Muhammad Shakeel Ashraf
CCNP
ISCW LAB MANUAL
Prepared by:
MUHAMMAD SHAKEEL ASHRAF
0092-300-4772177
shakeel-ashraf@[Link]
Under kind supervision of
SIR HAROON AHMAD MALIK
CORVIT SYSTEMS/SOLUTIONS
Gulberg, Lahore, Pakistan
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 1
TABLE OF CONTENTS
COURSE OUTLINE............................................................3
CABLE TECHNOLOGY / HFC....................................................4
HFC NETWORK (HYBRID FIBER-COAX NETWORK) ........................................ 4
LAST-MILE TECHNOLOGY ........................................................... 4
SINGLE LINE ISP ................................................................ 5
16 LINES ISP ................................................................... 5
120 LINES ISP .................................................................. 6
SNR (SIGNAL-TO-NOISE RATIO) .................................................... 6
CATV (Community Antenna Television) ............................................ 7
DOCSIS (Data Over Cable Specification Interface Service) ....................... 7
UPSTREAM ....................................................................... 8
DOWNSTREAM ..................................................................... 9
ROUTER MODES.............................................................10
USER EXEC MODE (User Mode): ................................................... 10
PRIVILEGED EXEC MODE (Enable Mode) ............................................ 10
GLOBAL CONFIGURATION MODE ..................................................... 11
PRIVILEGE LEVELS.........................................................12
HOW TO CHECK PRIVILEGE LEVEL .................................................. 12
CHANGING PRIVILEGE LEVEL OF USER EXEC MODE .................................... 12
CHANGING PRIVILEGE LEVEL OF PRIVILEGE EXEC MODE ............................... 13
HOW TO CREATE LEVELS .......................................................... 13
ASSIGNING COMMANDS TO PRIVILEGE EXEC MODE ..................................... 14
ASSIGNING COMMANDS TO PRIVILEGE CONFIGURE MODE ................................ 15
ASSIGNING COMMANDS TO PRIVILEGE ROUTER MODE ................................... 15
AAA SERVER...............................................................16
RADIUS SERVER............................................................16
AUTHENTICATION SERVER....................................................16
ACCESS CONTROL...........................................................17
LOCAL DATABASE...........................................................18
APPLYING AUTHENTICATION FOR TRUSTED USER ...................................... 18
APPLYING AUTHENTICATION FOR NON TRUSTED USER .................................. 19
APPLYING AUTHENTICATION ON CONSOLE PORT USING LABEL ........................... 19
AUTHENTICATION FOR VTY USING LABEL ............................................ 19
LOGIN ATTEMPTS ................................................................ 20
FAIL-MESSAGE .................................................................. 20
USERNAME-PROMPT & PASSWORD-PROMPT ............................................. 21
AAA SERVER (CISCO ACS / TACACS) - LAB....................................22
CISCO ACS SERVER .............................................................. 22
CISCO ACS SERVER CONFIGURATION ................................................ 23
USER SETUP............................................................................ 23
NETWORKING CONFIGURATION:............................................................. 25
INTERFACE CONFIGURATION:.............................................................. 27
ASSIGNING PRIVILEGE LEVEL TO USER (ACS) ....................................... 30
ACCESSING ROUTER-A FROM CLIENT'S WORKSTATION .................................. 31
USER ACCOUNT DISABLE OPTIONS .................................................. 32
HOW TO LIMIT LEVELS FOR TELNET USERS .......................................... 34
PPPoE (POINT-TO-POINT PROTOCOL OVER ETHERNET)............................38
VIEWS....................................................................43
VPN/IPSEC (Site-to-Site).................................................46
EZVPN....................................................................51
IPSEC over GRE...........................................................56
DMVPN (Dynamic Multipoint Virtual Private Network).......................63
SDM (Security Device Manager)............................................71
HSRP (High Availability of VPN)..........................................73
SYSLOG SERVER (KIWI SYSLOG SERVER).......................................74
TIME BASED ACCESS CONTROL LIST (ACL).....................................77
NTP SERVER...............................................................77
ATTACKS..................................................................78
RECOVERING ENCRYPTED SERVICE PASSWORD ......................................... 78
CAPTURING RUNNING CONFIGURATION ............................................... 79
RECOVERING ENABLE SECRET ...................................................... 80
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 2
GRABING PORTS USING "PORT FUCK" TOOL .......................................... 83
USING "THE ETHEREAL NETWORK ANALYZER" FOR RECOVERING RUNNING-CONFIGURATION .... 86
IOS FIREWALL.............................................................88
CBAC (CONTACT BASE ACCESS CONTROL).......................................88
IOS IDS (Intrusion Detection System).....................................93
IOS IPS (Intrusion Prevention System)....................................97
HOW TO CHECK SIGNATURES DATABASE ............................................. 100
COPYING CISCO SIGNATURES FILE INTO ROUTER .................................... 101
MPLS (Multi Protocol Label Switching)...................................102
MPLS VPNs...............................................................112
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 3
LECTURE NO. 1
23 Feb 2009
COURSE OUTLINE
Module# 1 4-5 Lectures
♦ Cable Network / HFC e.g World Call - 2 Lectures
♦ DSL Technologies e.g. Habib Rafique - 2-3 Lectures
Module# 2 4-5 Lectures
♦ MPLS Basic & Lab - 2 Lectures
♦ MPLS VPN & Lab - 2-3 Lectures
Module# 3 6-7 Lectures
♦ VPN Theory & Site-to-Site VPN - 3 Lectures
♦ Remote Access (E2VPN) - 1 Lecture
♦ DMVPN - 1 Lecture
♦ GRE - 1 Lecture
♦ HA VPNs
♦ SDM - 1 Lecture
Module# 4 6-7 Lectures
♦ AAA - 3 Lectures
♦ IOS Firewall / CBAC - 1 Lecture
♦ IOS IDS / IPS - 1 Lecture
♦ Attacks & Mitigation - 1 Lecture
♦ SSH, ACL, Switches Security - 1 Lecture
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 4
LECTURE NO. 2
27 Feb 2009
CABLE TECHNOLOGY / HFC
HFC NETWORK (HYBRID FIBER-COAX NETWORK)
A communications network (typically a cable TV network) that uses a
combination of optical fibers and coaxial cable. The fiber provides the
high-speed backbone, and the coax is used to connect end users to the
backbone. Such networks typically use matching DOCSIS cable modems at the
head end and the customer premises, providing bidirectional paths and
Internet access.
Optical fiber runs from the cable head end to neighborhoods of 500 to 2,000
subscribers. Coaxial cable runs from the optical-fiber feeders to each
subscriber. Hybrid networks provide many of fiber's reliability and
bandwidth benefits at a lower cost than a pure fiber network. As of late
1996, about 7 percent of cable systems had been upgraded to HFC.
LAST-MILE TECHNOLOGY
9 Refers to the telecommunications technology that connects the customer's
home directly to the cable or telephone company. The hardware used to
make the connection between the Internet customer and the ISP is called
the last-mile channel. Last-mile technologies typically include dial-up
access, ISDN (Integrated Services Digital Network), DSL (Digital
Subscriber Line), cable modem access, wireless access, and leased-
circuit access. Each type of last-mile technology requires a specific
type of hardware to make the connection and specific software protocols
to manage the data movement. Some ISPs can offer several types of last-
mile technology; others can offer only one type. The last-mile
technology you’ll choose depends on the type of hardware and connections
you have available at your home or business.
9 Last-mile technology is any telecommunications technology, such as
wireless radio, that carries signals from the broad telecommunication
along the relatively short distance (hence, the "last mile") to and from
the home or business. Or to put it another way: the infrastructure at
the neighborhood level. In many communities, last-mile technology
represents a major remaining challenge to high-bandwidth applications
such as on-demand television, fast Internet access, and Web pages full
of multimedia effects.
Today, in addition to "plain old telephone (dial-up) service", last-mile
technologies to deliver voice, data, and TV can include:
• ISDN, a somewhat faster technology than regular phone service
• Digital Subscriber Line (DSL) over existing telephone twisted pair
lines
• Cable and the cable modem for data, using the same installed
coaxial cable that already is used for television
• wireless, including services such as DirecTV
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 5
SINGLE LINE ISP
Figure-2A (Single Line ISP)
16 LINES ISP
Figure-2B (16 Lines ISP)
Figure-2C (16 Ports Asynchronous 2511 CISCO Router)
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 6
120 LINES ISP
Figure-2D (120 Lines ISP)
Figure-2E (CISCO AS5400 RAS)
SNR (SIGNAL-TO-NOISE RATIO)
As the name suggests, signal to noise ratio is a comparison or ratio of the
amount of signal to the amount of noise and is expressed in decibels.
Signal to noise ratio is abbreviated SNR or S/N Ratio, and higher numbers
mean a better specification. A component with a signal to noise ratio of
100dB means that the level of the audio signal is 100dB higher than the
level of the noise and is a better specification than a component with a
S/N ratio of 90dB.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 7
LECTURE NO. 3
02 March 2009
CABLE TECHNOLOGY / HFC
Figure-3A
CATV (Community Antenna Television)
The abbreviation CATV is often used to mean "Cable TV". It originally stood
for Community Antenna Television, from cable television's origins in 1948:
in areas where over-the-air reception was limited by mountainous terrain,
large "community antennas" were constructed, and cable was run from them to
individual homes.
DOCSIS (Data Over Cable Services Interface Specification)
Data Over Cable Service Interface Specification (DOCSIS) defines the
interface standards for cable modems and supporting equipment involved in
high speed data transfer and distribution over cable television system
networks. It permits additional high-speed data transfer over an existing
cable TV system and is widely used by television operators to offer
Internet access through an already existing hybrid fiber coaxial
infrastructure. Other devices that recognize and support DOCSIS include
HDTV's and Web-enabled set-top boxes for televisions. In other words, the
same cable that brings you CSI can also allow you to send email and receive
Internet news.
DOCSIS ARCHITECTURE
The DOCSIS architecture consists of two primary components. 1) A
cable modem located with the customer and, 2) the cable modem
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 8
termination system operated by cable service providers. The second
function is to perform as a Hi Speed way station for multiple cable
modems and then communicate with the system network. DOCSIS defines
protocol for bi-directional signal exchange between these two
components through the use of cable.
DOCSIS TYPES
DOCSIS 1.0 debuted in March 1997 and is what most consumers typically
link with high speed cable Internet access. This version facilitates
a downstream traffic transfer rates of 27-36 Mbps over a radio
frequency (RF) path in the 50 MHz to 750+ MHz range, and upstream
traffic transfer rates between 320 Kbps-10 Mbps (average 5 Mbps) over
a RF path between 5 and 42 MHz. In layman's terms when more people
who use DOCSIS 1.0 are using the Internet the slower the overall
speed will be for customers.
DOCSIS 1.1 can coexist with DOCSIS 1.0, but features an
increased upstream data transmission and improved security.
This version facilitates multiple services such as voice and
streaming. The end result is faster transmission and
reception with a greater inventory of features.
DOCSIS 2.0 has an added capacity for symmetric services by
operating at 64 QAM, backed by a new 6.4 MHz wide channel.
Enhanced modulation and improved error correction ensures
that this standard offers an increased bandwidth for IP
traffic. The upstream traffic DOCSIS 2.0 is above 30 Mbps
which is 3 times better than DOCSIS 1.1 and 6 times faster
than DOCSIS 1.0. DOCSIS 2.0 is interoperable and backward
compatible with DOCSIS 1.x. Long story short - this version
works with both of the others but remains much faster and
exhibits fewer errors.
eDOCSIS The latest development in cable Internet connection
is Embedded DOCSIS (eDOCSIS). eDOCSIS is designed to provide
subordinate services at the core chip level to the host
device. Its purpose includes end device management
(including traffic management), configuration and security
issues to significantly reduce cost in the service operation
and to enhance speed and quality of end customer services.
This evolution of service provides greater overall speed,
reduced costs, and is less problematic for your service
provider.
UPSTREAM
In computer networking, upstream refers to the direction in which data can
be transferred from the client to the server (uploading). This differs
greatly from downstream not only in theory and usage, but also in that
upstream speeds are usually at a premium.[citation needed] Whereas
downstream speed is important to the average home user for purposes of
downloading content, uploads are used mainly for web server applications
and similar processes where the sending of data is critical. Upstream
speeds are also important to users of peer-to-peer software.
ADSL and cable modems are asymmetric, thereby rendering the upstream speed
to be much lower than that of its downstream. Symmetric connections such as
SDSL and T1, however, offer identical upstream and downstream speeds.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 9
If a node A on the Internet is closer (fewer hops away) to the Internet
backbone than a node B, then A is said to be upstream of B or conversely, B
is downstream of A. Related to this is the idea of upstream providers. An
upstream provider is usually a large ISP that provides Internet access to a
local ISP. Hence, the word upstream also refers to the data connection
between two ISPs.
DOWNSTREAM
In information technology, downstream refers to the transfer speed (usually
that of an internet connection) by which data can be sent from the server
to the client. The process by which downstream is utilized is known as
downloading.
In the US, optimal 56k connections are able to send 53 kilobits per second
to the client. Asymmetrical (or asynchronous) DSL and Cable Modems, the two
most popular broadband services in the world today, have greatly improved
downstream speeds in comparison with 56 k, with speeds reaching over 7
Mbit/s. However, the overall download speed of a file is dependent on both
the downstream of the user and the upstream of the server.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 10
Lecture No. 6
9 March 2009
ROUTER MODES
Cisco routers have different configuration modes (depending on the router
model), and by this I mean there are different modes in which different
aspects of the router can be configured.
USER EXEC MODE (User Mode):
The first mode you'll see on a router (if the person before you logged off
as they should have) is user exec mode. This is also the default mode a
user is placed into when using Telnet to connect to a router. The prompt
will look like this:
Router>
You can't write or add to a configuration in this mode, but you can run
quite a few show commands. This is a good mode to have users in who need to
see the configuration, but shouldn't be allowed to change it.
PRIVILEGED EXEC MODE (Enable Mode):
This mode has two names, the official one being privileged exec mode. It's
more commonly referred to as enable mode, since "enable" is what you type
to get into this mode. This mode gives you more options for show and other
commands, but you still can't configure anything. To enter into this mode,
use following command:
Router> enable
The next prompt will look like this:
Router#
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 11
GLOBAL CONFIGURATION MODE:
Used only for change of configuration
Not password protected from privileged mode
Privileged mode commands don’t have meaning in configuration mode
Most statements can be removed from the configuration with the prefix
no (ex. no shutdown)
To enter into Global Config Mode, use following command:
Router# configure terminal
OR
Router# config t
To be able to get into either User Exec or Privileged mode, you will most
likely need a password. This password is set during the initial
configuration of the router or later on. Once in Privileged Mode, you can
then enter Global Configuration Mode (password not needed to enter this
mode) to then further configure interfaces, routing protocols, access lists
and more.
The picture below shows you a quick view of the modes. Notice the red
arrow, it's pointing towards the Global Configuration Mode and Privileged
mode meaning that some of the specific configuration modes can be entered
from Global Configuration Mode and other from Privileged mode:
CONFIGURATION MODE PROMPT
Interface Router(config-if)#
Subinterface Router(config-subif)#
Controller Router(config-controller)#
Map-list Router(config-map-list)#
Map-class Router(config-map-class)#
Line Router(config-line)#
Router Router(config-router)#
IPX-router Router(config-ipx-router)#
Router-map Router(config-route-map)#
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 12
PRIVILEGE LEVELS
Cisco IOS permits to define multiple privilege levels for different
accounts. This could be useful when many people work on the same router /
switch, but with different roles (operator, technician, network manager)
and there is no time to implement an authentication server.
There are 16 different privilege levels that can be used. Level 0 is user
mode. Level 15 is the privileged mode. Levels 1 through 14 are available
for customization and use.
When it comes to the different privilege levels in the Cisco IOS, the
higher your privilege level, the more router access you have. But most
users of Cisco routers are familiar with only two privilege levels:
User EXEC Mode — Privilege Level 1
Privileged EXEC Mode — Privilege Level 15
Level 0 might be a guest who is only allowed to connect or disconnect.
When you log in to a Cisco router under the default configuration, you're
in user EXEC mode (level 1). From this mode, you have access to some
information about the router, such as the status of interfaces, and you can
view routes in the routing table. However, you can't make any changes or
view the running configuration file.
Because of these limitations, most Cisco router users immediately type
enable to get out of user EXEC mode. By default, typing enable takes you to
level 15, privileged EXEC mode. In the Cisco IOS, this level is equivalent
to having root privileges in UNIX or administrator privileges in Windows.
In other words, you have full access to the router.
HOW TO CHECK PRIVILEGE LEVEL?
A# show privilege
Current privilege level is 15
A> show ip route
CHANGING PRIVILEGE LEVEL OF USER EXEC MODE:
A> enable 0
A> show ip route
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 13
A> exit
A con0 is now available
Press RETURN to get started.
A> By default privilege level is 0
A> enable
A# By default privilege level is 15
CHANGING PRIVILEGE LEVEL OF PRIVILEGE EXEC MODE:
A# enable 10
A# show privilege
Current privilege level is 10
A# enable 8
A# show privilege
Current privilege level is 8
A# enable 12
% No password set
NOTE: When you go from upper level
(e.g. level-10) to a lower level (e.g. level-8), no
password is required but when you go from a lower level
(e.g. level-8) to any upper level (e.g. level-10 or 14),
password is required.
HOW TO CREATE LEVELS?
A> exit
A con0 is now available
Press RETURN to get started.
A> enable 15
A# show privilege
Current privilege level is 15
A# configure terminal
A(config)# enable secret level 5 *****
NOTE: Here ***** is password
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 14
A(config)# exit
A# exit
A con0 is now available
Press RETURN to get started.
A> enable 5
Password: *****
A# configure terminal
NOTE: CONFIGURE TERMINAL command does not work in this level.
ASSIGNING COMMANDS TO PRIVILEGE EXEC MODE:
A# exit
A con0 is now available
Press RETURN to get started.
A> enable 15
A# configure terminal
A(config)# privilege exec level 5 configure terminal
NOTE: Here, we have assigned CONFIGURE TERMINAL command to
level 5 of privilege exec mode.
A(config)# exit
A# enable 5
A# show running-configuration
A# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
NOTE: After assigning CONFIGURE TERMINAL command to level 5 of
privilege exec mode, it is working, but SHOW RUNNING-
CONFIG is not working.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 15
ASSIGNING COMMANDS TO PRIVILEGE CONFIGURE MODE:
A> enable 5
A# configuration terminal
A(config)# router rip
NOTE: ROUTER RIP command does not work in this level. To make
it working, use the following way:
A(config)# exit
A# enable 15
A# configuration terminal
A(config)# privilege configure level 5 router rip
NOTE: Here, we have assigned ROUTER RIP command to level 5 of
privilege configure mode.
A(config)# exit
A# enable 5
A# configuration terminal
A(config)# router rip
A(config)# network [Link]
NOTE: NETWORK command does not work in this level. To make it
working, use the following way:
ASSIGNING COMMANDS TO PRIVILEGE ROUTER MODE:
A(config)# exit
A# enable 15
A# configuration terminal
A(config)# privilege router level 5 network
NOTE: Here, we have assigned NETWORK command to level 5 of
privilege router mode.
A(config)# exit
A# enable 5
A# configuration terminal
A(config)# router rip
A(config)# network [Link]
NOTE: Now the NETWORK command is working.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 16
LECTURE NO. 7
11 March 2009
AAA SERVER
Authentication Authorization Accounting Server: A network server used for
access control. Authentication identifies the user. Authorization
implements policies that determine which resources and services a valid
user may access. Accounting keeps track of time and data resources used for
billing and analysis.
AUTHENTICATION
Authentication refers to the process of establishing the digital
identity of one entity to another entity. Commonly one entity is a
client (a user, a client computer, etc.) and the other entity is a
server (computer). Authentication is accomplished via the
presentation of an identity and its corresponding credentials.
Examples of types of credentials are passwords, one-time tokens,
digital certificates, and phone numbers (calling/called).
AUTHORIZATION
Authorization refers to the granting of specific types of privileges
(including "no privilege") to an entity or a user, based on their
authentication, what privileges they are requesting, and the current
system state. Authorization may be based on restrictions, for example
time-of-day restrictions, or physical location restrictions, or
restrictions against multiple logins by the same user. Most of the
time the granting of a privilege constitutes the ability to use a
certain type of service. Examples of types of service include, but
are not limited to: IP address filtering, address assignment, route
assignment, QoS/differential services, bandwidth control/traffic
management, compulsory tunneling to a specific endpoint, and
encryption.
ACCOUNTING
Accounting refers to the tracking of the consumption of network
resources by users. This information may be used for management,
planning, billing, or other purposes. Real-time accounting refers to
accounting information that is delivered concurrently with the
consumption of the resources. Batch accounting refers to accounting
information that is saved until it is delivered at a later time.
Typical information that is gathered in accounting is the identity of
the user, the nature of the service delivered, when the service
began, and when it ended.
RADIUS SERVER
Remote Authentication Dial-In User Service) The de facto standard protocol
for authentication servers (AAA servers). Developed by Livingston
Enterprises (later acquired by Lucent), RADIUS uses a challenge/response
method for authentication.
AUTHENTICATION SERVER
A device used in network access control. It stores the usernames and
passwords that identify the clients logging in, or it may hold the
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 17
algorithms for token access. For access to specific network resources, the
server may itself store user permissions and company policies or provide
access to directories that contain the information.
RADIUS is the most widely used protocol for authentication servers. TACACS+
is a Cisco-developed product that has also been popular. The authentication
server may be a stand-alone system or software that resides in an Ethernet
switch, wireless access point (AP) or network access server (NAS)
ACCESS CONTROL
The management of admission to system and network resources. The first part
of access control is authenticating the user, which proves the identity of
the user or client machine attempting to log in. The second part is
granting the authenticated user access to specific resources based on
company policies and the permission level assigned to the user or user
group.
Figure-7a
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 18
LOCAL DATABASE
Figure-7b
(Note: Lab results are produced using GNS3 simulator)
APPLYING AUTHENTICATION FOR TRUSTED USER:
ROUTER-A:
A# configure terminal
A(config)# aaa new-model
A(config)# aaa ?
A(config)# username shakeel password 0 *****
A(config)# username nabeel password 0 *****
A(config)# username haroon password 0 *****
NOTE: shakeel = username
***** = password
0 = Specifies an unencrypted password will follow
A(config)# aaa authentication login default local
NOTE: Here, we are saying that perform authentication from
local database at the time of login for all accessible
paths e.g. aux, vty, console.
ROUTER-B:
B# telnet [Link]
****
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 19
APPLYING AUTHENTICATION FOR NON TRUSTED USER:
ROUTER-A:
A(config)# no aaa authentication login default local
A(config)# aaa authentication login default local none
NOTE: This command is used when a username does not exist in
the local database and you want to allow him/her to
access your router.
ROUTER-B:
B# telnet [Link]
NOTE: We have successfully accessed Router-A by using a
username “ali”, however, it does not exist in the local
database.
APPLYING AUTHENTICATION ON CONSOLE PORT USING LABEL:
ROUTER-A:
A(config)# no aaa authentication login default local none
A(config)# aaa authentication login pakistan none
NOTE: Here, pakistan is label name
None means no authentication
A(config)# line consol 0
A(config)# login authentication pakistan (applying label)
NOTE: The above process will allow you to safeguard your
router’s console port. There’ll be no authentication on
console port.
AUTHENTICATION FOR VTY USING LABEL:
ROUTER-A:
A(config)# aaa authentication login corvit local (creating label)
A(config)# line vty 0 4
A(config)# login authentication corvit (applying label)
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 20
ROUTER-B:
B# telnet [Link]
****
LOGIN ATTEMPTS:
ROUTER-A:
A(config)# aaa authentication attempts login 2
ROUTER-B:
B# telnet [Link]
FAIL-MESSAGE:
ROUTER-A:
A(config)# aaa authentication fail-message $
Enter TEXT message. End with the character ‘$’.
Incorrect username & password $
ROUTER-B:
B# telnet [Link]
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 21
USERNAME-PROMPT & PASSWORD-PROMPT:
ROUTER-A:
A(config)# aaa authentication username-prompt Please-enter-username
A(config)# aaa authentication password-prompt please-enter-your-password
ROUTER-B:
B# telnet [Link]
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 22
LECTURE NO. 8
13 March 2009
AAA SERVER (CISCO ACS / TACACS) - LAB
CISCO ACS SERVER:
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 23
CISCO ACS SERVER CONFIGURATION:
USER SETUP:
1. Click on USER SETUP.
2. Type user name e.g. shakeel
3. Click on ADD/EDIT button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 24
4. Type password for user.
5. Click on SUBMIT button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 25
NETWORKING CONFIGURATION:
6. Click on NETWORK CONFIGURATION button.
7. Click on ADD ENTRY button for AAA CLIENT.
8. Set/type the configuration as show in below window.
9. Click on SUBMIT + APPLY button,
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 26
10. Click on ADD ENTRY button for AAA SERVER.
11. Set/type the configuration as shown in below window.
12. Click on SUBMIT + APPLY button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 27
INTERFACE CONFIGURATION:
13. Click on ADVANCED OPTIONS.
14. Apply following setting and click on SUBMIT button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 28
15. Click on INTERFACE CONFIGURATION button.
16. Click on TACACS+ (Cisco IOS) option.
17. Click on SHELL (EXEC) checkbox.
18. Turn ON all checkboxes under USER option and click on SUBMIT button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 29
GENERAL CONFIGURATION (ROUTER-A):
A(config)# aaa new-model
A(config)# tacacs-server host [Link] key cisco
A(config)# username haroon password cisco
A(config)# aaa authentication login AA local
A(config)# line console 0
A(config-line)# login authentication AA
A(config-line)# exit
A(config)# aaa authentication login BB group tacacs+
A(config)# aaa authorization exec CC group tacacs+
A(config)# line vty 0 4
A(config-line)# login authentication BB
A(config-line)# authorization exec CC
TRYING TELNET TO ROUTER FROM CLIENT’S WORKSTATION:
NOTE: Here, authentication has been passed but authorization
has been failed because we have not defined any
authorization for client in ACS.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 30
ASSIGNING PRIVILEGE LEVEL TO USER (ACS):
1. Click on USER SETUP button.
2. Click on FIND button.
3. Select user e.g. shakeel
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 31
4. Turn on SHELL (EXEC) checkbox.
5. Turn on PRIVILEGE LEVEL checkbox and write 10 in the text box.
6. Click on SUBMIT button.
ACCESSING ROUTER-A FROM CLIENT'S WORKSTATION:
1. Launch the following command from windows command shell:
C:\ telnet [Link]
2. Type username and password, which you have created using ACS.
NOTE: You’ll notice that after turning ON SHELL (exec) and
PRIVILEGE LEVEL checkboxes, authentication and
authorization has successfully been passed.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 32
3. Checking user privileges level.
USER ACCOUNT DISABLE OPTIONS:
1. Apply the following setting under the USER SETUP option.
2. Click on SUBMIT button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 33
3. Try to telnet Router [Link] from client’s workstation
[Link] with wrong password.
NOTE: You’ll notice that after 3rd attempt with wrong password,
authentication has been failed.
4. Click on DISABLE ACCOUNT IF option.
5. Click on DATE EXCEEDS option and set the expiry date for account.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 34
6. Try to telnet Router [Link] from client’s workstation [Link]
with correct password.
NOTE: If current date exceeds 8th May 2009, you’ll see
“authentication failed” message. Here, I tried on 9th
May 2009. Therefore, the authentication has been failed.
HOW TO LIMIT LEVELS FOR TELNET USERS?
1. Set the user privilege level to 15.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 35
2. Set the following configuration on Router-A.
A(config)# aaa authorization commands 15 TT group tacacs+
A(config)# line vty 0 4
A(config-line)# authorization commands 15 TT
3. Telnet the Router-A from client’s workstation.
C:\> telnet [Link]
Username: shakeel
Password: *****
A#
4. Type SHOW RUNNING-CONFIG and SHOW STARTUP-CONFIG commands.
NOTE: You’ll see COMMAND AUTHORIZATION FAILED message, because
we have not set the commands for user shakeel (level 15)
in user setup of ACS.
5. In USER SETUP option, find "SHELL COMMAND AUTHORIZATION SET" option.
6. Click on "PER USER COMMAND AUTHORIZATION UNMATCHED CISCO IOS COMMANDS"
option button.
7. Click on DENY option button.
8. Click on COMMAND checkbox and type "SHOW" in the text box.
9. Type following commands in ARGUMENTS textbox.
Permit show running-config
10. Click on submit button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 36
11. Telnet the Router-A from client’s workstation.
C:\> telnet [Link]
Username: shakeel
Password: *****
A#
12. Apply following commands:
A# show running-config
A# show startup-config
A# configure terminal
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 37
NOTE: SHOW RUNNING-CONFIG and SHOW STARTUP-CONFIG commands are
working but CONFIGURE TERMINAL command is not working.
Actually the setting in para 5 to 9 (above) will only
permit SHOW RUNNING-CONFIG and SHOW STARTUP-CONFIG
commands.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 38
LECTURE NO. 9
16 March 2009
PPPoE (POINT-TO-POINT PROTOCOL OVER ETHERNET)
(DSL SETUP)
Source: [Link]
PPPoE (Point-to-Point Protocol over Ethernet) is a specification for
connecting multiple computer users on an Ethernet local area network to a
remote site through common customer premises equipment, which is the
telephone company's term for a modem and similar devices. PPPoE can be used
to have an office or building-full of users share a common Digital
Subscriber Line (DSL), cable modem, or wireless connection to the Internet.
PPPoE combines the Point-to-Point Protocol (PPP), commonly used in dialup
connections, with the Ethernet protocol, which supports multiple users in a
local area network. The PPP protocol information is encapsulated within an
Ethernet frame.
PPPoE has the advantage that neither the telephone company nor the Internet
service provider (ISP) needs to provide any special support. Unlike dialup
connections, DSL and cable modem connections are "always on." Since a
number of different users are sharing the same physical connection to the
remote service provider, a way is needed to keep track of which user
traffic should go to and which user should be billed. PPPoE provides for
each user-remote site session to learn each other's network addresses
(during an initial exchange called "discovery"). Once a session is
established between an individual user and the remote site (for example, an
Internet service provider), the session can be monitored for billing
purposes. Many apartment houses, hotels, and corporations are now providing
shared Internet access over DSL lines using Ethernet and PPPoE.
Source: [Link]
PPPoE, Point-to-Point Protocol over Ethernet, is a network protocol for
encapsulating Point-to-Point Protocol (PPP) frames inside Ethernet frames.
It is used mainly with ADSL services where individual users connect to the
ADSL transceiver (modem) over Ethernet and in plain Metro Ethernet
networks. It was developed by UUNET, Redback Networks, and RouterWare and
is available as an informational RFC 2516.
Ethernet networks are packet-based and have no concept of a connection or
circuit and also lack basic security features to protect against IP and MAC
conflicts and rogue DHCP servers. By using PPPoE, users can virtually
"dial" from one machine to another over an Ethernet network, establish a
point to point connection between them and then securely transport data
packets over the connection.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 39
Figure-9a
(Note: Lab results are produced using GNS3 simulator)
CLIENT SIDE CONFIGURATION:
GENERAL CONFIGURATION:
CLIENT(config)# vpdn enable
CLIENT(config)# vpdn-group 1
CLIENT(config-vpdn)# request-dialin
CLIENT(config-req-in)# protocol pppoe
NOTE: pppoe is a hidden protocol
CLIENT(config-req-in)# exit
CLIENT(config-vpdn)# exit
CONFIGURATION OF INTERFACE FASTETHERNET 0/0:
CLIENT(config)# interface fastethernet 0/0
CLIENT(config-if)# no shutdown
CLIENT(config-if)# no ip address
CLIENT(config-if)# pppoe enable
CLIENT(config-if)# pppoe-client dial-pool-number 15
CLIENT(config-if)# exit
CONFIGURATION OF INTERFACE DIALER 1:
CLIENT(config)# interface dialer 1
CLIENT(config-if)# no shutdown
CLIENT(config-if)# ip address dhcp
CLIENT(config-if)# encapsulation ppp
CLIENT(config-if)# dialer pool 15
CLIENT(config-if)# ppp chap hostname shakeel
CLIENT(config-if)# ppp chap password *******
CLIENT(config-if)# Ctrl+Z
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 40
SERVER SIDE CONFIGURATION:
AAA CONFIGURATION / AUTHENTICATION FOR USER:
SERVER(config)# aaa new-model
SERVER(config)# aaa authentication login corvit none
NOTE: corvit is label name for line consol 0
SERVER(config)# line console 0
SERVER(config-line)# login authentication corvit
SERVER(config-line)# exit
NOTE: Use this configuration to save line consol 0. It means
that there is no authentication for line console 0.
SERVER(config)# aaa authentication login default line
NOTE: This command is applied to use the default password which
is set for other lines, e.g. when we set password
pakistan for line vty 0 4 and we try to telnet to router,
we need to provide this password (pakistan) for telnet.
Here, we can also use tacacs server.
SERVER(config)# aaa authentication ppp nabeel local
SERVER(config)# username shakeel password *******
NOTE: nabeel is label name for ppp authentication. Local means
that ppp authentication would be performed from local
database. Here, we can also use tacacs server instead of
local server.
DHCP CONFIGURATION:
SERVER(config)# ip dhcp pool POOL1
NOTE: POOL1 is the label for dhcp pool.
SERVER(dhcp-config)# network [Link] [Link]
SERVER(dhcp-config)# exit
SERVER(config)# ip dhcp excluded-address [Link] [Link]
GENERAL CONFIGURATION:
SERVER(config)# vpdn enable
SERVER(config)# vpdn-group 1
SERVER(config-vpdn)# accept-dialin
SERVER(config-req-in)# protocol pppoe
SERVER(config-req-in)# virtual-template 1
SERVER(config-req-in)# exit
SERVER(config-vpdn)# exit
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 41
CONFIGURATION OF INTERFACE FASTETHERNET 0/0:
SERVER(config)# interface fastethernet 0/0
SERVER(config-if)# no shutdown
SERVER(config-if)# ip address [Link] [Link]
SERVER(config-if)# pppoe enable
SERVER(config-if)# exit
CONFIGURATION OF INTERFACE VIRTUAL-TEMPLATE 1:
SERVER(config)# interface virtual-template 1
SERVER(config-if)# no shutdown
SERVER(config-if)# ip unnumbered fastethernet 0/0
SERVER(config-if)# encapsulation ppp
SERVER(config-if)# ppp authentication chap callin nabeel
CLIENT# show ip interface brief
SERVER# show ip interface brief
CLIENT# show pppoe session
CLIENT# show pppoe summary
CLIENT# ping [Link]
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 42
VERIFYING PPP AUTHENTICATION USING DEBUGGING:
SERVER(config)# logging console
SERVER(config)# exit
SERVER# debug ppp authentication
PPP authentication debugging is on
CLIENT(config)# interface dialer1
CLIENT(config-if)# shutdown
CLIENT(config-if)# no shutdown
SERVER#
BEHAVIOR OF OSPF WITH PPPOE:
CLIENT(config)# router ospf 1
CLIENT(config)# network [Link] [Link] area 0
SERVER(config)# router ospf 1
SERVER(config)# network [Link] [Link] area 0
CLIENT# show ip ospf neighbor
NOTE: You’ll notice that the neighbor [Link] is in the
OPSF EXCHANGE state, which means that OPSF Link State
Database cannot be exchanged between neighbors. To solve
this issue, we have two solutions:
SOLUTION-1:
CLIENT(config)# interface dialer 1
CLIENT(config-if)# ip mtu 1492
SERVER(config)# interface virtual-template 1
SERVER(config)# ip mtu 1492
SOLUTION-2:
CLIENT(config)# interface dialer 1
CLIENT(config-if)# ip ospf mtu ignore
SERVER(config)# interface virtual-template 1
SERVER(config)# ip ospf mtu ignore
CLIENT# show ip ospf neighbor
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 43
LECTURE NO. 10
18 March 2009
VIEWS
“iews and Superviews" provides the selective or limited access to Cisco IOS
commands. You can restrict your users to run and display some particular
commands that are defined in View for particular user. First time this
feature was introduced in 12.3(7)T IOS version. CLI views provide the
detailed access control for network administrator to manage over network
security and accountability.
GENERAL CONFIGURATION:
A(config)# aaa new-model
A(config)# enable password *****
A(config)# exit
A# exit
A con0 is now available
Press RETURN to get started.
1. CREATING VIEW A:
A> enable view
Password: *****
A#
A# configure terminal
A(config)# parser view A
A(config-view)#
NOTE: A = view name
view = hidden command
A(config-view)# secret *****
A(config-view)# command exec include show run
OR
A(config-view)# command exec include all show
NOTE: Apply the above command, if you want to
view all commands of show.
A(config-view)# Ctrl+Z
A# exit
A con0 is now available
Press RETURN to get started.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 44
A> enable view A
Password: *****
A#
A# show ?
2. CREATING VIEW B:
A# exit
A con0 is now available
Press RETURN to get started.
A> enable view
Password: *****
A#
A# configure terminal
A(config)# parser view B
A(config-view)#
NOTE: B = view name
view = hidden command
A(config-view)# secret *****
A(config-view)# command exec include show start
A(config-view)# command exec include all show ip
A(config-view)# command exec include config terminal
A(config-view)# Ctrl+Z
A# exit
A con0 is now available
Press RETURN to get started.
A> enable view B
Password: *****
A#
A# show ip route
NOTE: All SHOW IP commands including SHOW IP ROUTE are working
now.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 45
A# configure terminal
A(config)#
NOTE: CONFIG TERMINAL command is now available.
3. CREATING SUPERVIEW: Superview is a combination of multiple
views (e.g. View A + View B)
A# exit
A con0 is now available
Press RETURN to get started.
A> enable view
Password: *****
A#
A# configure terminal
A(config)# parser view C superview
A(config-view)#
NOTE: C = superview name
A(config-view)# secret *****
A(config-view)# view A
A(config-view)# View B
A(config-view)#
A(config-view)# Ctrl+Z
A# exit
A con0 is now available
Press RETURN to get started.
A> enable view C
Password: *****
A#
A# show ?
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 46
LECTURE NO. 12
25 March 2009
VPN/IPSEC (Site-to-Site)
A virtual private network (VPN) is a computer network in which some of the
links between nodes are carried by open connections or virtual circuits in
some larger networks (such as the Internet), as opposed to running across a
single private network. The Link Layer protocols of the virtual network are
said to be tunneled through the transport network. One common application
is to secure communications through the public Internet, but a VPN does not
need to have explicit security features such as authentication or content
encryption. For example, VPNs can also be used to separate the traffic of
different user communities over an underlying network with strong security
features, or to provide access to a network via customized or private
routing mechanisms.
VPN service providers may offer best-effort performance, or may have a
defined service level agreement (SLA) with their VPN customers. Generally,
a VPN has a topology more complex than point-to-point.
VPN configuration is divided into two phases:-
a. Phase-I
i. Define policies
ii. Define keys
b. Phase-II
i. Define interesting traffic (ACL)
ii. Define transform set
iii. Apply all (policies, key, interesting traffic, transform
set)
Figure-12a
(Note: Lab results are produced using GNS3 simulator)
BASIC CONFIGURATION OF ROUTER-A & B:
A(config)# interface fastethernet 0/0
A(config-if)# ip address [Link] [Link]
A(config-if)# no shutdown
B(config)# interface fastethernet 0/0
B(config-if)# ip address [Link] [Link]
B(config-if)# no shutdown
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 47
A# ping [Link]
PHASE-I (ROUTER-A)
ISAKMP(Internet Security Association Key Management Protocol)
DEFINING POLICY:
A(config)# crypto isakmp policy 10 10 = policy number
A(config-isakmp)# encryption des
A(config-isakmp)# hash md5
A(config-isakmp)# authentication pre-share
A(config-isakmp)# group 2
A(config-isakmp)# exit
A(config)#
DEFINING KEY:
A(config)# crypto isakmp key hello address [Link]
hello = key/password
PHASE-II (ROUTER-A)
IPSEC
DEFINING TRANSFORM-SET:
A(config)# crypto ipsec transform-set shakeel esp-des
shakeel = label name
esp-des = encryption type
A(config-trans)# exit
A(config)#
DEFINING INTERESTING TRAFFIC:
A(config)# access-list 101 permit ip any any
101 = ACL number
APPLYING ALL CONFIGURATION:
A(config)# crypto map mymap 100 ipsec-isakmp
mymap = label name
100 = map number
A(config-crypto-map)# match address 101
A(config-crypto-map)# set transform-set shakeel
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 48
A(config-crypto-map)# set peer [Link]
A(config-crypto-map)# exit
A(config)# interface fastethernet 0/0
A(config-if)# crypto map mymap
A(config-if)#
A(config-if)# exit
PHASE-I (ROUTER-B)
ISAKMP(Internet Security Association Key Management Protocol)
DEFINING POLICIY:
B(config)# crypto isakmp policy 10 10 = policy number
B(config-isakmp)# encryption des
B(config-isakmp)# hash md5
B(config-isakmp)# authentication pre-share
B(config-isakmp)# group 2
B(config-isakmp)# exit
B(config)#
DEFINING KEY:
B(config)# crypto isakmp key hello address [Link]
hello = key/password
PHASE-II (ROUTER-B)
IPSEC
DEFINING TRANSFORM-SET:
B(config)# crypto ipsec transform-set shakeel esp-des
shakeel = label name
esp-des = encryption type
B(config-trans)# exit
B(config)#
DEFINING INTERESTING TRAFFIC:
B(config)# access-list 101 permit ip any any
101 = ACL number
APPLYING ALL CONFIGURATION:
B(config)# crypto map mymap 100 ipsec-isakmp
mymap = label name
100 = map number
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 49
B(config-crypto-map)# match address 101
B(config-crypto-map)# set transform-set shakeel
B(config-crypto-map)# set peer [Link]
B(config-crypto-map)# exit
B(config)# interface fastethernet 0/0
B(config-if)# crypto map mymap
B(config-if)#
B(config-if)# exit
B(config)#
A# ping [Link]
A# ping [Link]
A# show crypto ipsec sa
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 50
A# show crypto ipsec transform-set
A# show crypto isakmp key
A# show crypto isakmp sa
A# show crypto isakmp peers
ADDING DATA INTEGRITY/HASHING (MD5 and HMAC):
A(config)# crypto ipsec transform-set shakeel esp-des esp-md5-hmac
REFRESHING TUNNEL:
A# clear crypto isakmp
A# clear crypto sa
A# ping [Link]
NOTE: To resolve the ping issue, we need to apply following
commands on the other side i.e. Router-B.
B(config)# crypto ipsec transform-set shakeel esp-des esp-md5-hmac
B# clear crypto isakmp
B# clear crypto sa
A# ping [Link]
A# ping [Link]
A# show crypto ipsec transform-set
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 51
LECTURE NO. 13
27 March 2009
EZVPN
Figure-13a
(Note: Lab results are produced using GNS3 simulator)
SERVER SIDE CONFIGURATION (ROUTER-A):
BASIC CONFIGURATION:
A(config)# interface fastethernet 0/0
A(config-if)# ip address [Link] [Link]
A(config-if)# no shutdown
DEFINING LOOPBACK INTERFACES:
A(config)# interface loopback 0
A(config-if)# ip address [Link] [Link]
A(config-if)# exit
A(config)# interface loopback 1
A(config-if)# ip address [Link] [Link]
A(config-if)# exit
NOTE: We have defined 2 loopback interfaces for testing
function only.
AAA CONFIGURATION:
A(config)# aaa new-model
A(config)# aaa authentication login CORVIT local CORVIT = label name
A(config)# aaa authorization network CORVIT local CORVIT = lable for
network service
A(config)# username shakeel password *****
***** is the password
DHCP CONFIGURATION:
A(config)# ip local pool NABEEL [Link] [Link] NABEEL= pool name
A(config)# ip route [Link] [Link] fastethernet 0/0
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 52
DEFINING POLICY:
A(config)# crypto isakmp policy 10
A(config-isakmp)# encryption des
A(config-isakmp)# hash md5 (md5 = Hashing Algorithm)
A(config-isakmp)# authentication pre-share
A(config-isakmp)# group 2 (Diffie-Helman Group 2)
A(config-isakmp)# exit
A(config)#
DEFINING KEY:
A(config)# crypto isakmp key cisco address [Link]
cisco = key/password
NOTE: This is the optional command.
DEFINING CLIENT CONFIGURATION GROUP:
A(config)# crypto isakmp client configuration group marketing
marketing = group name
A(config-isakmp-group)# key cisco
A(config-isakmp-group)# pool NABEEL
A(config-isakmp-group)# acl 101
A(config-isakmp-group)# exit
DEFINING TRANSFORM-SET:
A(config)# crypto ipsec transform-set tset esp-des esp-md5-hmac
tset = name for transform-set
A(config-crypto-trans)# exit
DEFINING CRYPTO MAPS (DYNAMIC + STATIC):
A(config)# crypto dynamic-map dmap 10
dmap = label for dynamic map
A(config-crypto-map)# set transform-set tset
A(config-crypto-map)# exit
A(config)# crypto map smap 10
ipsec-isakmp dynamic dmap
smap = label for static map
NOTE: Here, we are associating/linking dynamic map (dmap) with
static map (smap).
A(config)# crypto map smap client authentication list CORVIT
A(config)# crypto map smap isakmp authorization list CORVIT
A(config)# crypto map smap client configuration address respond
APPLYING CRYPTO MAP:
A(config)# interface fastethernet 0/0
A(config-if)# crypto map smap
A(config-if)# exit
A(config)#
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 53
A# show ip route
CLIENT SIDE CONFIGURATION:
1. Click on “NEW” button.
2. Type/set the configuration as show below.
3. Click on “SAVE” button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 54
4. Select your connection e.g. (shakeel).
5. Click on “CONNECT” button.
6. Type username and password.
7. Press "OK" button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 55
8. Clik on "STATUS" menu.
9. Select "STATISTIC".
10. Ping [Link] address and see results in "STATISTICS" window.
A(config)# access-list 101 permit ip host [Link] any
A(config)# crypto isakmp client configuration group marketing
A(config-isakmp-group)# acl 101
A(config-isakmp-group)# exit
A(config)#
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 56
LECTURE NO. 14
30 March 2009
IPSEC over GRE
Figure-14a
(Note: Lab results are produced using GNS3 simulator)
BASIC CONFIGURATION OF ROUTER-A:
A(config)# interface fastethernet 0/0
A(config-if)# ip address [Link] [Link]
A(config-if)# no shutdown
A(config-if)# exit
A(config)#
A(config)# interface loopback 0
A(config-if)# ip address [Link] [Link]
A(config-if)# no shutdown
A(config-if)# exit
A(config)#
BASIC CONFIGURATION OF ROUTER-B:
B(config)# interface fastethernet 0/0
B(config-if)# ip address [Link] [Link]
B(config-if)# no shutdown
B(config-if)# exit
B(config)#
B(config)# interface loopback 0
B(config-if)# ip address [Link] [Link]
B(config-if)# no shutdown
B(config-if)# exit
B(config)#
RUNNING EIGRP ON ROUTER-A & B:
A(config)# router eigrp 1
A(config-if)# network [Link]
A(config-if)# network [Link]
B(config)# router eigrp 1
B(config-if)# network [Link]
B(config-if)# network [Link]
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 57
A# ping [Link]
ROUTING TABLE OF ROUTER-A & B:
(After running IGRP)
A# show ip route
A# show ip route
CREATING IPSEC/VPN TUNNEL
PHASE-I (ROUTER-A)
DEFINING POLICY:
A(config)# crypto isakmp policy 10 10 = policy number
A(config-isakmp)# encryption des
A(config-isakmp)# hash md5
A(config-isakmp)# authentication pre-share
A(config-isakmp)# group 2
A(config-isakmp)# exit
A(config)#
DEFINING KEY:
A(config)# crypto isakmp key hello address [Link]
hello = key/password
PHASE-II (ROUTER-A)
DEFINING TRANSFORM-SET:
A(config)# crypto ipsec transform-set shakeel esp-des esp-md5-hmac
shakeel = label name
A(config-trans)# exit
A(config)#
DEFINING INTERESTING TRAFFIC:
A(config)# access-list 101 permit ip any any
101 = ACL number
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 58
APPLYING ALL CONFIGURATION:
A(config)# crypto map smap 100 ipsec-isakmp
smap = label name
100 = label number for map
A(config-crypto-map)# match address 101
A(config-crypto-map)# set transform-set shakeel
A(config-crypto-map)# set peer [Link]
A(config-crypto-map)# exit
A(config)# interface fastethernet 0/0
A(config-if)# crypto map smap
A(config-if)# exit
PHASE-I (ROUTER-B)
DEFINING POLICIY:
B(config)# crypto isakmp policy 10 10 = policy number
B(config-isakmp)# encryption des
B(config-isakmp)# hash md5
B(config-isakmp)# authentication pre-share
B(config-isakmp)# group 2
B(config-isakmp)# exit
B(config)#
DEFINING KEY:
B(config)# crypto isakmp key hello address [Link]
hello = key/password
PHASE-II (ROUTER-B)
DEFINING TRANSFORM-SET:
B(config)# crypto ipsec transform-set shakeel esp-des esp-md5-hmac
shakeel = label name
B(config-trans)# exit
B(config)#
DEFINING INTERESTING TRAFFIC:
B(config)# access-list 101 permit ip any any
101 = ACL number
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 59
APPLYING ALL CONFIGURATION:
B(config)# crypto map smap 100 ipsec-isakmp
smap = label name
100 = label number for map
B(config-crypto-map)# match address 101
B(config-crypto-map)# set transform-set shakeel
B(config-crypto-map)# set peer [Link]
B(config-crypto-map)# exit
B(config)# interface fastethernet 0/0
B(config-if)# crypto map smap
B(config-if)# exit
B(config)#
ROUTING TABLE OF ROUTER-A & B:
(After running IGRP)
A# show ip route
B# show ip route
NOTE: You’ll notice that network [Link] on Router-A, and
network [Link] on Router-B are nowhere to be found.
This is because IPSEC tunnel does not carry traffic of
routing protocols and you will see following log message
on both sides.
On Router-A
On Router-B
To resolve this issue we define GRE tunnel (a logical
tunnel).
CREATING GRE TUNNEL
ROUTER-A:
A(config)# interface tunnel 1
A(config-if)# ip address [Link] [Link]
A(config-if)# tunnel source fastethernet 0/0
A(config-if)# tunnel destination [Link]
A(config-if)# tunnel mode gre ip
A(config-if)# keepalive
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 60
ROUTER-B:
B(config)# interface tunnel 1
B(config-if)# ip address [Link] [Link]
B(config-if)# tunnel source fastethernet 0/0
B(config-if)# tunnel destination [Link]
B(config-if)# tunnel mode gre ip
B(config-if)# keepalive
MODIFYING ROUTING PROTOCOLS
REMOVING EIGRP 1 FROM ROUTER-A & B:
A(config)# no router eigrp 1
B(config)# no router eigrp 1
RUNNING EIGRP 1 ON ROUTER-A & B:
A(config)# router eigrp 1
A(config-router)# network [Link]
A(config-router)# network [Link]
B(config)# router eigrp 1
B(config-router)# network [Link]
B(config-router)# network [Link]
NOTE: Here, we are not advertising network [Link] in EIGRP to
avoid routing traffic over IPSEC tunnel.
ROUTING TABLE OF ROUTER-A & B:
A# show ip route
B# show ip route
A# show ip interface brief
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 61
A# ping [Link]
A# ping [Link]
A# show interface tunnel 1
MODIFYING ACL
REMOVING ACL-101 FROM ROUTER A & B:
A(config)# no access-list 101
B(config)# no access-list 101
CREATING NEW ACL 101 ON ROUTER A:
A(config)# access-list 101 permit ip host [Link]
host [Link]
A(config)# access-list 101 permit gre any any
CREATING NEW ACL 101 ON ROUTER B:
B(config)# access-list 101 permit ip host [Link]
host [Link]
B(config)# access-list 101 permit gre any any
APPLYING CRYPTO MAP ON GRE TUNNEL INTERFACE
ROUTER A:
A(config)# interface tunnel 1
A(config-if)# crypto map smap
ROUTER B:
B(config)# interface tunnel 1
B(config-if)# crypto map smap
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 62
A# ping [Link] source [Link]
4
Packets
A# ping [Link] source [Link]
5
Packets
A# show crypto ipsec sa
Routing Packets
which are using
GRE Tunnel
Total 9 Data
Packets which are
using IPSEC Tunnel
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 63
LECTURE NO. 15
1st April 2009
DMVPN (Dynamic Multipoint Virtual Private Network)
A Dynamic Multipoint Virtual Private Network is an enhancement of the
virtual private network (VPN) configuration process of Cisco IOS-based
routers. DMVPN prevents the need for pre-configured (static) IPSEC peers in
crypto-map configurations and ISAKMP peer statements. This feature of Cisco
IOS allows greater scalability over previous IPsec configurations. An ipsec
tunnel between two Cisco routers may be created on an as needed basis.
Tunnels may be created between a spoke router and a hub router (VPN
headend), or between spokes. This greatly alleviates the need for the hub
to route data between spoke networks, as was common in a non-fully meshed
frame relay topology.
Figure-15a
(Note: Lab results are produced using GNS3 simulator)
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 64
ROUTER-A (SERVER)
BASIC CONFIGURATION:
A(config)# interface fastethernet 0/0
A(config-if)# ip address [Link] [Link]
A(config-if)# no shutdown
A(config-if)# exit
DEFINING LOOPBACK INTERFACE:
A(config)# interface loopback 0
A(config-if)# ip address [Link] [Link]
A(config-if)# exit
DEFINING POLICY:
A(config)# crypto isakmp policy 20 20 = policy number
A(config-isakmp)# encryption des
A(config-isakmp)# hash md5
A(config-isakmp)# authentication pre-share
A(config-isakmp)# group 2
A(config-isakmp)# exit
DEFINING KEY:
A(config)# crypto isakmp key hello address [Link] [Link]
hello = key/password
DEFINING TRANSFORM-SET:
A(config)# crypto ipsec transform-set shakeel esp-des esp-md5-hmac
shakeel = label for
transform-set
A(config-trans)# exit
DEFINING PROFILE:
A(config)# crypto ipsec profile haroon (haroon = profile name)
A(config-profile)# set transform-set shakeel
A(config-profile)# exit
DEFINING TUNNEL INTERFACE:
A(config)# interface tunnel 1
A(config-if)# ip address [Link] [Link]
A(config-if)# ip mtu 1412 (MTU must be between 1400 to 1420)
A(config-if)# ip nhrp authentication corvit (corvit =password for nhrp)
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 65
A(config-if)# ip nhrp map multicast dynamic
A(config-if)# ip nhrp network-id 99
A(config-if)# tunnel source fastethernet 0/0
A(config-if)# tunnel mode gre multipoint
A(config-if)# tunnel key 123456 (123456 = set key/password for tunnel)
A(config-if)# tunnel protection ipsec profile haroon
A(config-if)# exit
RUNNING EIGRP:
A(config)# router eigrp 1
A(config-router)# network [Link]
A(config-router)# network [Link]
A(config-router)# no auto-summary
A(config-router)# exit
ROUTER-B (CLIENT-1)
BASIC CONFIGURATION:
B(config)# interface fastethernet 0/0
B(config-if)# ip address [Link] [Link]
B(config-if)# no shutdown
B(config-if)# exit
DEFINING LOOPBACK INTERFACE:
B(config)# interface loopback 0
B(config-if)# ip address [Link] [Link]
B(config-if)# exit
DEFINING POLICY:
B(config)# crypto isakmp policy 20 20 = policy number
B(config-isakmp)# encryption des
B(config-isakmp)# hash md5
B(config-isakmp)# authentication pre-share
B(config-isakmp)# group 2
B(config-isakmp)# exit
DEFINING KEY:
B(config)# crypto isakmp key hello address [Link] [Link]
hello = key/password
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 66
DEFINING TRANSFORM-SET:
B(config)# crypto ipsec transform-set shakeel esp-des esp-md5-hmac
shakeel = label for
transform-set
B(config-trans)# exit
DEFINING PROFILE:
B(config)# crypto ipsec profile haroon (haroon = profile name)
B(config-profile)# set transform-set shakeel
B(config-profile)# exit
DEFINING TUNNEL INTERFACE:
B(config)# interface tunnel 1
B(config-if)# ip address [Link] [Link]
B(config-if)# ip mtu 1412 (MTU should be between 1400 to 1420)
B(config-if)# ip nhrp authentication corvit (corvit =password for nhrp)
B(config-if)# ip nhrp map [Link] [Link]
[Link] = Tunnel interface address of
Server (Router-A)
[Link] = Actual interface address of
Server (Router-A)
B(config-if)# ip nhrp map multicast [Link]
[Link] = Actual interface address of
Server (Router-A)
B(config-if)# ip nhrp network-id 99
B(config-if)# ip nhrp nhs [Link]
[Link] = Tunnel interface address of
Server (Router-A)
NHS = Next Hop Server
NHRP = Next Hop Routing Protocol
B(config-if)# tunnel source fastethernet 0/0
B(config-if)# tunnel mode gre multipoint
B(config-if)# tunnel key 123456 (123456 = set key/password for tunnel)
B(config-if)# tunnel protection ipsec profile haroon
B(config-if)# exit
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 67
RUNNING EIGRP:
B(config)# router eigrp 1
B(config-router)# network [Link]
B(config-router)# network [Link]
B(config-router)# no auto-summary
B(config-router)# exit
B# show ip route
B# ping [Link] source [Link]
ROUTER-C (CLIENT-2)
BASIC CONFIGURATION:
C(config)# interface fastethernet 0/0
C(config-if)# ip address [Link] [Link]
C(config-if)# no shutdown
C(config-if)# exit
DEFINING LOOPBACK INTERFACE:
C(config)# interface loopback 0
C(config-if)# ip address [Link] [Link]
C(config-if)# exit
DEFINING POLICY:
C(config)# crypto isakmp policy 20 20 = policy number
C(config-isakmp)# encryption des
C(config-isakmp)# hash md5
C(config-isakmp)# authentication pre-share
C(config-isakmp)# group 2
C(config-isakmp)# exit
DEFINING KEY:
C(config)# crypto isakmp key hello address [Link] [Link]
hello = key/password
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 68
DEFINING TRANSFORM-SET:
C(config)# crypto ipsec transform-set shakeel esp-des esp-md5-hmac
shakeel = label for
transform-set
C(config-trans)# exit
DEFINING PROFILE:
C(config)# crypto ipsec profile haroon (haroon = profile name)
C(config-profile)# set transform-set shakeel
C(config-profile)# exit
DEFINING TUNNEL INTERFACE:
C(config)# interface tunnel 1
C(config-if)# ip address [Link] [Link]
C(config-if)# ip mtu 1412 (MTU should be between 1400 to 1420)
C(config-if)# ip nhrp authentication corvit (corvit =password for nhrp)
C(config-if)# ip nhrp map [Link] [Link]
[Link] = Tunnel interface address of
Server (Router-A)
[Link] = Actual interface address of
Server (Router-A)
C(config-if)# ip nhrp map multicast [Link]
[Link] = Actual interface address of
Server (Router-A)
C(config-if)# ip nhrp network-id 99
C(config-if)# ip nhrp nhs [Link]
[Link] = Tunnel interface address of
Server (Router-A)
NHS = Next Hop Server
NHRP = Next Hop Routing Protocol
C(config-if)# tunnel source fastethernet 0/0
C(config-if)# tunnel mode gre multipoint
C(config-if)# tunnel key 123456 (123456 = set key/password for tunnel)
C(config-if)# tunnel protection ipsec profile haroon
C(config-if)# exit
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 69
RUNNING EIGRP:
C(config)# router eigrp 1
C(config-router)# network [Link]
C(config-router)# network [Link]
C(config-router)# no auto-summary
C(config-router)# exit
C# show ip route
NOTE: Network [Link] is not found in the routing table
of Router-C.
B# show ip route
NOTE: Network [Link] is not found in the routing table
of Router-B.
To complete the routing tables of Router-B & C, apply the following command
at Server (Router-A):
A(config)# interface fastethernet 0/0
A(config-if)# no ip split-horizon eigrp 1
A(config-if)# exit
A# show ip route
B# show ip route
NOTE: Network [Link] has been reached on Router-B.
C# show ip route
NOTE: Network [Link] has been reached on Router-C.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 70
B# ping [Link] source [Link]
B# ping [Link] source [Link]
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 71
LECTURE NO. 16
3rd April 2009
SDM (Security Device Manager)
Source: [Link]
Cisco Router and Security Device Manager (SDM) is a Web-based device-
management tool for Cisco routers that can improve the productivity of
network managers, simplify router deployments, and help troubleshoot
complex network and VPN connectivity issues.
Cisco SDM offers smart wizards and advanced configuration support for LAN
and WAN interfaces, Network Address Translation (NAT), stateful and
application firewall policy, IPS, IPSec VPN, QoS, and NAC policy features.
The firewall wizard allows a single-step deployment of high, medium, or low
firewall policy settings. Cisco SDM also offers a one-click router lockdown
and an innovative security auditing capability to check and recommend
changes to router configuration based on ICSA Labs and Cisco TAC
recommendations.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 72
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 73
HSRP (High Availability of VPN)
Source: [Link]
Short for Hot Standby Routing Protocol, a proprietary protocol from Cisco.
HSRP is a routing protocol that provides backup to a router in the event of
failure. Using HSRP, several routers are connected to the same segment of
an Ethernet, FDDI or token-ring network and work together to present the
appearance of a single virtual router on the LAN. The routers share the
same IP and MAC addresses, therefore in the event of failure of one router,
the hosts on the LAN are able to continue forwarding packets to a
consistent IP and MAC address. The process of transferring the routing
responsibilities from one device to another is transparent to the user.
Source: [Link]
The memo specifies the Hot Standby Router Protocol (HSRP). The goal of the
protocol is to allow hosts to appear to use a single router and to maintain
connectivity even if the actual first hop router they are using fails.
Multiple routers participate in this protocol and in concert create the
illusion of a single virtual router. The protocol insures that one and only
one of the routers is forwarding packets on behalf of the virtual router.
End hosts forward their packets to the virtual router.
The router forwarding packets is known as the active router. A standby
router is selected to replace the active router should it fail. The
protocol provides a mechanism for determining active and standby routers,
using the IP addresses on the participating routers. If an active router
fails a standby router can take over without a major interruption in the
host's connectivity.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 74
SYSLOG SERVER (KIWI SYSLOG SERVER)
Source: [Link]
Kiwi Syslog Server receives syslog messages from network devices, and
displays them in real-time. Actions can be performed on received messages
and messages can be filtered by host name, host IP address, priority,
message text or time of day.
Syslog messages can then be processed using events like:
• Display the message in the scrolling window
• Logging the message to a text file
• Forward the message to another syslog server
• Log to an ODBC database
• Log to the NT Application Event Log
• E-mail the message to someone via SMTP
• Triggering a sound alarm
• Run an external program
• Send an SNMP Trap message
• Page someone using NotePager Pro
GENERATING LOG MESSAGES USING SYSLOG SERVER
1. Run Syslog Server.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 75
2. Apply following commands on Router.
A(config)# logging on
A(config)# logging host [Link]
A(config-if)# logging trap 7
A(config-if)# Ctrl+Z
NOTE: [Link] is the ip address of the computer onto which
Syslog Server is installed.
3. Apply some commands (which generate messages after they are applied) on
Router and see results at Syslog Server. e.g.
A(config)# crypto map smap 10 ipsec-isakmp
A(config)# interface tunnel 1
A(config-if)# crypto map smap
A(config-if)# Ctrl+Z
A#
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 76
GENERATING LOG MESSAGES USING ROUTER MEMORY
NOTE: This method is highly not recommended because it utilizes
routers memory, which causes slow performance of router.
A(config)# logging on
A(config)# logging buffered
A(config)# exit
A# show logging
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 77
TIME BASED ACCESS CONTROL LIST (ACL)
A(config)# access-list 101 deny tcp any host [Link] equal
www time-range pakistan
Pakistan is label name
A(config)# time-range pakistan
A(config-time-range)# periodic weekdays 09:00 to 18:00
NOTE: Before applying above commands, set your router time.
Practiced way is to create a NTP server which set the
time of all routers in a setup.
NTP SERVER
A(config)# ntp server [Link]
NOTE: [Link] is the ip address of the router onto which
you are preparing NTP Server. After applying this
command, all routers will sink time from NTP Server.
A# clock set 18:57:00 6 April 2009
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 78
LECTURE NO. 17
6 April 2009
ATTACKS
RECOVERING ENCRYPTED SERVICE PASSWORD:
A(config)# service password-encryption
A(config)# line console 0
A(config-if)# password shakeel
A(config-if)# Ctrl+Z
A# show running
Copy the above encrypted service password from running-configuration, paste
it into [Link] website and click on
"CRACK IT" button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 79
CAPTURING RUNNING CONFIGURATION:
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 80
RECOVERING ENABLE SECRET:
A(config)# no service password-encryption
A(config)# enable secret dct
A(config)# Ctrl+Z
A# show running
1. Copy enable secret from running-configuration.
2. Run "CAIN" software/application.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 81
3. Click on "CRACKER" tab.
4. Click "CISCO-IOS-MD5-HASHES" option.
5. Right click on the white area and select "ADD TO LIST" option.
6. Paste the enable secret and press "OK" button.
7. Right click on the hash key value and select "BRUTE-FORCE ATTACK"
option.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 82
8. Brute-Force Attack window appears. Click on "START" button.
9. Hash value has been cracked i.e. dct
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 83
GRABING PORTS USING "PORT FUCK" TOOL:
HACKER'S PC – BEFORE RUNNING PORTFUCK APPLICATION
1. Launch PortFuck application from hacker's pc.
2. Type Host Ip Address.
3. Type port number of host; the port which you want to grab.
4. Press START button.
5. Apply following command at command shell of hacker's pc.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 84
HACKER'S PC – AFTER RUNNING PORTFUCK APPLICATION
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 85
PROTOCOL vs PORT NUMBERS
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 86
USING "THE ETHEREAL NETWORK ANALYZER" FOR RECOVERING
RUNNING-CONFIGURATION:
1. Launch "The Ethereal Network Analyzer" .
2. Click on "CAPTURE" menu.
3. Select "OPTIONS".
4. Select interface from interface list box.
5. Press START button.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 87
6. "Ethereal: Capture from Adapter for generic dialup and VPN capture"
window appears.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 88
LECTURE NO. 18
8 April 2009
IOS FIREWALL
CBAC (CONTACT BASE ACCESS CONTROL)
Figure-18a (Firewall)
CASE # 1
Figure-18b
(Note: Lab results are produced using GNS3 simulator)
BASIC CONFIGURATION OF ROUTER-INSIDE, BORDER-ROUTER &
ROUTER-OUTSIDE:
INSIDE(config)# interface fastethernet 0/1
INSIDE(config-if)# ip address [Link] [Link]
INSIDE(config-if)# no shutdown
BORDER(config)# interface fastethernet 0/1
BORDER(config-if)# ip address [Link] [Link]
BORDER(config-if)# no shutdown
BORDER(config-if)# exit
BORDER(config)# interface fastethernet 0/0
BORDER(config-if)# ip address [Link] [Link]
BORDER(config-if)# no shutdown
OUTSIDE(config)# interface fastethernet 0/0
OUTSIDE(config-if)# ip address [Link] [Link]
OUTSIDE(config-if)# no shutdown
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 89
RUNNING EIGRP ON ROUTER-INSIDE, BORDER-ROUTER & ROUTER-
OUTSIDE:
INSIDE(config)# router eigrp 1
INSIDE(config-router)# network [Link]
BORDER(config)# router eigrp 1
BORDER(config-router)# network [Link]
BORDER(config-router)# network [Link]
OUTSIDE(config)# router eigrp 1
OUTSIDE(config-router)# network [Link]
INSIDE# ping [Link]
NOTE: Successfully ping to OUTSIDE Router.
INSIDE# telnet [Link]
NOTE: Successfully telnet to OUTSIDE Router.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 90
CASE # 2
Figure-18c
(Note: Lab results are produced using GNS3 simulator)
BASIC CONFIGURATION OF ROUTER-INSIDE, BORDER-ROUTER &
ROUTER-OUTSIDE:
Same as above.
RUNNING EIGRP ON ROUTER-INSIDE, BORDER-ROUTER & ROUTER-
OUTSIDE:
Same as above.
DEFINING & APPLYING ACCESS-LIST ON BORDER ROUTER:
BORDER(config)# access-list 101 deny ip any any
BORDER(config)# interface fastethernet 0/0
BORDER(config-if)# ip access-group 101 in
BORDER(config-if)# Ctrl+Z
INSIDE# ping [Link]
NOTE: Failed to ping OUTSIDE Router.
INSIDE# telnet [Link]
NOTE: Failed to telnet OUTSIDE Router.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 91
CASE # 3
Figure-18d
(Note: Lab results are produced using GNS3 simulator)
(After applying ACL at interface fastethernet 0/0 and inspection rule at
fastethernet 0/1, Border Router shall behave as IOS Firewall.)
BASIC CONFIGURATION OF ROUTER-INSIDE, BORDER-ROUTER &
ROUTER-OUTSIDE:
Same as above.
RUNNING EIGRP ON ROUTER-INSIDE, BORDER-ROUTER & ROUTER-
OUTSIDE:
Same as above.
DEFINING & APPLYING ACCESS-LIST AT BORDER ROUTER:
BORDER(config)# access-list 101 deny ip any any
BORDER(config)# interface fastethernet 0/0
BORDER(config-if)# ip access-group 101 in
BORDER(config-if)# Ctrl+Z
INSIDE# ping [Link]
NOTE: Failed to ping OUTSIDE Router.
INSIDE# telnet [Link]
NOTE: Failed to telnet OUTSIDE Router.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 92
DEFINING & APPLYING INSPECTION RULE FOR ICMP AT BORDER
ROUTER:
BORDER(config)# ip inspect name shakeel icmp
BORDER(config)# interface fastethernet 0/1
BORDER(config-if)# ip inspect shakeel in
BORDER(config-if)# Ctrl+Z
NOTE: shakeel is a lable name.
INSIDE# ping [Link]
NOTE: Successfully ping to OUTSIDE Router.
INSIDE# telnet [Link]
NOTE: Failed to telnet OUTSIDE Router.
DEFINING & APPLYING INSPECTION RULE FOR TCP AT BORDER
ROUTER:
BORDER(config)# ip inspect name nabeel tcp
BORDER(config)# interface fastethernet 0/1
BORDER(config-if)# ip inspect nabeel in
BORDER(config-if)# Ctrl+Z
NOTE: nabeel is a lable name.
INSIDE# telnet [Link]
NOTE: Successfully telnet to OUTSIDE Router.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 93
LECTURE NO. 19
10 April 2009
IOS IDS (Intrusion Detection System)
When a hacker attacks at your router, the attack matches with built-in or
custom made signature, which can be found in router's database and if
attack matches with any signature, the signature fires and attacks blocks.
The results can be logged into a logging server (see Lecture No. 16).
Signature definition file can be downloaded from Cisco's web site.
Figure-19a
(Note: Lab results are produced using GNS3 simulator)
BASIC CONFIGURATION OF ROUTER-A:
A(config)# interface fastethernet 0/0
A(config-if)# ip address [Link] [Link]
A(config-if)# no shutdown
A(config-if)# exit
A(config)# logging on
A(config)# logging console
A(config)# logging host [Link]
A(config)# logging trap 7
DEFINING IDS FOR ALARMING/ALERTING:
A(config)# ip audit name shakeel attack action alarm
NOTE: shakeel is lable name.
A(config)# interface fastethernet 0/0
A(config-if)# ip audit shakeel in
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 94
HACKER'S ATTACK:
C:\ PING [Link] -T -L 2000
NOTE: When a hacker attacks, signature no. 2150 fires/triggers
and it generates an alarm message into Syslog Server as
well as into router’s console window.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 95
DEFINING IDS FOR DROPPING THE ATTACK:
A(config)# interface fastethernet 0/0
A(config-if)# no ip audit shakeel in
A(config-if)# exit
A(config)# no ip audit name shakeel attack action alarm
A(config)# ip audit name shakeel attack action drop
A(config)# interface fastethernet 0/0
A(config-if)# ip audit shakeel in
HACKER'S ATTACK:
C:\ PING [Link] -T -L 2000
NOTE: When a hacker attacks, signature no. 2150 fires/triggers
it blocks/drops the attack and no alarm generates in
Syslog Server.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 96
DEFINING IDS FOR ALARMING AND DROPPING THE ATTACK:
A(config)# interface fastethernet 0/0
A(config-if)# no ip audit shakeel in
A(config-if)# exit
A(config)# no ip audit name shakeel attack action drop
A(config)# ip audit name shakeel attack action alarm drop
A(config)# interface fastethernet 0/0
A(config-if)# ip audit shakeel in
HACKER'S ATTACK:
C:\> PING [Link] -T -L 2000
NOTE: When a hacker attacks, signature no. 2150 fires/triggers
and drops/blocks the attack and also it generates an
alarm message into Syslog Server as well as into router’s
console window.
HOW TO DISABLE ALARMS?
A(config)# ip audit signature 2150 disable
A(config)# ip audit signature 2151 disable
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 97
IOS IPS (Intrusion Prevention System)
A(config)# ip ips name shakeel
NOTE: shakeel is lable name.
A(config)# interface fastethernet 0/0
A(config-if)# ip ips shakeel in
A(config-if)# exit
A# show ip ips all
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 98
HACKER'S ATTACK:
C:\> PING [Link] -T -L 2000
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 99
NOTE: Log has been generated and can be seen on Syslog Server
as well as on Router. Three signatures 2004, 2150 & 2151
have been triggered.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 100
SIGNATURES FILE
A signature file is a package of network patterns, policies, and/or
countermeasures developed for Cisco intrusion detection and prevention
system (IDS/IPS) products. This signature package, used by the IDS/IPS
products, enables the sensors to provide up-to-date protection for the
evolving threat environment. These IDS/IPS devices compare network traffic
(packets and streams) against data patterns within the signature file
library. This comparison is used to detect and control unauthorized or
malicious network traffic. Therefore, the signature file, once installed on
an IDS/IPS product, becomes the signature database used to detect
suspicious behavior and to provide protection against the latest
vulnerabilities and exploits.
HOW TO CHECK SIGNATURES DATABASE ?
A# show ip ips signatures
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 101
COPYING CISCO SIGNATURES FILE INTO ROUTER:
A# copy tftp flash
A(config)# ip ips sdf location flash:
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 102
LECTURE NO. 22
17 April 2009
MPLS
Source: [Link]/TERM/M/[Link]
Short for Multiprotocol Label Switching, an IETF initiative that
integrates Layer 2 information about network links (bandwidth, latency,
utilization) into Layer 3 (IP) within a particular autonomous system--or
ISP--in order to simplify and improve IP-packet exchange.
MPLS gives network operators a great deal of flexibility to divert and
route traffic around link failures, congestion, and bottlenecks.
From a QoS standpoint, ISPs will better be able to manage different kinds
of data streams based on priority and service plan. For instance, those who
subscribe to a premium service plan, or those who receive a lot of
streaming media or high-bandwidth content can see minimal latency and
packet loss.
When packets enter a MPLS-based network, Label Edge Routers (LERs) give
them a label (identifier). These labels not only contain information based
on the routing table entry (i.e., destination, bandwidth, delay, and other
metrics), but also refer to the IP header field (source IP address), Layer
4 socket number information, and differentiated service. Once this
classification is complete and mapped, different packets are assigned to
corresponding Labeled Switch Paths (LSPs), where Label Switch Routers
(LSRs) place outgoing labels on the packets.
With these LSPs, network operators can divert and route traffic based on
data-stream type and Internet-access customer.
Figure-22a
(Note: Lab results are produced using GNS3 simulator)
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 103
BASIC CONFIGURATION OF ROUTER-A:
A(config)# interface serial 1/0
A(config-if)# ip address [Link] [Link]
A(config-if)# no shutdown
A(config-if)# exit
A(config)# interface fastethernet 0/0
A(config-if)# ip address [Link] [Link]
A(config-if)# no shutdown
A(config-if)# exit
A(config)# interface loopback 0
A(config-if)# ip address [Link] [Link]
A(config-if)# exit
BASIC CONFIGURATION OF ROUTER-B:
B(config)# interface serial 1/1
B(config-if)# ip address [Link] [Link]
B(config-if)# clock rate 64000
B(config-if)# no shutdown
B(config-if)# exit
B(config)# interface serial 1/0
B(config-if)# ip address [Link] [Link]
B(config-if)# clock rate 64000
B(config-if)# no shutdown
B(config-if)# exit
B(config)# interface fastethernet 0/0
B(config-if)# ip address [Link] [Link]
B(config-if)# no shutdown
B(config-if)# exit
B(config)# interface loopback 0
B(config-if)# ip address [Link] [Link]
B(config-if)# exit
BASIC CONFIGURATION OF ROUTER-C:
C(config)# interface serial 1/1
C(config-if)# ip address [Link] [Link]
C(config-if)# no shutdown
C(config-if)# exit
C(config)# interface serial 1/0
C(config-if)# ip address [Link] [Link]
C(config-if)# no shutdown
C(config-if)# exit
C(config)# interface fastethernet 0/0
C(config-if)# ip address [Link] [Link]
C(config-if)# no shutdown
C(config-if)# exit
C(config)# interface loopback 0
C(config-if)# ip address [Link] [Link]
C(config-if)# exit
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 104
BASIC CONFIGURATION OF ROUTER-D:
D(config)# interface serial 1/1
D(config-if)# ip address [Link] [Link]
D(config-if)# clock rate 64000
D(config-if)# no shutdown
D(config-if)# exit
D(config)# interface serial 1/0
D(config-if)# ip address [Link] [Link]
D(config-if)# clock rate 64000
D(config-if)# no shutdown
D(config-if)# exit
D(config)# interface fastethernet 0/0
D(config-if)# ip address [Link] [Link]
D(config-if)# no shutdown
D(config-if)# exit
D(config)# interface loopback 0
D(config-if)# ip address [Link] [Link]
D(config-if)# exit
BASIC CONFIGURATION OF ROUTER-E:
E(config)# interface serial 1/1
E(config-if)# ip address [Link] [Link]
E(config-if)# no shutdown
E(config-if)# exit
E(config)# interface fastethernet 0/0
E(config-if)# ip address [Link] [Link]
E(config-if)# no shutdown
E(config-if)# exit
E(config)# interface loopback 0
E(config-if)# ip address [Link] [Link]
E(config-if)# exit
RUNNING OSPF ON ROUTER-A, B, C, D & E:
A(config)# router ospf 5
A(config-router)# network [Link] [Link] area 0
A(config-router)# network [Link] [Link] area 0
A(config-router)# network [Link] [Link] area 0
A(config-router)# end
A#
B(config)# router ospf 5
B(config-router)# network [Link] [Link] area 0
B(config-router)# network [Link] [Link] area 0
B(config-router)# network [Link] [Link] area 0
B(config-router)# network [Link] [Link] area 0
B(config-router)# end
B#
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 105
C(config)# router ospf 5
C(config-router)# network [Link] [Link] area 0
C(config-router)# network [Link] [Link] area 0
C(config-router)# network [Link] [Link] area 0
C(config-router)# network [Link] [Link] area 0
C(config-router)# end
C#
D(config)# router ospf 5
D(config-router)# network [Link] [Link] area 0
D(config-router)# network [Link] [Link] area 0
D(config-router)# network [Link] [Link] area 0
D(config-router)# network [Link] [Link] area 0
D(config-router)# end
D#
E(config)# router ospf 5
E(config-router)# network [Link] [Link] area 0
E(config-router)# network [Link] [Link] area 0
E(config-router)# network [Link] [Link] area 0
E(config-router)# end
E#
ROUTING TABLE OF ROUTER-A, B, C, D & E:
A# show ip route
B# show ip route
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 106
C# show ip route
D# show ip route
E# show ip route
NOTE: Routing tables of Router-A, B, C, D & F have been
completely converged.
RUNNING MPLS ON ROUTER-A, B C & D:
A(config)# ip cef
A(config)# mpls ip
A(config)# mpls label protocol ldp
A(config)# mpls ldp router-id loopback 0
A(config)# interface serial 1/0
A(config-if)# mpls ip
A(config-if)# end
A#
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 107
B(config)# ip cef
B(config)# mpls ip
B(config)# mpls label protocol ldp
B(config)# mpls ldp router-id loopback 0
B(config)# interface serial 1/1
B(config-if)# mpls ip
B(config-if)# exit
B(config)# interface serial 1/0
B(config-if)# mpls ip
B(config-if)# end
B#
C(config)# ip cef
C(config)# mpls ip
C(config)# mpls label protocol ldp
C(config)# mpls ldp router-id loopback 0
C(config)# interface serial 1/1
C(config-if)# mpls ip
C(config-if)# exit
C(config)# interface serial 1/0
C(config-if)# mpls ip
C(config-if)# end
C#
D(config)# ip cef
D(config)# mpls ip
D(config)# mpls label protocol ldp
D(config)# mpls ldp router-id loopback 0
D(config)# interface serial 1/1
D(config-if)# mpls ip
D(config-if)# end
D#
SHOW MPLS LDP NEIGHBOR COMMAND:
A# show mpls ldp neighbor
B# show mpls ldp neighbor
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 108
C# show mpls ldp neighbor
D# show mpls ldp neighbor
E# show mpls ldp neighbor
--- No neighbor is found ---
SHOW MPLS INTERFACES COMMAND:
A# show mpls interfaces
B# show mpls interfaces
C# show mpls interfaces
D# show mpls interfaces
E# show mpls interfaces
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 109
SHOW MPLS LDP BINDINGS COMMAND:
A# show mpls ldp bindings
B# show mpls ldp bindings
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 110
C# show mpls ldp bindings
D# show mpls ldp bindings
E# show mpls ldp bindings
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 111
SHOW MPLS FORWARDING-TABLE COMMAND:
A# show mpls forwarding-table
B# show mpls forwarding-table
C# show mpls forwarding-table
D# show mpls forwarding-table
E# show mpls forwarding-table
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 112
LECTURE NO. 25
25 MAY 2009
MPLS VPNs
(PEER-TO-PEER + OVERLAY)
Figure-25a
(Note: Lab results are produced using GNS3 simulator)
BASIC CONFIGURATION OF ROUTER-A:
A(config)# interface serial 1/0
A(config-if)# ip address [Link] [Link]
A(config-if)# no shutdown
A(config-if)# exit
A(config)# interface fastethernet 0/0
A(config-if)# ip address [Link] [Link]
A(config-if)# no shutdown
A(config-if)# exit
A(config)# interface loopback 0
A(config-if)# ip address [Link] [Link]
A(config-if)# exit
BASIC CONFIGURATION OF ROUTER-B:
B(config)# interface serial 1/1
B(config-if)# ip address [Link] [Link]
B(config-if)# clock rate 64000
B(config-if)# no shutdown
B(config-if)# exit
B(config)# interface serial 1/0
B(config-if)# ip address [Link] [Link]
B(config-if)# clock rate 64000
B(config-if)# no shutdown
B(config-if)# exit
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 113
B(config)# interface fastethernet 0/0
B(config-if)# ip address [Link] [Link]
B(config-if)# no shutdown
B(config-if)# exit
B(config)# interface loopback 0
B(config-if)# ip address [Link] [Link]
B(config-if)# exit
BASIC CONFIGURATION OF ROUTER-C:
C(config)# interface serial 1/1
C(config-if)# ip address [Link] [Link]
C(config-if)# no shutdown
C(config-if)# exit
C(config)# interface serial 1/0
C(config-if)# ip address [Link] [Link]
C(config-if)# no shutdown
C(config-if)# exit
C(config)# interface fastethernet 0/0
C(config-if)# ip address [Link] [Link]
C(config-if)# no shutdown
C(config-if)# exit
C(config)# interface loopback 0
C(config-if)# ip address [Link] [Link]
C(config-if)# exit
BASIC CONFIGURATION OF ROUTER-D:
D(config)# interface serial 1/1
D(config-if)# ip address [Link] [Link]
D(config-if)# clock rate 64000
D(config-if)# no shutdown
D(config-if)# exit
D(config)# interface serial 1/0
D(config-if)# ip address [Link] [Link]
D(config-if)# clock rate 64000
D(config-if)# no shutdown
D(config-if)# exit
D(config)# interface fastethernet 0/0
D(config-if)# ip address [Link] [Link]
D(config-if)# no shutdown
D(config-if)# exit
D(config)# interface loopback 0
D(config-if)# ip address [Link] [Link]
D(config-if)# exit
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 114
BASIC CONFIGURATION OF ROUTER-E:
E(config)# interface serial 1/1
E(config-if)# ip address [Link] [Link]
E(config-if)# no shutdown
E(config-if)# exit
E(config)# interface fastethernet 0/0
E(config-if)# ip address [Link] [Link]
E(config-if)# no shutdown
E(config-if)# exit
E(config)# interface loopback 0
E(config-if)# ip address [Link] [Link]
E(config-if)# exit
RUNNING OSPF ON ROUTER- B, C, & D:
B(config)# router ospf 1
B(config-router)# network [Link] [Link] area 0
B(config-router)# network [Link] [Link] area 0
B(config-router)# network [Link] [Link] area 0
B(config-router)# end
B#
C(config)# router ospf 1
C(config-router)# network [Link] [Link] area 0
C(config-router)# network [Link] [Link] area 0
C(config-router)# network [Link] [Link] area 0
C(config-router)# network [Link] [Link] area 0
C(config-router)# end
C#
D(config)# router ospf 1
D(config-router)# network [Link] [Link] area 0
D(config-router)# network [Link] [Link] area 0
D(config-router)# network [Link] [Link] area 0
D(config-router)# end
D#
ROUTING TABLE OF ROUTER-A, B, C, D & E:
A# show ip route
B# show ip route
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 115
C# show ip route
D# show ip route
E# show ip route
NOTE: Routing tables of Router-A, B, C, D & F are not fully
converged.
RUNNING MPLS ON ROUTER-B, C & D:
B(config)# ip cef
B(config)# mpls ip
B(config)# mpls label protocol ldp
B(config)# mpls ldp router-id loopback 0
B(config)# interface serial 1/0
B(config-if)# mpls ip
B(config-if)# end
B#
C(config)# ip cef
C(config)# mpls ip
C(config)# mpls label protocol ldp
C(config)# mpls ldp router-id loopback 0
C(config)# interface serial 1/1
C(config-if)# mpls ip
C(config-if)# exit
C(config)# interface serial 1/0
C(config-if)# mpls ip
C(config-if)# end
C#
D(config)# ip cef
D(config)# mpls ip
D(config)# mpls label protocol ldp
D(config)# mpls ldp router-id loopback 0
D(config)# interface serial 1/1
D(config-if)# mpls ip
D(config-if)# end
D#
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 116
VRF CONFIGURATION (PE1-to-CE1 SIDE):
B(config)# ip vrf shakeel
B(config-vrf)# rd 1:1
B(config-vrf)# route-target 1:1 OR route-target both
B(config-vrf)# end
B# ping [Link]
NOTE: Router-B has successfully ping the ip [Link]
B# configure terminal
B(config)# interface serial 1/1
B(config-if)# ip vrf forwarding shakeel
B(config-if)# ip address [Link] [Link]
B(config-if)# end
B# ping [Link]
NOTE: Router-B is failed to ping the ip address [Link]
B# show ip route
NOTE: Network [Link] is not found in the global routing table
of Router-B, that’s why it is failed to ping the ip
address [Link]
B# show ip route vrf shakeel
EXPLANATION: When we apply the above command (ip vrp forwarding
shakeel), it removes the ip address [Link] from
interface serial 1/1 of Router-B, or we can say that
directly connected network [Link] with Router-B has been
removed from global routing table of Router-B. After
again configuring ip address on serial 1/1 of Router-B,
you’ll notice that network [Link] is listed in the vrf
routing table of Router-B and you can ping the ip address
[Link] by using the following command:
B# ping vrf shakeel [Link]
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 117
VRF CONFIGURATION (PE2-to-CE2 SIDE):
D(config)# ip vrf shakeel
D(config-vrf)# rd 1:1
D(config-vrf)# route-target 1:1 OR route-target both
D(config-vrf)# exit
D(config)# interface serial 1/0
D(config-if)# ip vrf forwarding shakeel
D(config-if)# ip address [Link] [Link]
D(config-if)# end
D# ping [Link]
NOTE: Router-D is failed to ping the ip address [Link]
D# show ip route
NOTE: Network [Link] is not found in the global routing table
of Router-D, that’s why it is failed to ping the ip
address [Link].
D# show ip route vrf shakeel
EXPLANATION: When we apply the above command (ip vrp forwarding
shakeel), it removes the ip address [Link] from
interface serial 1/0 of Router-D, or we can say that
directly connected network [Link] with Router-D has been
removed from global routing table of Router-D. After
again configuring ip address on serial 1/0 of Router-D,
you’ll notice that network [Link] is listed in the vrf
routing table of Router-D and you can ping the ip address
[Link] by using the following command:
D# ping vrf shakeel [Link]
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 118
RUNNING MULTIPROTOCOL IBGP ON ROUTER-B & D:
B(config)# router bgp 1
B(config-router)# no auto-summary
B(config-router)# no synchronization
B(config-router)# neighbor [Link] remote-as 1
B(config-router)# neighbor [Link] update-source loopback 0
B(config-router)# address-family vpnv4
B(config-router-af)# neighbor [Link] activate
B(config-router-af)# exit
B(config-router)# exit
B(config)#
D(config)# router bgp 1
D(config-router)# no auto-summary
D(config-router)# no synchronization
D(config-router)# neighbor [Link] remote-as 1
D(config-router)# neighbor [Link] update-source loopback 0
D(config-router)# address-family vpnv4
D(config-router-af)# neighbor [Link] activate
D(config-router-af)# exit
D(config-router)# exit
D(config)#
RUNNING OSPF BETWEEN PE1 & CE1:
A(config)# router ospf 1
A(config-router)# network [Link] [Link] area 0
A(config-router)# network [Link] [Link] area 0
A(config-router)# network [Link] [Link] area 0
A(config-router)# end
A#
B(config)# router ospf 2 vrf shakeel
B(config-router)# router-id [Link]
OSPF: router-id [Link] in use by ospf process 1
B(config-router)# router-id [Link]
B(config-router)# network [Link] [Link] area 0
B(config-router)# end
B#
B# show ip route vrf shakeel
NOTE: Networks [Link] and [Link] have been reached in the
vrf (virtual routing & forwarding) table of Router-B.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 119
RUNNING OSPF BETWEEN PE2 & CE2:
D(config)# router ospf 2 vrf shakeel
D(config-router)# router-id [Link]
OSPF: router-id [Link] in use by ospf process 1
D(config-router)# router-id [Link]
D(config-router)# network [Link] [Link] area 0
D(config-router)# end
D#
E(config)# router ospf 1
E(config-router)# network [Link] [Link] area 0
E(config-router)# network [Link] [Link] area 0
E(config-router)# network [Link] [Link] area 0
E(config-router)# end
E#
D# show ip route vrf shakeel
NOTE: Networks [Link] and [Link] have been reached in the
vrf (virtual routing & forwarding) table of Router-D.
REDISTRIBUTION OF OSPF 2 INTO BGP:
B(config)# router bgp 1
B(config-router)# address-family ipv4 vrf shakeel
B(config-router-af)# redistribute ospf 2 match internal external 1
B(config-router-af)# end
B#
D(config)# router bgp 1
D(config-router)# address-family ipv4 vrf shakeel
D(config-router-af)# redistribute ospf 2 match internal external 1
D(config-router-af)# end
D#
VRF TABLE OF ROUTER-B & D:
B# show ip route vrf shakeel
D# show ip route vrf shakeel
NOTE: VRF routing tables of Router-B & D have been completely
converged and are maintaining separately from global
routing table.
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 120
REDISTRIBUTION OF BGP INTO OSPF 2:
B(config)# router ospf 2
B(config-router)# redistribute bgp 1 subnets
B(config-router)# end
B#
D(config)# router ospf 2
D(config-router)# redistribute bgp 1 subnets
D(config-router)# end
D#
ROUTING TABLE OF ROUTER-A & E:
A# show ip route
E# show ip route
NOTE: Routing tables of Router-A & E (client’s end) have been
completely converged and has no concern with the routes
of service provider.
MPLS FORWARDING-TABLE OF ROUTER-B & D:
B# show mpls forwarding-table
D# show mpls forwarding-table
Muhammad Shakeel Ashraf
ISCW LAB MANUAL Page No. 121
EZVPN - 47
SDM – 66-67-68
Running Config using Cain – 74
Etherial 81-82
IPS Signature File – 97
Signature File – 96
Muhammad Shakeel Ashraf