update”, or by going to http://windowsupdate.microsoft.com/ . >From there you can scan your system for missing patches and then download the ones you need. You should try and do this regularly so that the backlog of patches you need to download is not very large. If you miss out on a lot of patches, the download could be really huge. This is also the case when you reinstall the operating system.

Install A Personal Firewall

A personal firewall is a piece of software that runs on your machine and lets you decide exactly what data is allowed to enter or leave your machine over the network. For example, if an attacker is scanning your system for vulnerabilities, it will alert you. If an attacker is just looking through ranges of the Internet for targets, your system will not respond to your probes.

In short, your system operates in a stealthy mode – invisible to an attacker. You also need to be careful about what data leaves your system via the network. Viruses and worms that try and email themselves to other people or use your machine to scan for more victims, spyware tries to send data back to an advertiser, and trojan horse programs may try to connect to an attacker. The personal firewall helps by alerting you every time a program tries to access the network connection. This can be tricky to novice users because even when legitimate programs such as Internet Explorer try to access the internet, the firewall will pop-up a warning box.

However, if you are unsure if an alert is malicious or not, most firewalls have a ‘more info' button on the alert which will take you to their website and tell you whether the program is a legitimate one or a known offender. A personal firewall is no good if you just keep answering ‘yes' to every program that wants to access your internet connection.

Take the trouble to understand what programs on your machine need legitimate access and only allow those. For example if you just downloaded a new screensaver program and the firewall says it wants to access the internet, you can be pretty sure it is trying to send some data back somewhere. It may be spyware or a trojan. Soon you will get used to weeding out the suspicious programs. If you have a permanently on connection like cable-modem or DSL, you should most definitely install a personal firewall. Some of the good ones you can get are:

ZoneAlarm – Very easy to install and use, there is a free version with a few less features than the professional version. Gives you very good information about the alerts it generates. Considered the market leader.

BlackICE – Another very highly rated personal firewall, it is not as user friendly as ZoneAlarm, but allows for some further configuration options

Sygate Personal Firewall – Also less user friendly, but it allows you to make some very powerful configuration changes and it contains a rudimentary intrusion detection system to alert you about common attacks.

If you go to any search engine and search for ‘personal firewall' you will find a whole lot of other options. If you use Windows XP, it is a good idea to turn on the built in Internet Connection Firewall by double clicking on your connection icon near the clock, clicking properties >> advanced >> Protect my computer and network…. This built in firewall is not meant to be a replacement for a full solution like the ones above. It only filters incoming traffic and will not alert you if a trojan or worm tries to use your machine for some malicious purpose.

Scan For Spyware

All through this article we have talked about spyware that lets companies customise their advertising by watching what you do on the net. While spyware may not be destructive, it is one of the biggest pests around and will result in a mailbox full of spam before you know it. However there are a number of tools that will scan for well known spyware on your machine and will allow you to delete it safely.

Note that AntiVirus packages do not usually alert you when you install spyware because it is not considered harmful to the computer itself. Two of the most popular programs for detecting and removing spyware are Ad-aware and Spybot Search & Destroy .

Choose Strong Passwords

Most of the time an attacker need not resort to a technical hack to break into a system because he can simply guess at poorly chosen passwords. Here are some general rules when selecting a password :

1. Do not use a word which can be found in a dictionary, or a birthdate / name these are very easy to crack
2. Adding numbers like 123 at the end does not make it more difficult to crack the password
3. Choose at least a 6 character long password.
4. Use different capitalisation for the letters, e.g. “suRViVor” (Don't use this one, its in a dictionary remember… its just an example)
5. Add some random numbers to the end or in the middle
6. If possible use a few special characters like !(;,$#& etc.
7. When choosing a password hint question, choose one that only you will be able to answer. “What is my birthdate ?” is something anyone who knows you even remotely will be able to guess.

A very useful method for choosing an easy to remember random password is to take a line of a song that you remember and then take the first letter of each word in that line. Now you can randomise the capitalisation, add a couple of numbers and special characters, and have a very strong password that is still difficult to crack.

Remember as far as possible to use a different password for different accounts (e.g. one password for your personal email, one for work email, one for internet banking). This may make things more difficult to remember, but in the event that one password gets compromised, the attacker will not have access to all the other accounts.

How To Configure DNS Server On A Cisco Router

How To Configure DNS Server On A Cisco Router

The DNS protocol is used to resolve FQDN (Fully Qualified Domain Names) to IP addresses around the world. This allows us to successfully find and connect to Internet websites and services no matter where they are. Its usefulness, however, doesn't stop there: local company and private networks also rely on DNS to operate efficiently and correctly.
In many cases, where a local DNS server is not available, we are forced to either use our ISP's DNS servers or some public DNS server, however, this can sometimes prove troublesome. Today, small low-end routers have the ability to integrate DNS functionality, making life easier, but so do Cisco routers - they simply have to be setup and you're done.
This article will show you how to configure your Cisco router to provide DNS services to your network, and make all clients use it as a DNS server. Our easy to follow step-by-step process ensures you'll understand the process and have it running within minutes.

Example Scenario

Consider the following network diagram. This is our example network, we'd like to enable the DNS Service so our workstations can properly resolve Internet domains but also local network names.

First step is to enable the DNS service on the router.


Next, we need to configure the router with a public name-server, this will force the router to perform recursive DNS lookups, in other words, for every request it receives from our
workstations the router will try to find the answer by asking as many DNS servers it needs, and finally return with an answer.


The Cisco IOS will allow you to enter up to 6 different name servers (essentially DNS servers). Usually you would use your ISP's DNS server to ensure you have quick responses, then place a few free public DNS servers such as the ones above. This will ensure that you'll get a DNS response from either your ISP or public DNS servers.
Next step is to configure your DNS server with the host names of your local network, this way when Alan's PC trys to ping or connect to Wayne, the router will successfully resolve its netbios name to the appropriate IP address.


If you now try to ping 'wayne' directly from your router's CLI prompt, you should receive an answer:


At this point, you can configure your workstations to use your router's IP address as the primary DNS server.


Article Summary
We've covered how a Cisco router can be used as a basic DNS server to enable network clients to perform DNS queries for the local network and Internet.
Future articles in DNS will cover more advanced configurations, including full domain resource records, DNS load balancing and more.
If you have found the article useful, we would really appreciate you sharing it with others by using the provided services on the top left corner of this article. Sharing our articles takes only a minute of your time and helps Firewall.cx reach more people through such services.

The Defense Advance Research Projects Agency (DARPA) originally developed Transmission Control Protocol/Internet Protocol (TCP/IP)

The Defense Advance Research Projects Agency (DARPA) originally developed Transmission Control Protocol/Internet Protocol (TCP/IP)

The Defense Advance Research Projects Agency (DARPA) originally developed Transmission Control Protocol/Internet Protocol (TCP/IP) to interconnect various defense department computer networks. The Internet, an international Wide Area Network, uses TCP/IP to connect government and educational institutions across the world. TCP/IP is also in widespread use on commercial and private networks. The TCP/IP suite includes the following protocols:

Physical



Data Link Layer
ARP/RARP: Address Resolution Protocol/Reverse Address
DCAP: Data Link Switching Client Access Protocol

Network Layer
DHCP: Dynamic Host Configuration Protocol
DVMRP :Distance Vector Multicast Routing Protocol
ICMP/ICMPv6: Internet Control Message Protocol
IGMP: Internet Group Management Protocol
IP: Internet Protocol version 4
IPv6: Internet Protocol version 6
MARS: Multicast Address Resolution Server
PIM: Protocol Independent Multicast-Sparse Mode (PIM-SM)
RIP2: Routing Information Protocol
RIPng: for IPv6 Routing Information Protocol for IPv6
RSVP: Resource ReSerVation setup Protocol
VRRP: Virtual Router Redundancy Protocol

Transport Layer
ISTP:
Mobile: IP Mobile IP Protocol
RUDP: Reliable UDP
TALI: Transport Adapter Layer Interface
TCP: Transmission Control Protocol
UDP: User Datagram Protocol
Van: Jacobson compressed TCP
XOT: X.25 over TCP

Session Layer
BGMP: Border Gateway Multicast Protocol
Diameter:
DIS: Distributed Interactive Simulation
DNS: Domain Name Service
ISAKMP/IKE: Internet Security Association and Key Management Protocol and
Internet Key Exchange Protocol
iSCSI: Small Computer Systems Interface
LDAP: Lightweight Directory Access Protocol
MZAP: Multicast-Scope Zone Announcement Protocol
NetBIOS/IP: NetBIOS/IP for TCP/IP Environment

Application Layer
COPS: Common Open Policy Service
FANP: Flow Attribute Notification Protocol
Finger: User Information Protocol
FTP: File Transfer Protocol
HTTP: Hypertext Transfer Protocol
IMAP4: Internet Message Access Protocol rev 4
IMPPpre/IMPPmes: Instant Messaging and Presence Protocols
IPDC: IP Device Control
IRC: ·Internet Relay Chat Protocol
ISAKMP: Internet Message Access Protocol version 4rev1
ISP:
NTP: Network Time Protocol
POP3: Post Office Protocol version 3
Radius: Remote Authentication Dial In User Service
RLOGIN: Remote Login
RTSP: Real-time Streaming Protocol
SCTP: Stream Control Transmision Protocol
S-HTTP: Secure Hypertext Transfer Protocol
SLP: Service Location Protocol
SMTP: Simple Mail Transfer Protocol
SNMP: Simple Network Management Protocol
SOCKS: Socket Secure (Server)
TACACS+: Terminal Access Controller Access Control System
TELNET: TCP/IP Terminal Emulation Protocol
TFTP: Trivial File Transfer Protocol
WCCP: Web Cache Coordination Protocol
X-Window: X Window

Routing
BGP-4: Border Gateway Protocol
EGP: Exterior Gateway Protocol
EIGRP: Enhanced Interior Gateway Routing Protocol
HSRP: Cisco Hot Standby Router Protocol
IGRP: Interior Gateway Routing
NARP: NBMA Address Resolution Protocol
NHRP: Next Hop Resolution Protocol
OSPF: Open Shortest Path First
TRIP: Telephony Routing over IP

Tunneling
ATMP: Ascend Tunnel Management Protocol
L2F: The Layer 2 Forwarding Protocol
L2TP: Layer 2 Tunneling Protocol
PPTP: Point to Point Tunneling Protocol

Security
AH: Authentication Header
ESP: Encapsulating Security Payload
TLS: Transport Layer Security Protocol The

TCP/IP suite is illustrated here in relation to the OSI model:
Click the map to see more details.

Configuring NTP On A Cisco Router

Configuring NTP On A Cisco Router

Network Time Protocol (NTP) is a vital service not only for Cisco devices but almost every network device. Any computer-based device needs to be accurately synchronised with a reliable time source such as an NTP server.
When it comes to Cisco routers, obtaining the correct time is extremely important because a variety of services depend on it. The logging service shows each log entry with the date and time - very critical if you're trying to track a specific incident or troubleshoot a problem.
Generally, most Cisco routers have two clocks (most people are unaware of this!): a battery-powered hardware clock, referenced as the 'calendar' in the IOS CLI, and a software clock, referenced as the 'clock' in the IOS CLI.
The software clock is the primary source for time data and runs from the moment the system is up and running. The software clock can be updated from a number of sources:
• NTP Server
• SNTP (Simple NTP)
• VINES Time Source
• Hardware clock (built into the router)

Because the software clock can be configured to be updated from an external source, it is considered more accurate in comparison to the hardware clock. The hardware clock can be configured to be updated from the software clock.

Example Scenario
This article will show you how to configure your Cisco router to synchronise its software clock from external sources such as NTP servers. We will also show you how to configure your router to act as an NTP server for your internal network devices, ensuring all devices are synchronised.
First example involves setting up the router to request NTP updates and synchronise itself from a public NTP server. This will ensure the router's time is constantly synchronised, however it will not act as an NTP server for internal hosts:
We'll need to configure the router to resolve FQDN using our ISP's name server:
Now we instruct our Cisco router to obtain its updates from the public NTP server.
As soon we issue the command, the router will resolve the FQDN into an ip address and begin its synchronisation. Right after issuing the command, we can verify the router is correctly configured and awaiting synchronisation:
The 'show ntp associations' command shows that the system is configured (~) to synchronise with our selected NTP server, however, it is not yet synchronised. When it is, expect to see the star (*) symbol in front of the tilde (~). The 'ref. clock' column shows the IP address of the NTP server from which our public server (1.gr.pool.ntp.org) is synchronising.
It is also worth noting the column named 'st' which is equal to two (2). This represents the stratum level. The higher the stratum, the closer to the Atomic clock source we are. As a general rule, always try to synchronise with a server that has a low stratum.
The 'show ntp status' command confirms that we are yet to be synchronised with the NTP server as it clearly states that the 'clock is unsynchronised' and also shows us the current system time: 1st of Jan. 1900.
After a couple of minutes, we re-visit the CLI prompt and re-issue the commands with the following results:
Looking at the new output, we can see that our Cisco router is now synchronising with the configured peer (*) - public NTP server. Polling of the public NTP server will occur every 64 seconds, as shown in the command output.
The 'show ntp status' command also confirms the synchronisation, however, notice that the router has set its stratum level to 3. This is expected as the reference is stratum 2. The time is now correctly shown (01:17:15.562 Athens Sun Apr 19 2009).

Synchronising Software clock and Hardware clock
Here we'll see how in fact the software and hardware clocks on a Cisco router can have different times and how we can synchronise them between each other.
The following two commands show the difference in time between the two clocks on our Cisco router:
While the difference is small, we want to keep everything in our network synchronised as precisely as possible.
Keep in mind that 'show clock' refers to the software clock and 'show calendar' refers to the hardware clock.
To synchronise the two clocks all we need to do is issue the following command:
The 'ntp update-calendar' forces the hardware clock to synchronise with the system's software clock. After a couple of minutes, we check to see if the two clocks have synchronised:
We can see now that both clocks are accurately synchronised.

Configuring The System as an Authoritative NTP Server
If you want your system to become an authoritative NTP server from which other internal routers or machines can synchronise, you can achieve this with the following command:
The router now acts as an NTP server and is able to respond to internal clients NTP requests. Checking the 'ntp association' will reveal that the router is obtaining its time synchronisation from itself:
Troubleshooting and Monitoring NTP Status
Troubleshooting NTP messages and events is important when you are trying to verify everything is working correctly. You might notice that your Cisco router is not able to create a peer connection with a configured NTP server or your internal LAN clients might not be able to synchronise with your Cisco router; In any case, knowing how to troubleshoot NTPs is something every engineer must be aware of.
Thankfully Cisco provides a number of options that allow you to troubleshoot many aspects of your NTP service.
The most useful debug commands are the 'debug ntp events', 'debug ntp adjust' and 'debug ntp core'. These three commands provide enough debugging to help you troubleshoot problems you might encounter.
Closing, if you would like more information on the ntp associations created by your router you can try the following command:
The 'show ntp associations detail' command will provide much information on the association created with the NTP servers. This is most helpful when you see you are unable to create an association with an NTP server.

Article Summary
This article provided an insight to NTP configuration on Cisco routers. We analysed why the NTP service is important and how it can be used to keep every node in a network synchronised. We examined different methods of NTP synchronisation and provided a fairly in-depth analysis.
If you have found the article useful, we would really appreciate you sharing it with others by using the provided services on the top left corner of this article. Sharing our articles takes only a minute of your time and helps Firewall.cx reach more people through such services.

BASIC - Configuring console password of a CISCO router

BASIC - Configuring console password of a CISCO router

1. Enter global configuration mode of the CISCO router.
2. Put the command line console 0 to the router.
3. Provide the password by using password command. For example, if you want to put password "cisco" then the command will be password cisco.
4. At last, put the command login.

Commands for configuring console password

Router>enable
Router#config t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#line console 0
Router(config-line)#password cisco
Router(config-line)#login
Router(config-line)#


Why virtual terminal password is required?

Virtual terminal password refers to telnet password. Through telnet, you can access the router and can change anything. So, it's really important to protect the use of telnet by giving a strong password.
Configuring virtual terminal password of a CISCO router:

Different hardware has different no of vty lines defined. Cisco has the range 0 to 4 vty lines. It means it has 5 vty lines. You can set the password of vty lines by the following steps:

1. Enter global configuration mode of the CISCO router.
2. Put the command line vty 0 4 to the router.
3. Provide the password by using password command. For example, if you want to put password "cisco" then the command will be password cisco.
4. At last, put the command login.

Commands for configuring virtual terminal password

Router>enable
Router#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#line vty 0 4
Router(config-line)#password cisco
Router(config-line)#login
Router(config-line)#


Why enable password is required?

Enable password is required to restrict the access of privileged EXEC mode.
Configuring enable password of a CISCO router:

From the global configuration mode, use the command enable password to restrict access to privileged EXEC mode. However, this password is visible in the routers configuration file. To encrypt the password, enable secret command is required. By using enable secret command the password is encrypted and can't be readable to a human.
Commands for configuring enable password

Enable password:

Router>enable
Router#config
Router#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#enable password cisco
Router(config)#


Perform password encryption:

Router>enable
Router#config
Router#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#enable secret cisco
Router(config)#

How to encrypt all the CISCO router password?

By default all the passwords of a CISCO router is readable in clear text in the configuration file. This is a great security threat if someone read it and configure or change the router configuration. So, to protect form display the password, service password-encryption command is used to encrypt the passwords. service password-encryption is a global command and encrypt the passwords:

* enable password
* console password
* vty password
* aux password

By following the above steps you can easily configure CISCO router passwords.

INTERNET TEACHING LAB: CISCO ROUTER BASICS INSTRUCTOR VERSION

INTERNET TEACHING LAB: CISCO ROUTER BASICS INSTRUCTOR VERSION

OVERVIEW
In this lab, we will explore some of the basic information on how to configure a Cisco router. In particular, we will see how to access the FSU Computer Science Internet Teaching Lab routers through the Cisco 2511 firewall router, also known as R6. From that router, we will use a feature called “inverse telnet” to access other lab routers through external RS-232 cables. We will also explore some of the router modes including user mode, enable mode, global configuration mode, and sub configuration mode. For additional information you can access the Cisco IOS manuals online at http://www.cisco.com. (From the Cisco home page, choose Technical Documents-Documentation Home Page-Cisco IOS Software Configuration-Cisco IOS Release 11.1-Cisco IOS Configuration Guides and Command References).
BACKGROUND
The ITL lab consists of six Cisco routers labeled R1, R2, R3, R4, R5, and R6; three Cisco catalyst 3500XL series ethernet switches, and several PCs. Cisco routers run an operating system called Cisco IOS or Cisco Internetwork Operating System. Inside the lab network, devices are numbered using IP private address space documented in the RFC1918 standard. Usually, the lab devices are numbered with the block of class C IP networks from 192.168.1.0/24 through 192.168.254.0/24. (If you are unfamiliar with the “/24” notation, it simply indicates the length of the subnet mask. For example, “/24” indicates a network mask of 255.255.255.0.) Routers R1, R2, R3, R4, and R5 are programmed by students to implement a series of lab exercises to learn about networking. Router R6 also called the “firewall” provides security and connects the lab network to the Computer Science departmental network and Internet. Only limited access is granted to students on this router to prevent changes that might compromise the integrity of the firewall. The firewall uses access lists to selectively block traffic on its ethernet interface. In particular, TELNET access is only permitted when originating from the FSU Computer Science departmental server XI.CS.FSU.EDU. Since the private IP address space is unknown on the Internet backbone, even without these access lists, the lab devices would be unreachable from the Internet. The firewall also performs another important function called “network address translation” or NAT. NAT is configured such that IP packets originating from the lab network will be translated where the source IP address of the packet is replaced by the R6 ethernet address so that it will be globally routable. When the destination server responds, R6 performs the translation in reverse. When enabled, this will allow PCs inside the lab network to access devices outside the lab when communication is initiated from inside the lab only. This will allow you to do things like download files with a web browser on the lab PCs from outside servers. For more background information, see the paper entitled “FSU Computer Science Internet Teaching Lab” which can be found at http://www.cs.fsu.edu/~curci/itl.
PART1 – Log into the Cisco 2511:
The Cisco 2511 firewall access router labeled R6 can be accessed in any of 3 ways:
1. Dumb Terminal or Terminal Emulator configured for 9600 baud and DEC VT100 emulation connected the router’s RS-232 console port.
2. TELNET to ethernet interface E0 from XI.CS.FSU.EDU.
3. TELNET to any router R6 interface from inside the lab network. (Only works when the lab routers are configured to provide connectivity.)
We will use the second method. TELNET from XI.CS.FSU.EDU to the R6 interface E0 will allow you to log into router R6. You can TELNET either using the DNS name ITL1.CS.FSU.EDU or the IP address 128.186.121.88. Access lists on interface E0 will allow access only from XI.CS.FSU.EDU, so you will not be able to TELNET in from any other system outside the lab network. When you are connected, the router prompts you for the user mode password that should have been given to you by your instructor. You will also want to enter the command “enable 2” to increase your security level which will enable some commands otherwise not allowed in the user mode.
xi% telnet itl1
Trying 128.186.121.88...
Connected to itl1.
Escape character is '^]'.
User Access Verification
Password: xxxxxx
fw/r6>enable 2
Password: xxxxxx
fw/r6#
Note that the boldface type above indicates the part that you must type, although you should substitute the password for the “xxxxxx”.
Note on enable levels:
Cisco routers have 16 privilege levels called “enable levels” numbered 0 through 15. Level 0 has the least privilege and cannot make any changes and is also called “user mode”. Level 15 is the most privileged and can make any changes and is often simply called “enable mode”. Intermediate levels are used to provide access between the two extremes. For example, in user mode you cannot list the startup configuration or change the configuration. However, you can set up an intermediate level that allows viewing the startup configuration but does not allow changing the configuration. That is what we have done on the firewall/R6 router with enable level 2. This prevents you from making changes to R6 but allows you to at least view the configuration to see what is going on. The command “enable X” prompts for a password and if accepted, changes to enable level X. If X is omitted, 15 is assumed. On the routers you will program, R1 through R5, we will only use enable levels 0 and 15 and refer to them as “user mode” and “enable mode”. Note that the command prompt changes between these two modes-- “user mode” has the “>” symbol while enable mode has the “#” symbol.
The RS-232 console ports on routers R1 through R5 connect to ports Line1 through Line5 on the 2511 respectively. You can connect to any of these routers across the RS-232 link by typing their name unless there is someone else already using the line. This feature is called “inverse telnet”. You can see if anyone else is logged into the firewall with “show user”. You can see any existing sessions you have with “show session”. Once connected to one of these lines, any characters you type are sent across the RS-232 link to the corresponding router and output from the router is displayed on your screen. The only exception is the special escape sequence that brings you back to router R6 – SHIFT-CONTROL-6-x. On your keyboard, press and hold the SHIFT key, press and hold the CONTROL key, then press the “6” key. Release all keys, then press “x”. You should now be back on router R6. The command “show session” will show you which sessions you have active. You can go back to your previous session by simply hitting return, or entering the integer session number displayed with the “show session” command. The command “clear line X” where X is the integer line number is sometimes necessary to clear an inactive session from an idle user. Here is a capture to demonstrate:
fw/r6#show user
Line User Host(s) Idle Location
0 con 0 r1 2w4d
* 18 vty 0 idle 00:00:00 128.186.121.41
fw/r6#show session
% No connections open
fw/r6#r1
Trying r1 (128.186.121.88, 2001)... Open
r1# - (RETURN and SHIFT-CONTROL-6-x typed here)
fw/r6#r2
Trying r2 (128.186.121.88, 2002)... Open
r2# - (RETURN and SHIFT-CONTROL-6-x typed here)
fw/r6#r3
Trying r3 (128.186.121.88, 2003)... Open
r3> - (RETURN and SHIFT-CONTROL-6-x typed here)
fw/r6#show session
Conn Host Address Byte Idle Conn Name
1 r1 128.186.121.88 0 0 r1
2 r2 128.186.121.88 0 0 r2
* 3 r3 128.186.121.88 0 0 r3
fw/r6#clear line 3
[confirm]y [OK]
fw/r6#logout
(You have open connections) [confirm]y
Closing: r1 !
Closing: r2 !
Closing: r3 ! Connection closed by foreign host.
xi%
Since only one person can use an RS-232 line at a time, if your network is already functional, it may be better to use TELNET from R6 to any of the other lab routers or PCs. By default, Cisco routers allow a maximum of 5 concurrent inbound TELNET sessions.
fw/r6#telnet 192.168.55.5
Trying 192.168.55.5 ... Open
User Access Verification
Password: xxxxxx
r5>enable
Password: xxxxxx
r5#logout
Once logged into your team router go to enable mode. Use the command “show version” to see your router’s IOS version number and operating system image filename. A baseline router configuration file should be located on your router’s flash memory device on a file named “base-rX.cfg” where X is the integer ID corresponding to your router. You can also find a listing of the baseline configuration at the end of this document. Get a directory on your flash filesystem with the command “dir flash:” and verify that the baseline configuration file is present. View this file with “show file flash:base-rX.cfg” If everything looks right, copy the baseline configuration file to your router’s startup configuration with “copy flash:base-rX.cfg startup-config” and reboot with the new configuration using the “reload” command. Follow these steps carefully. After the last step, your router will take about 3 minutes to reboot. The following is an example of these steps on router R3 with some of the unimportant messages removed:
xi% telnet itl1.cs.fsu.edu
Trying 128.186.121.88...
Connected to itl1.
User Access Verification
Password: xxxxx
fw/r6>en 2
Password: xxxxx
fw/r6#r3
Trying r3 (128.186.121.88, 2003)... Open
r3#enable
r3#show version
Cisco Internetwork Operating System Software
IOS (tm) GS Software (GS7-J-M), Version 11.1(24), RELEASE SOFTWARE (fc1)
r3 uptime is 2 days, 2 hours, 47 minutes
System restarted by power-on
System image file is "gs7-j-mz.111-24.bin", booted via flash
cisco RP1 (68040) processor (revision A0) with 65536K bytes of memory.
...
r3#dir flash:
-#- -length- -----date/time------ name
1 4025994 --- -- ---- --:--:-- gs7-j-mz.111-24.bin
2 1289 --- -- ---- --:--:-- base-r3.cfg
165776 bytes available (4028528 bytes used)
r3#show file flash:base-r3.cfg
version 11.1
service udp-small-servers
service tcp-small-servers
!
hostname r3
...
r3#copy flash:base-r3.cfg startup-config
Warning: distilled config is not generated
[OK]
r3#reload
Proceed with reload? [confirm]y
%SYS-5-RELOAD: Reload requested
System Bootstrap, Version 5.0(5), RELEASE SOFTWARE
RP1 processor with 65536 Kbytes of main memory
Reading gs7-j-mz.111-24.bin from flash memory
...
Press RETURN to get started!
r3>
r3>enable
Password: xxxxx
r3#
PART2 – IOS MODES:
The Cisco IOS software can operate in four modes:
1. User Mode
2. Enable Mode
3. Global Configure Mode
4. Sub Configure Mode
The diagram above shows you how to switch between router modes. The following example shows logging into a router (user mode), using the “enable” command to go to enable mode, and using the “configure terminal” command. I then enter a simple configuration to assign an IP address on two interfaces and enable the RIP routing protocol. Note how the command prompt changes as we change between modes. Whitespace is ignored, so I have added whitespace in front of the sub config mode commands for clarity. Note also that a command prefixed with the word “no” negates the meaning of the command such as “shutdown” and “no shutdown”.
Configuration to be entered:
ip classless
interface ethernet2/0
ip address 192.168.10.1 255.255.255.0
no shutdown
interface ethernet 2/1
ip address 192.168.20.1 255.255.255.0
router rip
network 192.168.10.0
network 192.168.20.0
no ip domain-lookup
Here is the captured session:
fw/r6#telnet 192.168.11.1
Trying 192.168.11.1 ... Open
User Access Verification
Password: xxxxxx
r1>enable
Password: xxxxxx
r1#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
r1(config)#ip classless
r1(config)#interface ethernet2/0
r1(config-if)#ip address 192.168.10.1 255.255.255.0
r1(config-if)#no shutdown
r1(config-if)#interface ethernet2/1
r1(config-if)#ip address 192.168.20.1 255.255.255.0
r1(config-if)#no shutdown
r1(config-if)#router rip
r1(config-router)#network 192.168.10.0
r1(config-router)#network 192.168.20.0
r1(config-router)#exit
r1(config)#no ip domain-lookup
r1(config)#exit
r1#logout
When entering commands, you need only enter enough letters for it to be unique. For example, you can use “config t” in place of “configuration terminal”. You can also type the question mark “?” at any point to see your options. If your terminal emulates a DEC VT100, you can also use the UP, DOWN, LEFT, and RIGHT arrow keys to recall previous commands and edit them. Here is a session capture that makes the same router configuration as shown above but demonstrates using abbreviated commands and the built-in “?” HELP facility.
fw/r6#telnet 192.168.11.1
Trying 192.168.11.1 ... Open
User Access Verification
Password: xxxxxx
r1>en
Password: xxxxxx
r1#conf t
Enter configuration commands, one per line. End with CNTL/Z.
r1(config)#ip clas?
classless
r1(config)#ip classless
r1(config)#int e2/0
r1(config-if)#ip add 192.168.10.1 255.255.255.0
r1(config-if)#no shut
r1(config-if)#int e2/1
r1(config-if)#ip add 192.168.20.1 255.255.255.0
r1(config-if)#no shut
r1(config-if)#router rip
r1(config-router)#net 192.168.10.0
r1(config-router)#net 192.168.20.0
r1(config-router)#exit
r1(config)#no ip d?
default-gateway default-network dhcp-server domain-list domain-lookup
domain-name dvmrp
r1(config)#no ip domain?
domain-list domain-lookup domain-name
r1(config)#no ip domain-lookup
r1(config)#^Z
r1#lo
Log into your router and modify the configuration to display a login message that says “Team X Router” replacing X with your team number using the “banner login” command. Also change your router’s command prompt from “rX” to “teamX” using the “hostname” command. Use the “show interface loopback0” and “show running-config” to view the configuration on your loopback0 interface. Delete your router’s loopback0 interface with “no interface loopback0” Verify it is gone with “show running-config”. Then put the interface back in with “interface loopback0” Make sure you remember to assign the interface an IP address and make sure it NOT shutdown. Since we have not saved any configuration changes in this part, if you get stuck, you can always use the “reload” command to reboot which will undo any changes you have made. Just remember that if you are prompted to save change, you should answer “NO”.
xi% telnet itl1.cs.fsu.edu
Password: xxxxx
fw/r6>r4
Trying r4 (128.186.121.88, 2004)... Open
r4>enable
Password: xxxxx
r4#config term
Enter configuration commands, one per line. End with CNTL/Z.
r4(config)#banner login "Team 4 Router"
r4(config)#hostname Team4
Team4(config)#^Z
Team4#
%SYS-5-CONFIG_I: Configured from console by console
Team4#show running-config
Building configuration...
Current configuration:
!
version 11.1
service udp-small-servers
service tcp-small-servers
!
hostname Team4
!
interface Loopback0
ip address 192.168.44.4 255.255.255.0
...
Team4#config term
Enter configuration commands, one per line. End with CNTL/Z.
Team4(config)#no interface loopback0
%LINEPROTO-5-UPDOWN: Line protocol on Int Loopback0, changed state to down
%LINK-5-CHANGED: Int Loopback0, changed state to administratively down
Team4(config)#interface loopback0
Team4(config-if)#
%LINEPROTO-5-UPDOWN: Line protocol on Interface Loopback0, changed state to up
%LINK-3-UPDOWN: Interface Loopback0, changed state to up
Team4(config-if)#ip address 192.168.44.4 255.255.255.0
Team4(config-if)#description Loopback Interface on Router R4
Team4(config-if)#no shutdown
Team4(config-if)#^Z
Team4#
%SYS-5-CONFIG_I: Configured from console by console
Team4#show running-config
Building configuration...
Current configuration:
!
version 11.1
!
hostname Team4
!
no ip domain-lookup
!
interface Loopback0
description Loopback Interface on Router R4
ip address 192.168.44.4 255.255.255.0
!
...
Team4#
PART3 – Saving and Viewing Configurations:
Cisco routers have two configurations, the startup configuration, and the running configuration. Normally, when a router is booted, it reads in the startup configuration which is stored in flash memory. Once the router is running, the current configuration in RAM is called the running configuration. If no changes are made after booting, both the startup and running configurations will be the same. You can make changes interactively to the running configuration. You can also commit the changes to the startup configuration in flash or reboot which will cause any changes you have made to be lost. Here are the relevant commands:
- show startup-config
List the startup configuration in flash to the screen.
- show running-config
List the running configuration currently executing in RAM to the screen.
- copy running-config startup-config
Copy the currently running configuration to the startup configuration in flash to commit any changes you have made. The committed changes will persist even after rebooting the router.
- terminal length 24
Set the router to pause every 24 lines when displaying messages larger than 24 lines.
- terminal length 0
Set the router to not pause when display messages, no matter how long they are even if they scroll off the screen. This is sometimes handy when using a terminal emulator to capture a command with lots of output.
- reload
Reboot the router.
- write erase
Completely erase the startup configuration. Use with care!
- write
An old deprecated command that is a synonym for “copy running-config startup-config”
- write terminal
An old deprecated command that is a synonym for “show running-config”
Your assignment is to capture your router’s running configuration to a text file, erase the startup config and reboot so your router will have no configuration, then get the your text file config back into the router and commit the changes. Afterwards, verify that your router will reboot with the appropriate configuration. Use the following steps to guide you through the process.
1. Log into your router and go to enable mode.
2. Configure your terminal session to inhibit paging.
3. Configure your terminal emulator to capture text.
4. Display the running configuration to your screen while simultaneously capturing it to a text file.
5. Stop capturing text and edit the captured text file with a text editor, removing any extraneous text.
6. Completely erase your router’s startup configuration with “erase startup-config”
7. Reboot your router with “reload”
8. After rebooting, you may see an error message indicating that the startup configuration is missing and get prompted by the auto configuration dialog. You should be able to simply press control-C to cancel the dialog.
9. Log into your router, go to enable mode, and list the running configuration to your screen. Compared to your captured text file in step 5 and explain which part of the configuration is still there and which part is missing.
10. Go to global configuration mode and use copy and paste to put the configuration back into your router.
11. List the running configuration and compared to your saved configuration from step 5. How do they differ? Fix any differences so the running configuration is identical to your saved configuration from step 5.
12. Save your changes by copying the running configuration to the startup configuration.
13. Reboot your router and verify it reboots with the correct configuration.
14. Log into your router and go to enable mode. Configure your session to not page every 24 lines. Set your terminal emulator program to capture text. Display the running configuration to your screen while simultaneously capturing to a text file. Get the text file into some text editor and clean up any extraneous text.
PART4 – Miscellaneous Commands:
Read up on the following commands and try them out on your router. Provide a brief explanation of what each does.
1. telnet
2. ping
3. traceroute
4. show version
5. show clock
6. show diagbus
7. show interface
8. show ip interface brief
9. show ip routing
10. show ip protocol
telnet w.x.y.z
TELNET to a remote host or router w.x.y.z, just like UNIX.
ping w.x.y.z
PING a remote host or router w.x.y.z, just like UNIX.
traceroute w.x.y.z
Trace the route to remote host or router w.x.y.z, just like UNIX.
show version
Display the Cisco IOS software version and additional info.
show clock
Display the time/date according to the router’s internal clock.
show interface
Display all router interfaces including lots of status information.
show ip interface brief
Display all router interfaces briefly, one per line, including the up/down status and IP address if one is assigned.
show ip routing
Display the IP routing table.
show ip protocol
Display information any active IP routing protocols.
BASELINE ROUTER CONFIGURATION:
For completeness, here is a listing of the baseline router configuration mentioned in part 1 for routers R1, R2, R3, R4 and R5. The section labeled “COMMON:” is needed on all routers. The sections labeled “R1:”, “R2”, etc, are the router specific sections. These configurations should already be present on each router’s flash memory on file
“base-rX.cfg” where X is the integer identifier of the router.

COMMON:
service udp-small-servers
service tcp-small-servers
enable password cisco
no ip domain-lookup
no ip classless
logging buffered
snmp-server community public RO
line con 0
exec-timeout 0 0
line aux 0
line vty 0 4
password cisco
login
R1:
hostname r1
interface Loopback0
ip address 192.168.11.1 255.255.255.0
no shutdown
interface Fddi0/0
ip address 192.168.1.1 255.255.255.0
no shutdown
interface Serial1/2
description Link to R2 S1/1
ip address 192.168.12.1 255.255.255.0
bandwidth 2000
no shutdown
interface Serial1/3
description Link to R3 S1/1
ip address 192.168.13.1 255.255.255.0
bandwidth 2000
no shutdown
interface Serial1/4
description Link to R4 S1/1
ip address 192.168.14.1 255.255.255.0
bandwidth 2000
no shutdown
interface Serial1/6
description Link to R6 S0
ip address 192.168.16.1 255.255.255.0
bandwidth 2000
no shutdown
interface E2/0
description Vlan 10 to cat1 FA0/1
ip address 192.168.10.1 255.255.255.0
no shutdown
interface E2/1
description Vlan 20 to cat1 FA0/2
ip address 192.168.20.1 255.255.255.0
no shutdown
interface E2/2
description Vlan 30 to cat1 FA0/3
ip address 192.168.30.1 255.255.255.0
no shutdown
interface E2/3
description Vlan 40 to cat1 FA0/4
ip address 192.168.40.1 255.255.255.0
no shutdown
interface E2/4
description Vlan 50 to cat1 FA0/5
ip address 192.168.50.1 255.255.255.0
no shutdown
interface E2/5
description Vlan 60 to cat1 FA0/6
ip address 192.168.60.1 255.255.255.0
no shutdown
router rip
network 192.168.11.0
network 192.168.12.0
network 192.168.13.0
network 192.168.14.0
network 192.168.16.0
network 192.168.1.0
network 192.168.10.0
network 192.168.20.0
network 192.168.30.0
network 192.168.40.0
network 192.168.50.0
network 192.168.60.0
R2:
hostname r2
interface Loopback0
ip address 192.168.22.2 255.255.255.0
no shutdown
interface Fddi0/0
ip address 192.168.1.2 255.255.255.0
no shutdown
interface Serial1/1
description Link to R1 S1/2
ip address 192.168.12.2 255.255.255.0
bandwidth 2000
clockrate 2000000
no shutdown
interface Serial1/3
description Link to R3 S1/2
ip address 192.168.23.2 255.255.255.0
bandwidth 2000
no shutdown
interface Serial1/4
description Link to R4 S1/2
ip address 192.168.24.2 255.255.255.0
bandwidth 2000
no shutdown
router rip
network 192.168.12.0
network 192.168.22.0
network 192.168.23.0
network 192.168.24.0
network 192.168.1.0
R3:
hostname r3
interface Loopback0
ip address 192.168.33.3 255.255.255.0
no shutdown
interface Fddi0/0
ip address 192.168.1.3 255.255.255.0
no shutdown
interface Serial1/0
description Link to self
no ip address
bandwidth 2000
no shutdown
interface Serial1/1
description Link to R1 S1/3
ip address 192.168.13.3 255.255.255.0
bandwidth 2000
clockrate 2000000
no shutdown
interface Serial1/2
description Link to R2 S1/3
ip address 192.168.23.3 255.255.255.0
bandwidth 2000
clockrate 2000000
no shutdown
interface Serial1/3
description Link to self
no ip address
bandwidth 2000
clockrate 2000000
no shutdown
interface Serial1/4
description Link to R4 S1/3
ip address 192.168.34.3 255.255.255.0
bandwidth 2000
no shutdown
interface Serial1/6
description Link to R6 S1
ip address 192.168.36.3 255.255.255.0
bandwidth 2000
no shutdown
router rip
network 192.168.33.0
network 192.168.13.0
network 192.168.23.0
network 192.168.34.0
network 192.168.36.0
network 192.168.1.0
R4:
hostname r4
interface Loopback0
ip address 192.168.44.4 255.255.255.0
no shutdown
interface Fddi0/0
description Link to R5 FDDI0
ip address 192.168.1.4 255.255.255.0
no shutdown
interface Serial1/1
description Link to R1 S1/4
ip address 192.168.14.4 255.255.255.0
bandwidth 2000
clockrate 2000000
no shutdown
interface Serial1/2
description Link to R2 S1/4
ip address 192.168.24.4 255.255.255.0
bandwidth 2000
clockrate 2000000
no shutdown
interface Serial1/3
description Link to R3 S1/4
ip address 192.168.34.4 255.255.255.0
bandwidth 2000
clockrate 2000000
no shutdown
router rip
network 192.168.44.0
network 192.168.14.0
network 192.168.24.0
network 192.168.34.0
network 192.168.1.0
R5:
hostname r5
interface loopback0
ip address 192.168.55.5 255.255.255.0
no shutdown
interface FastEthernet0
description Vlan70 to cat1 FA0/7
ip address 192.168.70.1 255.255.255.0
media-type 100BaseX
no shutdown
interface Ethernet0
description Vlan80 to cat1 FA0/8
ip address 192.168.80.1 255.255.255.0
media-type 10BaseT
no shutdown
interface Ethernet1
description Vlan90 to cat1 FA0/9
ip address 192.168.90.1 255.255.255.0
media-type 10BaseT
no shutdown
interface Fddi0
description Link to R4 FDDI0/0
ip address 192.168.1.5 255.255.255.0
no keepalive
no shutdown
router rip
network 192.168.55.0
network 192.168.70.0
network 192.168.80.0
network 192.168.90.0
network 192.168.1.0