Showing posts with label Cisco. Show all posts
Showing posts with label Cisco. Show all posts

Thursday, 27 September 2018

How to use other vendor SFP in Cisco Switch??

--> If you use any other vendor SFP instead of Cisco in Cisco Catalyst switches, the port automatically goes to the err-disable state.

--> This is because by default Cisco Catalyst switches do not support another vendor SFPs in switch ports.

--> Each and every SFP contains the following number of details in its EEPROM,

i)Vendor Name

ii)Vendor ID

iii)Serial Number

iv)Security Code

v) CRC



--> When an SFP is placed into a switch's SFP port, the switch immediately checks whether the SFP is from Cisco or not.

--> If the inserted SFP is not from Cisco then the port goes into an err-disabled state.

--> In order to use another vendor SFP in a switch's SFP port, execute the following commands on the Cisco switch.

S1: To enable other Vendor SFP on switch's SFP port.

switch(config)# service unsupported-transceiver

S2: Configure the SFP port is not disabled when inserting another vendor SFP.

switch(config)# no errdisable detect cause gbic-invalid

S3: Reload the Switch 

switch(config)# reload

--> All these commands are going to work from IOS version 12.2(25)SE and above.

--> It is better not to use Cisco SFP if you are using in production network as there is no support from Cisco SFP for SFP related issues.

--> You can use other Vendor SFP, in case if you are using in the lab or want to save money.

Ref: Cisco.com

Md.Kareemoddin

CCIE # 54759

Sunday, 23 September 2018

What is Passive Interface?

--> Passive Interface is a feature used by routing protocol to stop sending updates on the particular interface.

--> Basically this command is applied on the router interface which is connected to LAN or Loopback.

--> Routing updates are only understood by the routers.

--> In the below scenario, there is no use of sending of updates on the fa0/0 interface.



--> Passive Interface feature works differently for each routing protocol.

RIP

--> Prevents Sending multicast updates on a passive interface.

--> Sends unicast updates on the passive interface if the neighbor command is configured.

--> Receives unicast and multicast on the interface.

Configuration:

Router rip

Passive-interface fa0/0

EIGRP

--> Prevents Sending of hello messages on a passive interface.

--> The router does not form any relationship on the passive interface.

--> Prevents sending and receiving of routing updates on the Passive interface.

Configuration:

Router eigrp 100

Passive-interface fa0/0

OSPF

--> Prevents Sending of hello messages on a passive interface.

--> The router does not form any relationship on the passive interface.

--> Prevents sending and receiving of routing updates on the Passive interface.

Configuration

Router ospf 1

Passive-interface fa0/0

Reference: Cisco.com

Md.Kareemoddin

CCIE #54759 


Friday, 27 July 2018

What is Dual Active Detection in VSS?

--> A Virtual Switching System is formed by using a VSL (virtual switch link) between both switches of 4500 or 6500 series.

--> In VSS, one switch acts as Active Switch and other as Standby Switch.

--> If the VSL Link between both the switches is broken, then standby switch assumes the active switch chassis has failed and becomes as an active switch in VSS.

--> But here, in this case, only the link between both the switches has been failed but the active switch is still working.

--> This Scenario results in both switches to work as active switches and it can cause the problem in the network.

--> Dual-Active Detection method can be configured in VSS to prevent this problem from happening.

--> It is recommended to configure Dual-Active Detection in VSS.

--> The dual-active detection can be configured by using the following methods,

i) Dual-Active Detection Using Enhanced PAgP

--> An enhanced version of PAgP is configured on the EtherChannel which provides the Dual-Active Detection.

--> Upstream Switch should support this functionality.

--> Not commonly used.

ii) Dual-Active Detection Using IP BFD

--> In this method we need to provide direct Ethernet connection between the two switches.

--> The VSS uses the Bidirectional Forwarding Detection (BFD) protocol to detect the connectivity between both the switches.

--> If the VSL between both the switches fails then both the switches try to form BFD neighbor relationship between them.

--> When the active switch receives a BFD message from neighbor switch then it understands VSL link between both the switches has been failed.


iii) Dual-Active Detection Using Dual-Active Fast Hello Packets

--> In this method also, we need to provide a direct Ethernet connection between the two VSS switches.

--> We can use up to four non-VSL links for this method.

--> The two switches periodically exchange special Layer 2 dual-active hello messages containing information about the switch state.

--> If the VSL link between both the switches fails and a dual-active scenario occurs, each switch recognizes from the peer’s messages that there is a dual-active scenario and starts recovery actions.


Monday, 14 May 2018

What is Forced Authorization Codes in CUCM ?

--> Forced Authorization Codes (FAC) is another method of implementing call restriction in Voice networks.

--> Forced Authorization Codes (FAC) requires a user to enter a code or PIN before to the call being connected.

--> Forced Authorization Codes (FAC) restrict outgoing voice calls to particular numbers.

--> Forced Authorization Codes (FAC) allows a user to place the voice call to Particular numbers from the different phone which does not have permissions by entering FAC.

--> However, the primary function of Forced Authorization Codes is call accounting and billing.

--> Forced Authorization Codes (FAC) are applied to route patterns in CUCM.



--> When a user calls to a number which uses a route pattern that requires Forced Authorization Codes, he will hear a tone prior to entering the code.

--> Once the user enters the correct code, the call is allowed and that call is specifically marked in call records with the Forced Authorization Code used.

--> Each and every Forced Authorization Code is associated with authorization level and is a number between 0 and 255.

--> We have to mention the authorization level while configuring route patterns with Forced Authorization Codes (FAC).

--> The call will be only allowed if  If the authorization level of the code entered is higher than the authorization level set on the route pattern.

--> Basically Forced Authorization Codes (FAC) will be applied to force users making calls to International numbers.

Ref: Cisco.com

Md.Kareemoddin

CCIE # 54759






Wednesday, 21 March 2018

Types of Security Operation Centers(SOC) ?

1) Threat Centric SOC

--> A threat-centric SOC actively searches for malicious threats in the network.

--> New threats can be identified with the help of

i) known vulnerabilities

2) threat intelligence feed services

3) malicious anomalies across networks.

--> In order to perform analysis we need to acquire relevant data.

--> Any threat-centric SOC process model should include processes and procedures for acquiring relevant data.



--> To deal with the security challenges, organizations need a simpler, scalable, threat-centric approach that addresses security across the entire attack continuum—before, during, and after an attack.

--> Before an attack, we need to implement policies and controls to defend the organization from attacks.

--> During an attack, it is critical to have the ability to continuously detect the presence of malware and block identified threats.

--> After an attack,  we need to minimize the impact of an attack by identifying the point of entry, Determine the scope of the attack and Contain the threat and remediate the infected host.

2) Compliance Based SOC

--> A compliance-based SOC is focused on comparing the complete organization network with the help of configuration templates and standard system builds.

--> This type of monitoring provides the capability to detect unauthorized changes and existing config problems that could lead to the security breach.

--> Typically, these issues cannot be identified by common security tools, such as vulnerability scanners, unless the configuration problem is actively exploited. During an exploit is not the best time to identify potential security issues within the network.

--> Linking an organization's risk management and incident response practices to an automated system compliance process is key to a successful compliance-based SOC.



3) Operational-based SOC

--> An operational-based SOC is an internally focused organization that is tasked with monitoring the security posture of an organization’s internal network.

-->  Focused on maintaining the operational integrity of the identity management and access policies, intrusion detection system rules, and the administration of firewall ACLs rules.

-->  CSIRT ( Computer Security Incident Response Team) is the most technically accurate term that describes an operational-based SOC.



Md.Kareemoddin

CCIE # 54759

Ref: Cisco 

Sunday, 11 March 2018

Understanding IP Header

--> IP Address operates at Layer 3 of OSI reference model and Layer 2 of TCP/IP model.

--> IP uses Packets to carry the information throughout the network.

--> IP  is a connectionless protocol which does not require any acknowledgment from the destination after it has been sent.



1) Version  

--> This is the first field in IPv4 Protocol header.

--> The size of this field is of 4 bits.

--> The Version field indicates the current IP version being used(IPv4 or IPv6).


2) Internal Header Length 

--> Indicates the size of the IP header.

--> The minimum length of the IP header is 20 bytes and maximum length of 60 bytes.

3) Service Type or Type of Service 

--> This field is of 8 bits which are used in Quality of Service.

--> The first three bits of this field are known as precedence bits and are not used currently.

--> The next 4 bits define the type of service and the last bit is left unused.

-->  Devices use TOS filed to set various options, such as low delay, high throughput, or high reliability.


4) Packet Length 

--> Indicates the size of the packet including IP header.

--> The maximum size of the packet is 65,535 bytes because of the Packet Length field is 16 bits.

--> The minimum size of the packet is 20 bytes.

--> Router performs fragmentation if the size of the packet is more than 65,535 bytes.

5) Identification

--> This field is required when reassembling of IP Packets required.

--> This value is incremented every-time an IP datagram is sent from source to the destination.

--> These fields are used to fragment and reassemble packets.

--> This field is necessary to combine individual IP packets back into a single datagram.

6) Flag

--> The size of this field comprises of three bits.

-->  Devices only uses the last two bits of this field as first bit kept reserved.

-->  The second bit of this field is known as  ‘Don’t Fragment’ bit. If the value of this field is set to 1 then the IP Packet is never fragmented or divided into fragments.

--> The third bit of this field is known as the ‘More Fragment’ bit.If the value of this field is set to 1 then it represents fragmented IP packet and more fragmented IP packets need to come after this.

--> In case of the last fragment of an IP packet, ‘More Fragment’ bit is not set signifying that this is the last fragment of a particular IP datagram.

7)  Fragmented offset 

--> In case of fragmented IP datagrams, this field contains the offset from the start of IP datagram.

--> So again, this field is used in reassembly of fragmented IP datagrams.

8) Time to live

-->  This field represents the number of layer 3 devices or Routers that the IP datagram will go through before being dropped.

--> When the IP Packet arrives at a router, the router decrements the TTL field by one.

--> When the TTL field becomes zero, the router drops the packet by sending an ICMP Time Exceeded message to the sender.

--> The traceroute application uses these ICMP Time Exceeded messages to print the routers used by packets to go from the source to the destination.

9) Protocol

--> The Protocol field defines which application the data is from or which application the data.

--> This field does not identify the application but identifies a protocol that sits above the IP layer that is used for application identification.

--> For example, protocol number 1 = ICMP, 6 = TCP, 17 = UDP.

10) Header checksum 

--> Header Checksum contains the value that is calculated based on the data of the IP header.

--> This field is used to determine if any errors have been introduced during the process of sending the IP Packet from source to destination.

--> If the checksum value is same at both sender and receiver then the IP Packet was not corrupted else its assumed that IP Packet was received corrupted.

--> Basically this field is used to check the integrity of an IP Packet.

11) Source IP Address 

--> This field is of 32 bits used to define Sender IP Address.

12) Destination IP Address

--> This field is of 32 bits used to define Receiver IP Address.


--> This field is of 32 bits used to define Sender IP Address.

13) Options and padding

--> This field varies in length from 0 to a multiple of 32 bits. 

--> If the option values are not a multiple of 32 bits, 0s are added or padded to ensure that this field contains a multiple of 32 bits.

--> The options field is not often used. Note that the value in the IHL field must include enough extra 32-bit words to hold all the options.

Reference : Cisco & WikiPedia

Md.Kareemoddin

CCIE # 54759

Monday, 25 December 2017

What is BFD?

--> BFD stands for bidirectional forwarding detection.

--> BFD is used to detect link failures very fastly compared to normal hello/hold down timers which are used in routing protocols.

--> BFD is independent of any routing protocol such as EIGRP/OSPF/BGP/static.

--> Depending on the routing protocol, we can lower the timers to achieve fast failure detection. e.g. in the case of OSPF, the lowest dead time can be one second and one can set the hello interval as low as 50ms.

--> But this lowering the hello and hold down timer leads to higher CPU utilization and unnecessarily waste the link bandwidth.

--> BFD is a UDP-based protocol that provides fast independent detection of layer-3 next hop failures in milliseconds.

--> BFD uses smaller hello packets similar to any routing protocol hello packets used to detect link failures.



--> BFD can be configured in two modes i) Asynchronous ii) Demand

--> To configure BFD on Cisco router, we need to go to the interface where you want to detect the link failure and use the following command

Ex: interface fa0/0

    bfd interval 30 min_rx 20 multiplier 3 

Note: 

--> 30 is the hello timer which specifies the frequency of BFD packets sent by the router.

--> 20 is the receive-timer which represent the minimum interval between packets accepted from BFD peers.

--> 3 is the multiplier which is the number of BFD hello packets can be lost before BFD peer id declared down.

Thursday, 26 October 2017

What is IP Source Routing?

--> Source routing is a technique whereby the sender of a packet can specify the route that a packet should take through the network.

--> As a packet travels through the network, each router will examine the destination IP address and choose the next hop to forward the packet to.

--> In source routing, the "source" (i.e., the sender) makes some or all of these decisions.

--> Cisco routers normally accept and process source routes. Unless a network depends on it, source routing should be disabled.

--> Attackers can use source routing to probe the network by forcing packets into specific parts of the network.



--> Using source routing, an attacker can collect information about a network's topology, or other information that could be useful in performing an attack.

-->  During an attack, an attacker could use source routing to direct packets to bypass existing security restrictions.

--> Use the 'no ip source-route' command to disable IP source routing on the Cisco router.