0% found this document useful (0 votes)
41 views81 pages

Practical Exercises in Networking & Cybersecurity

Uploaded by

rakshitt10
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
41 views81 pages

Practical Exercises in Networking & Cybersecurity

Uploaded by

rakshitt10
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

As per ICAO DOC 9868

and DOC 10057

2024

Competency Based Training and Assessment for


ATSEP
Non-PLI Training
On
Data Communication Networking, Cyber
Security and Linux
MODULE-3
Practical Exercise

AAI/ANS/CNS/CATC/2024/CBTA-Non PLI/Data
Communication Networking/Cyber-
सी.ए.टी.सी.,
Security/Linux/Mod-3 /Ver.1.0
प्रयागराज
CATC, PRAYAGRAJ
THIS PAGE IS INTENTIONALLY KEPT BLANK
Module-3
Data Communication Networking, Cyber security and Linux

Training Quality Policy

“To develop the human


resources for the aviation
industry, ensuring conformity of
the processes, by adapting the
best practices within industry
and building higher skills and
standards in training.”
Module-3
Data Communication Networking, Cyber security and Linux
Module-3
Data Communication Networking, Cyber security and Linux
Version Control

Module Doc No. AAI/CATC/CNS/DCN/CYBER-SECURITY/LINUX/NPLI


Version 1.0 1. Sh. Pravin Kumar Singh, AGM (CNS), CATC
Developed by 2. Sh. Hasan Ashraf, AGM (CNS), CATC
3. Sh. V.P Ratheesh,AGM(CNS),Chennai
4. Narendra Patel,AGM(CNS),CATC
5. Dhiraj Kumar Gupta ,Mgr(CNS),Kolkata
6. Kumar Raunak , AM(CNS),Kolkata
Version 1.0 1. Sh. Govinda Kumar Gupta, AGM (CNS), CATC
vetted by 2. [Link] Ashraf, AGM (CNS), CATC
3. Sh. V.P Ratheesh, AGM (CNS), Chennai
4. Narendra Kr. Patel,AGM(CNS),CATC
5. Sh. Sandeep.G SM(CNS), Mangalore
Period of vetted Ver. 15th April 2024 to 18th April 2024
1.0
Maintained By CDRC, CATC, PRAYAGRAJ
Version Number Modified By Date Date
Modified approved
Ver 1.0
Module-3
Data Communication Networking, Cyber security and Linux
Module-3
Data Communication Networking, Cyber security and Linux
Preface
This “Data Communication Networking, Cyber Security and Linux NPLI Training”
handout conforms to the standards and recommended practices of International Civil Aviation
Organization (ICAO) vide Doc. 9868 (PANS Training) Part IV Chapter 3 for ATSEP and Doc. 10057
(Manual on Air Traffic Safety Electronics Personnel- Competency Based Training and Assessment).

With pleasure, I authenticate this handout and make it available for imparting NPLI training
course on “Data Communication Networking, Cyber Security and Linux” for ATSEPs in AAI.

The course content has been approved by CHQ of AAI. It is hoped that the trainee ATSEPs
will find it informative, interesting and better in presentation.

I am sure that the trainees will carry a sense of pride in undergoing this CBTA based NPLI
Training course of ICAO standard.

This handout on “Data Communication Networking, Cyber Security and Linux” is


specifically designed and developed to equip the ATSEPs with requisite competencies required
to understand Introduction to Data Communication, TCP/IP, Classification of networks, Network
devices with basic configuration in switch and router, Loop avoidance in LAN, IP Addressing &
Subnetting, IP Routing and configuration of static and dynamic routing, VLAN, VLAN Trunking and
inter VLAN routing and configure VLAN in switch and Inter VLAN routing, IP Multicast, Different
protocol, Linux operating system, Linux command, Introduction to cyber security, various cyber
threats , Cyber security threats prevention and basic configuration of network devices to
prevent cyber threats

This handout is intended to be kept up to date. It will be amended periodically as new


technological developments are made in the field of Data communication networking and cyber.

For the development and presentation of this module as per ICAO Doc 10057, I would like
to appreciate the meticulous and excellent work done by the course developers.

Errors, if any or suggestions, if brought to the notice of undersigned would be highly


commendable as it will serve to improve this module and contribute to our objective of achieving
excellence in the field of ATSEP training.

GM (CNS)/ Head of ATSEP training


CATC, PRAYAGRAJ-211012
Dated: 18th April. 2024
Module-3
Data Communication Networking, Cyber security and Linux
Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
TABLE OF CONTENTS

Practical Exercise: ---------------------------------------------------------------------------------------Page No


Exercise No:-1 Introduction to Network emulation software (CISCO Packet tracer )---------------2
Exercise No:-2 Basic switch and Router configuration--------------------------------------------------20
Exercise No:-3 IP Routing-----------------------------------------------------------------------------------24
Exercise No:-4 VLAN----------------------------------------------------------------------------------------29
Exercise No:-5 Introduction to Network emulation software (GNS3 )--------------------------------33
Exercise No:-6 Multicasting demo-------------------------------------------------------------------------34
Exercise No:-7 Network Analyzer tool--------------------------------------------------------------------35
Exercise No:-8 VRRP----------------------------------------------------------------------------------------36
Exercise No:-9 Switch port security-----------------------------------------------------------------------38
Exercise No:-10 Access List--------------------------------------------------------------------------------45
Exercise No:-11 Firewall------------------------------------------------------------------------------------49
Exercise No:-12 NAT----------------------------------------------------------------------------------------54
Exercise No:-13 LINUX Commands Exercise----------------------------------------------------------------------------60
Annexure-A:-Configuration to bring Radar data from source station to receiving station Example---------69

Civil Aviation Training College, India Page 1


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise No. 1:- Familiarization With Packet Tracer

Objective: The Objective of this practical exercise is to become familiar with creating
topologies in Packet Tracer.

Packet Tracer – Creating a New Topology


What is Packet Tracer? Packet Tracer is a protocol simulator developed by Dennis Frezzo and his team at
Cisco Systems. Packet Tracer (PT) is a powerful and dynamic tool that displays the various protocols used
in networking, in either Real Time or Simulation mode. This includes layer 2 protocols such as Ethernet and
PPP, layer 3 protocols such as IP, ICMP, and ARP and layer 4 protocols such as TCP and UDP. Routing
protocols can also be traced.

Version: This is based on Packet Tracer 5.0.

Step 1: Start Packet Tracer

Civil Aviation Training College, India Page 2


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Step 2: Selection of Devices and Connections
We will begin building our network topology by selecting devices and the media connecting them. Several
types of devices and network connections can be used. For this exercise, we will keep it simple by using
End Devices, Switches, Hubs, and Connections.

Single click on each group of devices and connections to display the various choices. The devices you see
may differ slightly.

Civil Aviation Training College, India Page 3


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Step 3: Building the Topology – Adding Hosts
Single click on the End Devices.

Single click on the Generic host.

Move the cursor into the topology area. You will notice that it turns into a plus “+” sign.

Single click in the topology area and it copies the device.

Add three more hosts in the same way.

Civil Aviation Training College, India Page 4


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Step 4: Building the Topology – Connecting the Hosts to Hubs and Switches
a) Adding a Hub

Select a hub, by clicking once on Hubs and once on a Generic hub.

Add the hub by moving the plus sign “+” below PC0 and PC1 and click once.

Connect PC0 to Hub0 by first choosing Connections.

Click once on the Copper Straight-through cable.

Civil Aviation Training College, India Page 5


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Perform the following steps to connect PC0 to Hub0:
1. Click once on PC0
2. Choose FastEthernet
3. Drag the cursor to Hub0
4. Click once on Hub0 and choose Port 0
5. Notice that green link light will appear on both the PC0 Ethernet NIC and the Hub0 Port 0 showing
that the link is active.

1 2 3 4 5

Repeat the steps above for PC1 connecting it to Port 1 on Hub0. (The actual hub port you choose does not
matter.)

Civil Aviation Training College, India Page 6


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
b) Adding a Switch

Select a switch, by clicking once on Switches and once on a 2950-24 switch.

Add the switch by moving the plus sign “+” below PC2 and PC3 and click once.

Connect PC2 to Hub0 by first choosing Connections.

Click once on the Copper Straight-through cable.

Civil Aviation Training College, India Page 7


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Perform the following steps to connect PC2 to Switch0:
1. Click once on PC2
2. Choose FastEthernet
3. Drag the cursor to Switch0
4. Click once on Switch0 and choose FastEthernet0/1
5. Notice the green link light will appear on PC2 Ethernet NIC and amber light will appear on
Switch0 FastEthernet0/1 port.
The switch port is temporarily not forwarding frames, while it goes through the stages for the
Spanning Tree Protocol (STP) process.
6. After about 30 seconds, the amber light will turn to green indicating that the port has entered the
forwarding stage. Frames can now be forwarded out of the switch port.

Note: Spanning Tree Protocol (STP) will be discussed later.

1 2 3 4 5 6

Repeat the steps mentioned above for PC3 connecting it to port FastEtherent0/2 of switch0. (The actual switch
port you choose does not matter.)

Move the cursor over the green link light to view the port number. Fa means FastEthernet, 100 Mbps Ethernet.

Civil Aviation Training College, India Page 8


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Step 5: Configuring IP Addresses and Subnet Masks on the Hosts
To communicate between the hosts, we need to configure IP Addresses and Subnet Masks on the
devices.

Click once on PC0.

Choose the Config tab and click on Settings. H e r e , you can change the name of PC0. You can also enter
a Gateway IP Address, also known as the default gateway and the DNS Server IP Address. We will discuss
this later, but the value in “default gateway address”, would be the IP address of the local router. If you want,
you can enter the Gateway IP Address [Link] and DNS Server IP Address [Link], although it will
not be used in this lab.

Civil Aviation Training College, India Page 9


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Click on Interface and then FastEthernet. Add the IP Address as [Link]. Click once in the Subnet
Mask field to enter the default Subnet Mask. You can leave this as [Link].

Also notice, here you can also change the Bandwidth (speed) and Duplex of the Ethernet NIC (Network
Interface Card). The default is Auto (auto-negotiation), which means the NIC will negotiate with the hub or
switch. The bandwidth and/or duplex can be manually set by removing the check from the Auto box and by
choosing the specific option.

Bandwidth - Auto

If the host is connected to a hub or a switch port which can support 100 Mbps, then the Ethernet NIC on
the host will choose 100 Mbps (Fast Ethernet). Otherwise, if the hub or switch port can only support 10
Mbps, then the Ethernet NIC on the host will automatically choose 10 Mbps (Ethernet).

Duplex - Auto

Hub: If the host is connected to a hub, then the Ethernet NIC on the host will choose Half Duplex.

Switch: If the host is connected to a switch, and the switch port is configured as Full Duplex (or
Autonegotiation), then the Ethernet NIC on the host will choose Full Duplex. If the switch port is configured
as Half Duplex, then the Ethernet NIC on the host will choose Half Duplex. (Full Duplex is a much more
efficient option.)

The information is automatically saved when entered.

Civil Aviation Training College, India Page 10


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
To close this dialog box, click the “X” in the upper right.

Repeat these steps for the other hosts. Use the information below for IP Addresses and Subnet Masks.

Host IP Address Subnet Mask


PC0 [Link] [Link]
PC1 [Link] [Link]
PC2 [Link] [Link]
PC3 [Link] [Link]

Verify the information

To verify the information that you entered, move the Select tool (arrow) over each host.

Deleting a Device or Link

To delete a device or link, choose the Delete tool and click on the item you wish to delete.

Civil Aviation Training College, India Page 11


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Step 6: Connecting Hub0 to Switch0
To connect like-devices, like a Hub and a Switch, we will use a Cross-over cable. Click once the Cross-over
Cable from the Connections options.

Move the Connections cursor over Hub0 and click once.

Select Port 5 (actual port does not matter).

Civil Aviation Training College, India Page 12


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Move the Connections cursor to Switch0.

Click once on Switch0 and choose FastEthernet0/4 (actual port does not matter).

The link light for switch port FastEthernet0/4 will first appear as amber and will eventually change to green as
the Spanning Tree Protocol transitions the port to forwarding.

Civil Aviation Training College, India Page 13


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Step 7: Verifying Connectivity in Realtime Mode
Be sure you are in Realtime mode.

Select the Add Simple PDU tool which are used to ping devices.

Click once on PC0, then once on PC3.

The PDU Last Status should show as Successful.

Civil Aviation Training College, India Page 14


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Resetting the Network
At this point, we want to reset the network. Whenever you want to reset the network and begin the
simulation again, perform the following tasks:

Click Delete in the PDU area.

Now, select Power Cycle Devices and confirm the action.

Waiting for Spanning Tree Protocol (STP)


Note: Because Packet Tracer also simulates the Spanning Tree Protocol, at times, the switch may show
amber lights on its interfaces. You need to wait for the lights to turn green on the switches before they will
forward any Ethernet frames.

Civil Aviation Training College, India Page 15


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Step 8: Verifying Connectivity in Simulation Mode
Be sure you are in Simulation mode.

Deselect all filters (All/None) and select only ICMP.

2
Civil Aviation Training College, India Page 16
Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Select the Add Simple PDU tool used to ping devices.

Click once on PC0, then once on PC3.

Continue clicking Capture/Forward button until the ICMP ping is completed. You should see the ICMP
messages move between the hosts, hubs and switches. The PDU Last Status should show as Successful.
Click on Clear Event List if you do not want to look at the events or click Preview Previous Events, if you
do. For this exercise, it does not matter.

Civil Aviation Training College, India Page 17


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Step 9: Saving the Topology
Perform the following steps to save the topology (uses .pkt file extension).

Opening Existing Topologies

Civil Aviation Training College, India Page 18


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Opening Existing PT Topologies

Civil Aviation Training College, India Page 19


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise No. 2: - Switch & Router Configuration

Objective: The objective of this practical exercise is to configure basic


settings on a Cisco switch and Router.
.
NETWORK DIAGRAM:

Lab instructions:
A new switch or router purchased from Cisco contains no default
configuration in it. You need to configure the switch or router with setup
mode using the setup mode or from scratch using the command line
interface (CLI) before connecting it in your network environment. It is very
important to know the basic Cisco switch or router configuration
commands to improve the performances and the security of your
internetwork.

This lab exercise will test your ability to configure basic settings on a cisco
switch and router.

Civil Aviation Training College, India Page 20


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Solution:-

Configure of Switch (SW1):


1. Configure Switch hostname.
Switch>en
Switch#config t
Switch(config)#hostname CATC
CATC(config)#

2. Configure the password for privileged mode access as "cisco"


CATC(config)#enable secret CNS

3. Configure CONSOLE access [...]


CATC(config)#line con 0
CATC(config-line)# password aai
CATC(config-line)# login

4. Configure TELNET access [...]


CATC(config)# line vty 0 15
CATC(config-line)# password dcn
CATC(config-line)# login

5. Configure the IP address of the switch as [Link]/8 and it's


default gateway IP ([Link]).

Note: This configuration is required when any host from different


network want to telnet to SW1.
CATC(config)# int vlan1

Civil Aviation Training College, India Page 21


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
CATC(config-if)# ip address [Link] [Link]

CATC(config)# ip default-gateway [Link]

Note: 1. Verify console protection from console PC

2. Verify telnet application from LAN PCs.

Router configuration:

1. Configure Router hostname :

Router >en
Router #config t
Router (config)#hostname CATC
CATC(config)#

2. Configure the password for privileged mode access as "cisco"


CATC(config)#enable secret 1234

3. Configure CONSOLE access [...]


CATC(config)#line con 0
CATC(config-line)# password 4567
CATC(config-line)# login
4. Configure TELNET access [...]
CATC(config)# line vty 0 15
CATC(config-line)# password 4321
CATC(config-line)# login

Civil Aviation Training College, India Page 22


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
5. Configure the IP address at the interface of the router:

CATC(config)#int f0/0
CATC(config-if)#ip add [Link] [Link]
CATC(config-if)#no shut
CATC(config)#int f0/1
CATC(config-if)#ip add [Link] [Link]
CATCconfig-if)#no shut

Note: 1. Verify console protection from console PC

2. Verify telnet application from network PCs.

3. Verify telnet application from different network PCs.

Civil Aviation Training College, India Page 23


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise No3: IP Routing
Task1: Configure the following network by Static Routing.

Solution:
Configure Router (R1):
R1>en
R1#config t
R1(config)#int f0/0
R1(config-if)#ip add [Link] [Link]
R1(config-if)#no shut
R1(config)#int se2/0
R1(config-if)#ip add [Link] [Link]
R1(config-if)#no shut
R1(config)#ip route [Link] [Link] [Link]
R1(config)#ip route [Link] [Link] [Link]
R1(config)#ip route [Link] [Link] [Link]

Civil Aviation Training College, India Page 24


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Configure Router(R2):
R2>en
R2#config t
R2(config)#int se2/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut
R2(config)#int f0/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut
R2(config)#int se3/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut
R2(config)#ip route [Link] [Link] [Link]
R2(config)#ip route [Link] [Link] [Link]

Configure Router (R3):


R3>en
R3#config t
R3(config)#int se2/0
R3(config-if)#ip add [Link] [Link]
R3(config-if)#no shut
R3(config)#int f0/0
R3(config-if)#ip add [Link] [Link]
R3(config-if)#no shut
R3(config)#ip route [Link] [Link] [Link]
R3(config)#ip route [Link] [Link] [Link]
R3(config)#ip route [Link] [Link] [Link]

Civil Aviation Training College, India Page 25


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Task2: Configure the following network by RIPV2.

Solution:
Configure R1:
R1>en
R1#config t
R1(config)#int f0/0
R1(config-if)#ip add [Link] [Link]
R1(config-if)#no shut
R1(config)#int se2/0
R1(config-if)#ip add [Link] [Link]
R1(config-if)#no shut
R1(config)#router rip
R1(config-router)#network [Link]
R1(config-router)#network [Link]
R1(config-router)#ver 2
R1(config-router)#no auto-summary

Civil Aviation Training College, India Page 26


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Configure R2:
R2>en
R2#config t
R2(config)#int se2/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut
R2(config)#int f0/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut
R2(config)#int se3/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut
R2(config)#router rip
R2(config-router)#network [Link]
R2(config-router)#network [Link]
R2(config-router)#network [Link]
R2(config-router)#ver 2
R2(config-router)#no auto-summary

Configure R3:
R3>en
R3#config t
R3(config)#int se2/0
R3(config-if)#ip add [Link] [Link]
R3(config-if)#no shut
R3(config)#int f0/0
R3(config-if)#ip add [Link] [Link]
R3(config-if)#no shut

Civil Aviation Training College, India Page 27


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
R3(config)#router rip
R3(config-router)#network [Link]
R3(config-router)#network [Link]
R3(config-router)#ver 2
R3(config-router)#no auto-summary

Civil Aviation Training College, India Page 28


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise No 4:Virtual LAN
Task1: Configure the Inter VLAN communication using router.

R1

Configure CNS Switch:


Switch(config)#vlan 2
Switch(config-vlan)#name CNS
Switch(config)#vlan 3
Switch(config-vlan)#name HR
Switch(config)#vlan 4
Switch(config-vlan)#name FIN
Switch(config)#Int f0
Switch(config-if)#switchport access vlan 2
Switch(config)#Int f1
Switch(config-if)#switchport access vlan 2
Switch(config)#Int f2
Switch(config-if)#switchport access vlan 2

Civil Aviation Training College, India Page 29


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Switch(config)#Int f3
Switch(config-if)#switchport mode trunk

Configure HR Switch:
Switch(config)#vlan 2
Switch(config-vlan)#name CNS
Switch(config)#vlan 3
Switch(config-vlan)#name HR
Switch(config)#vlan 4
Switch(config-vlan)#name FIN
Switch(config)#Int f0
Switch(config-if)#switchport access vlan 3
Switch(config)#Int f1
Switch(config-if)#switchport access vlan 3
Switch(config)#Int f3
Switch(config-if)#switchport mode trunk
Switch(config)#Int f4
Switch(config-if)#switchport access vlan 2

Configure Router:
R1(config)#Int f0/0
R1(config-if)#no shut down
R1(config-if)#int f0/0.1
R1(config-subif)#encapsulation dot1q 2
R1(config-subif)#ip add [Link] [Link]
R1(config-if)#int f0/0.2
R1(config-subif)#encapsulation dot1q 3
R1(config-subif)#ip add [Link] [Link]

Civil Aviation Training College, India Page 30


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Task2: Configure the Inter VLAN communication using Layer-3 Switch.

Configuration of Switch:

Switch>
Switch#config t
Switch(config)#VLAN2
Switch(config-VLAN)#name CNS
Switch(config)#VLAN3
Switch(config-VLAN)#name HR
Switch(config)#Int f0/1
Switch(config-if)#switchport access vlan 2
Switch(config)#Int f0/2
Switch(config-if)#switchport access vlan 2
Switch(config)#Int f0/3
Switch(config-if)#switchport access vlan 3
Switch(config)#Int f0/4
Switch(config-if)#switchport access vlan 3
Switch(config-if)#exit
Switch(config)#int vlan2
Switch(config-if)#ip add [Link]
Switch(config-if)#no shut

Civil Aviation Training College, India Page 31


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Switch(config)#int vlan3
Switch(config-if)#ip add [Link]
Switch(config-if)#no shut
Switch(config-if)#exit
Switch(config)#ip routing

Civil Aviation Training College, India Page 32


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise No 5: Introduction to Network emulation software (GNS3 ).
Task: Familiarization of GNS3 simulation software in the Data Communication
Networking LAB.

Civil Aviation Training College, India Page 33


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise No 6: Multicasting Demo.
Task: Configuration of Multicasting of any small network by the instructor.

Civil Aviation Training College, India Page 34


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise No 7: Network Analyzer tool.
Task: Familiarization of Wireshark network analyzer tools.

Civil Aviation Training College, India Page 35


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise No 8: Configure VRRP. All IPs are considered classful.

Step1: Configure IP Address to all the interfaces of the router and host.
Step2: Configure Routing by RIPV2.
Step3: Configure VRRP
Router R1 Configuration:
R1(Config)#int f0/0
R1(config-if)#vrrp 123 ip [Link]
R1(config-if)#vrrp 123 preempt
R1(config-if)#vrrp 123 priority 120
R1(config)#track 1 int f1/0 line-control
R1(config)#int f0/0
R1(config-if)#vrrp 123 track 1 decrement 40
Router R2 Configuration:
R2(Config)#int f0/0
R2(config-if)# vrrp 123 ip [Link]

Router R3 Configuration:
R3(Config)#int f0/0
R3(config-if)#vrrp 124 ip [Link]
R3(config-if)#vrrp 124 preempt
R3(config-if)#vrrp 124 priority 120
R3(config)#track 1 int f1/0 line-control
R3(config)#int f0/0
R3(config-if)#vrrp 124 track 1 decrement 40

Civil Aviation Training College, India Page 36


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Router R4 Configuration:
R4(Config)#int f0/0
R4(config-if)#vrrp 124 ip [Link]

Civil Aviation Training College, India Page 37


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Cyber Security
Exercise No 9: Configure Switch-Port Security:

Create above network topology in Cisco Packet tracer and perform following
exercises –

Task1: Perform restrict mode in switch:

Configure switch port security on interface Fa 0/1 of the switch with the
following settings:
- Port security: enabled
- Mode: restrict
- Allowed mac addresses: 3
- Dynamic mac address learning.

Command used:
#interface FastEthernet0/1
#switchport mode access
#switchport port-security
#switchport port-security maximum 3

Civil Aviation Training College, India Page 38


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
#switchport port-security mac-address sticky
#switchport port-security violation restrict

Status of port security and interface:

Switch# show port-security


Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security
Action
(Count) (Count) (Count)
------------------------------------------------------------------------------------------
-----
Fa0/1 3 3 0 Restrict
------------------------------------------------------------------------------------------
-----
Switch#show port-security interface fa0/1
Port Security : Enabled
Port Status : Secure-up
Violation Mode : Restrict
Aging Time : 0 mins
Aging Type : Absolute
Secure Static Address Aging : Disabled
Maximum MAC Addresses :3
Total MAC Addresses :3
Configured MAC Addresses :0
Sticky MAC Addresses :3
Last Source Address:Vlan : 0090.cc0e.5023:1
Security Violation Count :0

Now observe when Intruder laptop is connected to the hub and tries to
communicate with PC0 ([Link]), the number of mac-addresses
learned on fa0/1 interface exceeds 3. The interface drops traffic with the
new mac-address (not learned by the switch because 3 mac addresses
have already been registered on the fa0/1 interface) and increases the
security violation counter based on the 'restrict' port-security
configuration of the interface.

Status of port after violation:

Civil Aviation Training College, India Page 39


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Switch# show port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security
Action
(Count) (Count) (Count)
------------------------------------------------------------------------------------------
-----
Fa0/1 3 3 1 Restrict
------------------------------------------------------------------------------------------
-----
Switch#show port-security interface fa0/1
Port Security : Enabled
Port Status : Secure-up
Violation Mode : Restrict
Aging Time : 0 mins
Aging Type : Absolute
Secure Static Address Aging : Disabled
Maximum MAC Addresses :3
Total MAC Addresses :3
Configured MAC Addresses :0
Sticky MAC Addresses :3
Last Source Address:Vlan : 0090.cc0e.5023:1
Security Violation Count :1

Task 2: Perform shutdown mode in switch:

Configure port security on interface Fa 0/2 of the switch with the following
settings:
- Port security enabled
- Mode: shutdown (default)
- Allowed mac addresses: 1 (default)
- Dynamic mac address learning.

Command used:
#interface FastEthernet0/2
#switchport mode access
#switchport port-security
#switchport port-security maximum 1

Civil Aviation Training College, India Page 40


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
#switchport port-security mac-address sticky

Status of port security and interface:

Switch# show port-security


Secure Port Max Secure Addr Current Addr Security Violation Security
Action
(Count) (Count) (Count)
------------------------------------------------------------------------------------------
-----
Fa0/1 3 3 1 Restrict
Fa0/2 1 0 0
Shutdown
------------------------------------------------------------------------------------------
-----
Switch#show port-security interface fa0/2
Port Security : Enabled
Port Status : Secure-up
Violation Mode : Shutdown
Aging Time : 0 mins
Aging Type : Absolute
Secure Static Address Aging : Disabled
Maximum MAC Addresses :1
Total MAC Addresses :1
Configured MAC Addresses :0
Sticky MAC Addresses :0
Last Source Address:Vlan : 0090.cc0e.5023:1
Security Violation Count :0

Observed that interface Fast Ethernet 0/2 configuration - Shutdown mode


(default) connect one end device at fa0/2 and check communication (ping)
with PC0 ([Link]), which working normal. Now connect intruder
device with fa0/2 after disconnecting previously connected device and try
to communicate (ping) with PC0 ([Link]).
Now the port-security shutdown mode puts the interface into the error-
disabled state immediately as mac learning reached beyond 1 and sends
an SNMP trap notification.

Civil Aviation Training College, India Page 41


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Status of port security and interface after violation:

Switch# show port-security


Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security
Action
(Count) (Count) (Count)
------------------------------------------------------------------------------------------
-----
Fa0/1 3 3 1 Restrict
Fa0/2 1 1 1
Shutdown
------------------------------------------------------------------------------------------
-----
Switch#show port-security interface fa0/2
Port Security : Enabled
Port Status : Secure-up
Violation Mode : Shutdown
Aging Time : 0 mins
Aging Type : Absolute
Secure Static Address Aging : Disabled
Maximum MAC Addresses :1
Total MAC Addresses :1
Configured MAC Addresses :0
Sticky MAC Addresses :1
Last Source Address:Vlan : 0090.cc0e.5023:1
Security Violation Count :1

Task3: Perform protect mode in switch:

Configure port security on interface Fa 0/4 of the switch with the following
settings:
- Port security enabled
- Mode: protect
- Static mac address entry: mac address of device connected at Fa0/4
Command
#interface FastEthernet0/4
#switchport mode access

Civil Aviation Training College, India Page 42


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
#switchport port-security
#switchport port-security maximum 2
#switchport port-security mac-address 0005.5E24.7875
#switchport port-security violation protect

Status of port security and interface:

Switch# show port-security


Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security
Action
(Count) (Count) (Count)
------------------------------------------------------------------------------------------
-----
Fa0/1 3 3 1 Restrict
Fa0/2 1 1 1
Shutdown
Fa0/4 2 1 0 Protect
------------------------------------------------------------------------------------------

Switch#show port-security interface fa0/4


Port Security : Enabled
Port Status : Secure-up
Violation Mode : Protect
Aging Time : 0 mins
Aging Type : Absolute
Secure Static Address Aging : Disabled
Maximum MAC Addresses :2
Total MAC Addresses :1
Configured MAC Addresses :1
Sticky MAC Addresses :0
Last Source Address:Vlan : 0005.5E24.7875
Security Violation Count :0

Civil Aviation Training College, India Page 43


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Status of port security and interface after violation:
Observed that in this case port-security protect mode silently drops
packets with unknown source addresses (MAC)-

Switch# show port-security


Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security
Action
(Count) (Count) (Count)
------------------------------------------------------------------------------------------
-----
Fa0/1 3 3 1 Restrict
Fa0/2 1 1 1
Shutdown
Fa0/4 2 2 0 Protect
------------------------------------------------------------------------------------------
-----

Here you can see violation is not reported by port.

Civil Aviation Training College, India Page 44


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise 10: Access-List Configuration
Task1: Host ([Link]) is denied access for the [Link] network. All IPs
are considered classful.

Solution: According to the given task, we are denying access to a single host.
Therefore, we configured a standard access-list.
1. Apply the access-list near the destination, i.e., on R2.
2. Apply it outbound on the F0/0 interface of the R2 router.

R2(config)#access-list 10 deny host [Link]


R2(config)#access-list 10 permit any
R2(config)#int f0/1
R2(config-if)#ip access-group 10 out

Civil Aviation Training College, India Page 45


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Task2: Host ([Link]) is denied access icmp for the [Link] host. All IPs
are considered classful.

Solution: According to the given task, we are denying access to a host icmp protocol
with any one host. Therefore, we configured a Extended access-list.
1. Apply the access-list near the Source, i.e., on R1.
2. Apply it inbound on the F0/0 interface of the R1 router.

R1(config)#access-list 100 deny icmp [Link] [Link] [Link] [Link]


R1(config)#access-list 100 permit ip any any
R1(config)#int f0/1
R1(config-if)#ip access-group 100 in

Civil Aviation Training College, India Page 46


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Task3: Host ([Link]) is denied access for Web Services. All IPs are
considered classful.

Solution: According to the given task, we are denying access to a host for web service.
Therefore, we configured a Extended access-list.
1. Apply the access-list near the Source, i.e., on R1.
2. Apply it inbound on the F0/0 interface of the R1 router.

R1(config)#ip access-list extended abcd


R1(config)#deny tcp [Link] [Link] any eq 80
R1(config)#permit ip any any
R1(config)#int f0/1
R1(config-if)#ip access-group abcd in

Civil Aviation Training College, India Page 47


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Task4: Host ([Link]) is only permit for telnet to Router R3. All IPs are
considered classful.

Solution: According to the given task, we are denying access to a host for web service.
Therefore, we configured a Extended access-list.
1. Apply the access-list near the Source, i.e., on R1.
2. Apply it inbound on the F0/0 interface of the R1 router.

R1(config)#access-list 110 permit tcp [Link] [Link] any eq 23


R1(config)#access-list 110 deny ip any any
R1(config)#int f0/1
R1(config-if)#ip access-group 110 in

Civil Aviation Training College, India Page 48


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise 11: Basic Firewall Configuration
A firewall is a hardware or software network security device that monitors all incoming
and outgoing traffic based on a defined set of security rules, it accepts, rejects, or drops
that specific traffic.

 Accept: Allow traffic.


 Reject: Block traffic but respond with “reachable error”.
 Drop: Block unanswered traffic firewall establishes a barrier between secure
internal networks and untrusted external networks, such as the Internet.

Steps to Configure and Verify Firewall in Cisco Packet Tracer:

Step 1: First, open the Cisco packet tracer desktop and select the devices
given below:

[Link] Device Model Name Quantity

1. PC PC 3

2. server PT-Server 1

3. switch PT-Switch 1

IP Addressing Table:

[Link] Device IPv4 Address Subnet Mask

1. Server [Link] [Link]

2. PC0 [Link] [Link]

3. PC1 [Link] [Link]

Civil Aviation Training College, India Page 49


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
[Link] Device IPv4 Address Subnet Mask

4. PC2 [Link] [Link]

 Then, create a network topology as shown below the image.


 Use an Automatic connecting cable to connect the devices with others.

Server with
Firewall

Step 2: Configure the PCs (hosts) and server with IPv4 address and Subnet Mask
according to the IP addressing table given above.
 To assign an IP address in PC0, click on PC0.
 Then, go to desktop and then IP configuration and there you will IPv4 configuration.
 Fill IPv4 address and subnet mask.
 Repeat the same procedure with the server

Civil Aviation Training College, India Page 50


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________

 Assigning an IP address using the ipconfig command, or we can also assign an IP


address with the help of a command.
 Go to the command terminal of the PC.
 Then, type ipconfig <IPv4 address><subnet mask><default gateway>(if needed)

Example: ipconfig [Link] [Link]

 Repeat the same procedure with other PCs to configure them thoroughly.

Civil Aviation Training College, India Page 51


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Step 3: Configuring the firewall in a server and blocking packets and allowing
web browser.

 Click on server0 then go to the desktop.


 Then click on firewall IPv4.
 Turn on the services.
 First, Deny the ICMP protocol and set remote IP to [Link] and Remote wildcard
mask to [Link].
 Then, allow the IP protocol and set remote IP to [Link] and Remote wildcard mask
to [Link].
 And add them.

Step 4: Verifying the network by pinging the IP address of any PC.

 We will use the ping command to do so.


 First, click on PC2 then Go to the command prompt.
 Then type ping <IP address of targeted node>.
 We will ping the IP address of the server0.

Civil Aviation Training College, India Page 52


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
 As we can see in the below image we are getting no replies which means the packets
are blocked.

Check the web browser by entering the IP address in the URL.

 Click on PC2 and go to desktop then web browser.

Civil Aviation Training College, India Page 53


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise 12: Network Address Translation (NAT)

Task1: Configure static NAT. All IPs are considered classful.

Configuration R1 (Router R1 as a NAT Device)

R1>enable
R1#config t
R1(config)#interface F0/0
R1(config-if)#ip address [Link] [Link]
R1(config-if)#no shut
R1(config-if)#ip nat inside
R1(config)#interface Serial0
R1(config-if)#ip address [Link] [Link]
R1(config-if)#no shut
R1(config-if)#ip nat outside
R1(config)#ip nat inside source static [Link] [Link]
R1(config-if)#exit
R1(config)#ip route [Link] [Link] [Link]
(Configure static routing in R1 Router only)

Civil Aviation Training College, India Page 54


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Configuration R2

R2>en
R2#config t
R2(config)#int se2/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut
R2(config)#int f0/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut

Note: verify NAT configuration by sending packet from source ip [Link] to


destination ip [Link] or [Link].

See the NAT table by command given below:


R2#show nat translation

Civil Aviation Training College, India Page 55


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Task2:: Configure Dynamic NAT. All IPs are considered classful.

Configuration R1 (Router R1 as a NAT Device)

R1>enable
R1#config t
R1(config)#interface F0/0
R1(config-if)#ip address [Link] [Link]
R1(config-if)#ip nat inside
R1(config)#interface Se2/0
R1(config-if)#ip address [Link] [Link]
R1(config-if)#ip nat outside
R1(config)#ip nat pool CATC [Link] [Link] netmask [Link]
R1(config)#ip nat inside source list 1 pool CATC
R1(config)#access-list 1 permit [Link] [Link]
R1(config)#ip route [Link] [Link] [Link]

(Configure static routing in R1 Router only)

Civil Aviation Training College, India Page 56


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Configuration R2

R2>en
R2#config t
R2(config)#int se2/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut
R2(config)#int f0/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut

Note: verify NAT configuration by sending packet from source ip [Link] to


destination ip [Link] or [Link].

See the NAT table by command given below:


R2#show nat translation

Civil Aviation Training College, India Page 57


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Task3:: Configure PAT overloading. All IPs are considered classful.

Configuration R1 (Router R1 as a NAT Device)

R1>enable
R1#config t
R1(config)#interface F0/0
R1(config-if)#ip address [Link] [Link]
R1(config-if)#ip nat inside
R1(config)#interface Se2/0
R1(config-if)#ip address [Link] [Link]
R1(config-if)#ip nat outside
R1(config)#ip nat pool globalnet [Link] [Link] netmask [Link]
R1(config)# ip nat inside source list 1 pool globalnet overload
R1(config)#access-list 1 permit [Link] [Link]
R1(config)#ip route [Link] [Link] [Link]

(Configure static routing in R1 Router only)

Civil Aviation Training College, India Page 58


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Configuration R2

R2>en
R2#config t
R2(config)#int se2/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut
R2(config)#int f0/0
R2(config-if)#ip add [Link] [Link]
R2(config-if)#no shut

Note: verify NAT configuration by sending packet from source ip [Link] to


destination ip [Link] or [Link].

See the NAT table by command given below:


R2#show nat translation

Civil Aviation Training College, India Page 59


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Exercise-13 LINUX

Task 1:

a) Make two directory named under /home


b) Make a file DCN1 under/ home/< dir>/
c) Check the file permission & change its permission of the owner with 755
d) Copy the file under /tmp & move the file in /home/<dir2>.
e) Change the name of the file DCN1 to DCN2.

STEPS OF Task 1:

a) Make two directory named under /home

# cd /home //To change the directory to home directory.


# mkdir dir1 dir2 //To make two directories
b) Make a file DCN1 under/ home/< dir>/

# cd /home/dir1 //To change directory.


# touch DCN1 //To create a file named DCN1
c) Check the file permission & change its permission of the owner with 755

# cd /home/dir1 //To change directory.


# ls -latr //To list the files.
# chmod 755 DCN1 //To change the file permission.
d) Copy the file under /tmp & move the file in /home/<dir2>.

# cd /home/dir1 // To change directory.


# cp -p DCN1 /tmp //To copy DCN1 file to tmp directory.
#mv DCN1 /home/dir2 //To move DCN1 file to tmp directory.
e) Change the name of the file DCN1 to DCN2

# cd /home/dir2 // To change directory.


# mv DCN1 DCN2 //To change the file name.

Civil Aviation Training College, India Page 60


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________

Task 2:

a) Create a directory under /home


b) Create three files under /home/<dir>
c) Check the size of the directory
d) Make the tar file of the directory & zip it.
e) Copy the zip file to /tmp dir
f) Unzip & extract the contents.
g) Remove the tar file from /tmp.

STEPS OF Task 2:

a) Create a directory under /home

#cd /home //To change the directory.


#mkdir dir1 //To make a directory under home directory.
b) Create three files under /home/<dir>

#cd /home/dir1 //To change the directory


#touch file1 file2 file3 //To create three files under /home/dir1 directory
c) Check the size of the directory

#cd /home/dir1 //To change the directory


#du -h //To check the size of directory. ‘-h’ for human readable format.
d) Make the tar file of the directory & zip it.

#cd /home //To change the directory.


#tar -zcvf [Link] dir1 //To tar and zip.

e) Copy the zip file to /tmp directory

Go to home directory and execute the following commands:


#cp -p [Link] /tmp //To copy the tar and zip file to /tmp directory.
f) Unzip & extract the contents.

#cd /tmp //To change the directory.


#tar -zxvf [Link] //To unzip and untar the tar and zip file.

Civil Aviation Training College, India Page 61


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
g) Remove the tar file from /tmp.

#rm -f [Link] //To remove the file.

Task 3:

Use date command to set date to 07:30 Hrs 10/03/2024.


Using date command format output as
a) ddmmyyyy
b) mmddyyyy
c) dd/mm/yyyy
d) dd/mm/yy

STEPS OF Task 3:
Use date command to set date to 07:30 Hrs 10/03/2024.
Using date command format output as

# date //To check the current date and time


a) ddmmyyyy

#date “+%d%m%Y” //To view the date in ddmmyyyy format.


b) mmddyyyy

#date “+%m%d%Y” //To view the date in mmddyyyy format.


c) dd/mm/yyyy

#date “+%d/%m%Y” //To view the date in dd/mm/yyyy format.


d) dd/mm/yy

#date “+%d/%m/%y” //To view the date in dd/mm/yy format.

Civil Aviation Training College, India Page 62


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Task 4:

Use find command to search a file in a given path:


a) By type
b) By size
c) By name

STEPS OF Task 4:
Use find command to search a file in a given path:
a) By type

#find / -type f -print //To find the files inside ‘/’ directory. ‘f’ means to search by file type.
Similarly, ‘d’ means directory and ‘l’ means link file.
b) By size

#find /home -size +10c //To find files and directories of size greater than 10 bytes inside
home directory.
#find /home -size +1G // To find files and directories of size greater than 1 Gb inside home
directory.
c) By name

#find / -name file1 //To find a file named ‘file1’ inside ‘/’ directory.

Task 5:

Use grep, tail, and head command to:

a) Search a string from a given file[s]/directory


b) Show first 15 lines of the file
c) Show last 20 files of the file

STEPS OF Task 5:
Use grep, tail, and head command to:

a) Search a string from a given file[s]/directory

#ls -l|grep ab //To list all files having ‘ab’ pattern.


#cat file1|grep the* //To search for ‘the’ pattern inside file1
b) Show first 15 lines of the file

Civil Aviation Training College, India Page 63


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
#head -n 15 filename //To show first 15 lines of a file.
c) Show last 20 files of the file

#tail -n 20 filename //To list last 20 lines of a file.

Task 6:

a) Create a directory with the name CATC1 & CATC2 under/ home
b) Make a file with the name ‘file1’ under under /home/CATC1
c) Write some contents under the file
d) Insert a USB drive in the system
e) Mount it under/mnt
f) Copy ‘file1’ file into pendrive & restore this file in /CATC2
g) Remove the pen drive properly

STEPS OF Task 6:

a) Create a directory with the name CATC1 & CATC2 under/ home

#mkdir /home/CATC1 /home/CATC2 //To make two directories inside home directiory.
b) Make a file with the name ‘file1’ under under /home/CATC1

#cd /home/CATC1 //To change the directory.


#touch file1 //To create a file named ‘file1’.
c) Write some contents under the file

#vi file1 //To write some content in ‘file1’ using vi editor.


d) Insert a USB drive in the system.

#fdisk -l //To list the device partition. (output will be like /dev/sdb1 ********)
e) Mount it under/mnt.

#mount /dev/sdb1 /mnt //To mount the external device partition to /mnt directory.
f) Copy ‘file1’ file into pendrive & restore this file in /CATC2

#cp -p /home/CATC1/file1 /mnt //To copy ‘file1’ from CATC1 directory to /mnt directory i.e.
the pendrive..
#cd /mnt

Civil Aviation Training College, India Page 64


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
#cp -p file1 /home/CATC2 //To copy the file from pendrive. to CATC2 directory.
g) Remove the pen drive properly

#umount /mnt //To unmount the pendrive.

Task 7:

a) Create a user with the name cns & password root1


b) Create a groupuser with the name naa
c) Add cns into naa
d) Log in with this user cns with the above-mentioned password.
e) Create a directory with the name CATC4 under /home/cns
f) Create a file with the name DCN3 under /home/cns/CATC4/ with some contents.
g) Check the feature (creation/modification date and time) of the file with ls –al.
h) Now change the permission for group user as r—for naa (group user), Owner (CNS) has
permission rwx & others have r--

STEPS OF Task 7:

a) Create a user with the name cns & password root1

#useradd cns //To create a user with name as cns.


#id cns //To check if cns user created or not
#passwd cns //To set the password of ‘cns’ user. Enter password as root1 for cns user in
prompt.
b) Create a groupuser with the name naa

#groupadd naa //To create a group with name ‘naa’.


c) Add cns into naa

#usermod -G naa cns //To add cns user in ‘naa’ group.


d) Log in with this user cns with the above-mentioned password.

#su – cns //To switch user to ‘cns’ user. Enter the password root1.
e) Create a directory with the name CATC4 under /home/cns

[cns@localhost ~]$mkdir /home/cns /CATC4 //To create a directory named ‘CATC4’ under
/home/cns directory of cns user.
f) Create a file with the name DCN3 under /home/cns/CATC4/ with some contents.

Civil Aviation Training College, India Page 65


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
#[cns@localhost ~]$touch /home/cns/CATC4/DCN3 //To make a file named ‘DCN3’ under
/home/cns/CATC4 directory of cns user.
g) Check the feature (creation/modification date and time) of the file with ls –al.

#[cns@localhost ~]$ cd /home/cns


#[cns@localhost ~]$ls -al //To list all the files inside the directory
h) Now change the permission for group user as r—for naa (group user), Owner (CNS) has
permission rwx & others have r—

#[cns@localhost ~]$chmod 744 /home/cns/CATC4 //To set the given permission for the
file[CATC4].

Task 8: Refer section “vi editor” for this task.

a) Create a file named file2 by vi command and write some text in the file
b) Edit the document by inserting & deleting a line, words, & characters
c) Copy another line & undo it
d) Save the file
e) Continue with the same document & put additional information on the same document
f) Now save it & quit

STEPS OF Task 8: Refer section “vi editor” for this task.

a) Create a file named file2 by vi command and write some text in the file.
#vi /home/file2 //To create file2 under home directory. Use vi commands to write some text
in file.
b) Edit the document by inserting & deleting a line,words & characters
c) Copy another line & undo it
d) Save the file
e) Continue with the same document & put additional information on the same document
f) Now save it & quit.

Civil Aviation Training College, India Page 66


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Task 9:

Create schedule tasks as follows:


a) Create a dir under /home with name CATC5 and file with some contents with name file4 under
/home/CATC5/
b) Create a program to take a copy of file4 as tar and zipped file with name as backup_file4.[Link]
and to move file4 under /tmp.
c) Create a program to execute the above task mentioned in point (b) daily at 04:30 IST.

STEPS OF Task 9:

Create schedule tasks as follows:


a) Create a dir under /home with name CATC5 and file with some contents with name file4
under /home/CATC5/

#mkdir /home/CATC5 //To make a directory ‘CATC5’ under home directory.


#cd /home/CATC5 //To change directory to CATC5
#vi file4 //To create and add some content in file4 using vi editor.
b) Create a program to take a copy of file4 as tar and zipped file with name as
backup_file4.[Link] and to move file4 under /tmp.

#touch /home/script //To create a file named script under home directory.
#chmod 777 /home/script //To change the permission of script file so, that it becomes an
executable file.
#vi /home/script //To open script file with vi editor.
Write down following content in the script file:
cd /home/CATC5
tar -zcvf backup_file4.[Link] file4
mv file4 /tmp

c) Create a program to execute the above task mentioned in point (b) daily at 04:30 IST.

#crontab -l //To list all the scheduled cron jobs.


#crontab -e //To edit the cron job. After execution of this command a vi-editor window will
open and the following line:
30 04 * * * /home/script

Civil Aviation Training College, India Page 67


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Task 10:

Assign an IP=[Link] to the eth0 port of a Linux machine.

STEPS OF Task 10:

Assign an IP=[Link] to the eth0 port of a Linux machine.

#cd /etc/sysconfig/network-scripts //To go to network-scripts directory.


#ls //To list the files in this directory.
#vi ifcfg-eth0 //To edit the file ‘ifcfg-eth0’ in the network-scripts directory for assigning the IP to
eth0 port. Edit the IP address field of ifcfg-eth0 with vi and save.
#ifdown eth0 //To shutdown eth0 port.
#ifup eth0 //To up the eth0 interface.
#ifconfig -a //To check the IP address of all the ports.
Note: We executed ifdown and ifup commands above to make the IP change effective.

Task 11:

How to capture the data on eth0 port of a Linux machine.

STEPS OF Task 11:

How to capture the data on eth0 port of a Linux machine.

#tcpdump -i eth0 //To capture the data on eth0 port.

Civil Aviation Training College, India Page 68


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Annexure-A

Configuration to bring Radar data from source station to receiving station Example

Radar data from Station A need to be sent to Station B through FTI IP Circuit.

Configuration of Site A Router


Router_A>ena
Router_A#
Router_A#conf t
Router_A(config)#ip multicast-routing

Router_A(config)#int fa0/1
Router_A(config-if)#description Radar_In
Router_A(config-if)#ip address [Link] [Link]
Router_A(config-if)#ip pim sparse-mode
Router_A(config-if)#ip igmp static-group [Link]
Router_A(config-if)#ip pim neighbor-filter 11
Router_A(config-if)#exit

Router_A(config)#int fa0/0
Router_A(config-if)#description Radar WAN FTI to Site B
Router_A(config-if)#ip address [Link] [Link]

Civil Aviation Training College, India Page 69


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Router_A(config-if)#ip pim sparse-mode
Router_A(config-if)#ip igmp static-group [Link]
Router_A(config-if)#exit

Router_A(config)#interface loopback1
Router_A(config-if)#description RP_for_Radar
Router_A(config-if)# ip address [Link] [Link]
Router_A(config-if)# ip pim sparse-mode
Router_A(config-if)#exit

Router_A(config)#ip pim rp-address [Link] site_A_radar_rp override

Router_A(config)#ip access-list standard 11


Router(config-std-nacl)# deny any
Router(config-std-nacl)#exit

Router_A(config)#ip access-list standard site_A_radar_rp


Router_A(config-std-nacl)#permit host [Link]
Router_A(config-std-nacl)#exit
Router_A(config)#exit
Router_A#wr

Configuration of Site B Router


Router_B>ena
Router_B#
Router_B#conf t
Router_B(config)#ip multicast-routing

Router_B(config)#int fa0/1
Router_B(config-if)#description Site_A Radar to Auto_LAN
Router_B(config-if)#ip address [Link] [Link]
Router_B(config-if)#ip pim sparse-mode

Civil Aviation Training College, India Page 70


Module-3 Practical Exercise
Data Communication Networking, Cyber security and Linux
______________________________
Router_B(config-if)#ip igmp version 2
Router_B(config-if)#ip igmp static-group [Link]
Router_B(config-if)#exit

Router_B(config)#int fa0/0
Router_B(config-if)#description Radar WAN FTI from Site A
Router_B(config-if)#ip address [Link] [Link]
Router_B(config-if)#ip pim sparse-mode
Router_B(config-if)#ip igmp static-group [Link]
Router_B(config-if)#exit

Router_B(config)#ip pim rp-address [Link] site_A_radar_rp override

Router_B(config)#ip access-list standard site_A_radar_rp


Router_B(config-std-nacl)#permit host [Link]
Router_B(config-std-nacl)#exit
Router_B(config)#ip route [Link] [Link] [Link]
Router_B(config)#exit
Router_B#wr

Civil Aviation Training College, India Page 71


ATSEP CBTA
NON-PLI
DATA
COMMUNICATION
NETWORKING, CYBER
SECURITY AND LINUX

Contents

 Introduction to Network emulation software (CISCO Packet


tracer)
 Basic switch and Router configuration
 IP Routing
 VLAN
 Introduction to Network emulation software (GNS3 )
 Multicasting demo
 Network Analyzer tool
 VRRP
 Switch port security
 Access List
 Firewall
 NAT
 LINUX Commands Exercise
 Annexure-A

AAI/ANS/CNS/CATC/2024/NON-PLI
सी.ए.टी.सी., प्रयागराज TRNG/DATA COMMUNICATION
NETWORKING/CYBER-SECURITY/
LINUX/MOD 3/Ver.1.0
C.A.T.C., PRAYAGRAJ

Common questions

Powered by AI

Static NAT maps a specific private IP address to a specific public IP address, configured using 'ip nat inside source static' command. For example, mapping 10.0.0.2 to 20.0.0.3 . Dynamic NAT assigns a private IP to a public IP from a NAT pool, using 'ip nat pool' and 'ip nat inside source list' commands. It offers more flexibility than Static NAT because it allows multiple users to share a pool of public IPs .

To configure inter VLAN communication using a router, first, create VLANs on the switch using commands like 'Switch(config)#vlan 2' and 'Switch(config-vlan)#name CNS'. Assign VLANs to interfaces, e.g., 'Switch(config-if)#switchport access vlan 2' for interface f0. Similar configurations are applied for VLANs 3 and 4. After ensuring VLANs are configured on the switch, connect the router to the switch with trunking enabled to allow traffic between VLANs .

Denying ICMP improves security by preventing ping sweeps and other reconnaissance activities commonly used by attackers to map network topology. Allowing IP after denying ICMP enables legitimate traffic while still blocking potential probing attempts. This approach restricts malicious attempts at network discovery without interrupting essential IP-based traffic, which is crucial for maintaining normal operations while enhancing security .

Restrict mode on a switch port involves enabling port security, setting the mode to restrict, and allowing a maximum of 3 MAC addresses dynamically learned. Use commands like '#interface FastEthernet0/1', '#switchport mode access', and '#switchport port-security violation restrict'. When an intruder connects beyond this limit, the port security status remains 'Secure-up', with the violation count increasing, but without shutting down the port. The switch drops packets from the new unregistered MAC address .

Verifying console and Telnet access configurations ensures that only authorized users can manage network devices, preventing unauthorized access and potential security breaches. Methods to verify include attempting console login directly from a connected PC and testing Telnet connectivity from different network PCs to ensure remote management is properly secured. This process also verifies that password protections are correctly implemented as configured .

Creating directories with 'mkdir' and files with 'touch', and moving them with 'cp' and 'mv' are fundamental Linux file operations. Permissions, managed by 'chmod', dictate who can modify or execute files. For example, setting permissions to 755 allows the owner full access, while others can only read or execute, impacting how files can be shared or secured in multi-user environments .

Configuring a router for RIPV2 involves enabling RIP with 'router rip' and specifying networks to advertise using 'network' commands. For example, on R2, the commands 'R2(config-router)#network 20.0.0.0' and 'R2(config-router)#network 30.0.0.0' configure RIP for specific networks. 'R2(config-router)#ver 2' specifies RIP version 2, and 'R2(config-router)#no auto-summary' prevents the router from summarizing routes to their classful boundaries, allowing for more precise routing across subnetworks .

The amber light indicates that the switch port is in a transitional blocking state while the Spanning Tree Protocol (STP) is determining the network topology to avoid loops. It temporarily prevents frame forwarding for around 30 seconds. Once STP confirms no loops exist and the port is safe for forwarding, it changes to green, signifying active forwarding .

'Restrict' mode keeps the port active after a security violation, dropping unauthorized packets silently and logging the event. The switch does not shut down the interface. In contrast, 'shutdown' mode disables the port upon a security violation, requiring manual intervention to re-enable it. 'Restrict' is less disruptive, while 'shutdown' provides a stronger response to potential unauthorized access .

PAT assigns multiple private IP addresses to a single public IP by using different ports, unlike Static NAT, which binds one-to-one, and Dynamic NAT, which maps multiple users to a range of public IPs. PAT efficiently uses a single public IP to serve connections by using port numbers to distinguish between them, ideal for networks where public IP addresses are limited .

You might also like