Showing posts with label ccna. Show all posts
Showing posts with label ccna. Show all posts

Sunday, 14 October 2018

What is IP Fragmentation?

--> When a device sends IP Packet to another device on the network, it should not be bigger than MTU value.

--> MTU stands for Maximum Transmission Unit.

--> The Maximum size of the MTU is 1500 bytes.

--> If the IP Packet of more than 1500 bytes then we need to divide this packet into smaller packets that are equal or less than MTU before sending to the other device.

--> This process is called as Fragmentation.

--> In order to identify each and every fragmented packet on the other device ( Receiving host ), Sending device adds fragmented ID for each packet for reassembly.

--> Fragmentation ID is actually a copy of IP identification Field that is present in IP Header.

--> Packets won't be reassembled until all the fragmented packets reach on the destination.

--> Each and every fragmented packet contains three items with it,

i) Offset -- specifies the location or place of the fragmented packet

ii) Length -- Size of the data

iii) More Fragments -- Indicates whether the next packet is fragmented packet or not.



--> If More Fragments Flag is equal to One specifies fragmented packets are coming next.

--> If More Fragments Flag is equal to zero specifies fragmented packets are finished.

Ex: If you want to send 4000 bytes data to other devices with MTU of 1500.

--> IP Header contains 20 bytes which will be added to DATA before sending to another device.

Fragmented Packet1 : IP header(20) | Data ( 1500) | ID = 88, Len = 1500, off = 0, MF = 1


Fragmented Packet2 : IP header(20) | Data ( 1500) | ID = 88, Len = 1500, off = 20, MF = 1


Fragmented Packet3 : IP header(20) | Data ( 1000) | ID = 88, Len = 1000, off = 0, MF = 0

ID = IP Identification Number

Len = Data Length

off = offset

MF = More Fragment

Saturday, 11 August 2018

What is the use of IP Directed Broadcast?

--> Broadcast traffic is one type of traffic, in which data is sent from one source to all the destinations.

--> Broadcast address in the network can be of two types,

1) Network Broadcast address: 255.255.255.255 ( This is used to forward the packet to all the devices within the subnet)

2) IP Broadcast Address: Last IP Address of each subnet ( Broadcast address of specific subnet).

--> Routers drop broadcast traffic as soon as they receive that on any interface of the router.

--> IP directed broadcast allows the router to forward the broadcast packet on a particular subnet.

--> IP directed broadcast basically used in wake-on-LAN (WOL) application by forwarding broadcast packets targeted at the hosts in a specified destination subnet.

--> IP directed broadcast packets are sent over the network in the same way as unicast IP packets until they reach the destination subnet.

--> When they reach the destination subnet and IP directed broadcast is enabled on the receiving switch, the switch translates the IP directed broadcast packet into a broadcast that floods the packet on the target subnet.

--> All hosts on the target subnet receive the IP directed broadcast packet.

--> Typically, you do not enable IP directed broadcast on subnets that have direct connections to the Internet.

--> Disabling IP directed broadcast on a subnet’s Layer 3 interface affects only that subnet.

--> If you disable IP directed broadcast on a subnet and a packet that has the broadcast IP address of that subnet arrives at the switch, the switch drops the broadcast packet.


Example:

--> If a device with ip 192.168.1.20/24 is sending broadcast traffic on the subnet by forwarding packets to 192.168.3.255/24.

--> The routers in between the path forwards the packet is similar to the unicast packet if ip direct broadcast is enabled.

--> It can cause DOS attacks and hence it is recommended to disable it.


Configuration on Cisco Devices

Router(config)# Int G0/0

Router(config-if)# ip directed-broadcast


Friday, 27 July 2018

Understanding Cisco IOS 15 License

--> When you purchase a Cisco router, it comes with an IOS image that has all feature sets included in it but you need to activate it with the help of license.

--> Cisco IOS 15 comes with 4 Feature sets and these 4 Features set combined into one single IOS image called as the universal image.

--> The feature sets are now called as technology packages.

1) IP BASE: (ipbaseK9)

--> By default, all the new ISR routers come with IP BASE License.

--> Its entry-level License for Cisco IOS functionality.

2) DATA (dataK9)

--> support MPLS.ATM. Multiprotocol support

3) Unified Communications (ucK9)

--> support VOIP & IP Telephony

4) Security (securityK9) 

--> support Cisco IOS Firewall,IPS,IPsec,3DES,VPN

--> Every router that supports the new licensing model contains a unique device identifier (UDI). 

--> This unique device identifier (UDI) number is a combination of the product ID (PID) and a serial number (SN). 



--> We can check this unique device identifier (UDI) number on the router, with the help of the following command,

Router # show license udi

--> The UDI is also printed on a label that is located on the back of every switch or router.

--> To check which license is being installed on the router, with the help of the following command,

Router # show license

--> In order to install the license on the router or switch, we need PAK (Product Authorization Key).

--> This PAK includes a unique number which Cisco uses to check what license you have purchased.

--> Then this PAK and UDI of the router or Switch creates a license key.

--> This can be done with the help of Cisco License Registration Portal where you need to enter the PAK and the UDI. 

--> Cisco will check if your PAK and UDI are valid and activated or not before. If everything is OK, then you get the license key.

--> Once you get the license key, we need to copy this license key on Flash with the help of TFTP Server or FTP Server.

--> Once License Key in the flash of the router or switch then we can install the license using the following command,

Router# license install flash0:uck9-1900-SPE15dj0_K9-FHH1221357.xml

Router# reload 

--> This license can be permanent( Needs License from cisco to run it forever) or evaluation (available with all functionality for the trial period would be 60 days).

Md.Kareemoddin

CCIE # 54759

Wednesday, 21 March 2018

Types of Security Operation Centers(SOC) ?

1) Threat Centric SOC

--> A threat-centric SOC actively searches for malicious threats in the network.

--> New threats can be identified with the help of

i) known vulnerabilities

2) threat intelligence feed services

3) malicious anomalies across networks.

--> In order to perform analysis we need to acquire relevant data.

--> Any threat-centric SOC process model should include processes and procedures for acquiring relevant data.



--> To deal with the security challenges, organizations need a simpler, scalable, threat-centric approach that addresses security across the entire attack continuum—before, during, and after an attack.

--> Before an attack, we need to implement policies and controls to defend the organization from attacks.

--> During an attack, it is critical to have the ability to continuously detect the presence of malware and block identified threats.

--> After an attack,  we need to minimize the impact of an attack by identifying the point of entry, Determine the scope of the attack and Contain the threat and remediate the infected host.

2) Compliance Based SOC

--> A compliance-based SOC is focused on comparing the complete organization network with the help of configuration templates and standard system builds.

--> This type of monitoring provides the capability to detect unauthorized changes and existing config problems that could lead to the security breach.

--> Typically, these issues cannot be identified by common security tools, such as vulnerability scanners, unless the configuration problem is actively exploited. During an exploit is not the best time to identify potential security issues within the network.

--> Linking an organization's risk management and incident response practices to an automated system compliance process is key to a successful compliance-based SOC.



3) Operational-based SOC

--> An operational-based SOC is an internally focused organization that is tasked with monitoring the security posture of an organization’s internal network.

-->  Focused on maintaining the operational integrity of the identity management and access policies, intrusion detection system rules, and the administration of firewall ACLs rules.

-->  CSIRT ( Computer Security Incident Response Team) is the most technically accurate term that describes an operational-based SOC.



Md.Kareemoddin

CCIE # 54759

Ref: Cisco 

Monday, 19 March 2018

Why DNS uses both TCP and UDP?

-->  DNS and some other Services uses both the TCP and UDP Protocols for working.

--> These two protocols are so different from each other. TCP is a connection-oriented protocol whereas UDP is a connection-less protocol.

--> DNS Servers need to maintain the same database between each other, This is achieved by using Zone Transfer feature.

-->  The Zone Transfer feature of DNS Server always uses TCP protocol. The connection is established between the DNS Server to transfer the zone data and Source and Destination DNS Servers will make sure that data is consistent by using TCP ACK bit.

--> This communication happens between DNS Servers only.

--> A client computer will always send a DNS Query using UDP Protocol over Port 53.

-->  If a client computer does not get the response from a DNS Server, it must re-transmit the DNS Query using the TCP after 3-5 seconds of interval.

--> In simple terms,  the communication between DNS Servers done by TCP Protocol whereas the communication between client and DNS Server is done by UDP Protocol.

--> In Firewall Policies we need to allow both TCP and UDP Port 53 to Your DNS Servers.

Md.Kareemoddin

CCIE # 54759

Understanding Netstat Command

--> netstat (network statistics) is a network utility tool that shows network connections for the Transmission Control Protocol (both incoming and outgoing) and User Datagram Protocol, routing tables, and a number of network interface (network interface controller or software-defined network interface) and network protocol statistics.

--> It is used for finding problems in the network and to determine the amount of traffic on the network as a performance measurement.

--> The command “netstat” displays information about the network ports in use on the system. 

--> Netstat comes installed on all current releases of Windows systems. Run with no parameters, netstat will simply display a list of active connections on the local system.


-->  The last column shows the current state of the connection. This entry will normally be one of the
following:

LISTENING: The port is open and listening for inbound connections.

ESTABLISHED: The connection is active between the two systems.

TIMED_WAIT: The connection has recently ended.

SYN_SEND, SYN_RECEIVED: Either of these may appear during the initial connection setup.

FIN_WAIT, CLOSE_WAIT, LAST_ACK: Any of these may appear while a connection is being closed.

--> If it says 0.0.0.0 on the Local Address column, it means that port is listening on all 'network interfaces.

--> If it says 127.0.0.1 on the Local Address column, it means that port is ONLY listening for connections from your PC itself, not from the Internet or network.

--> If it displays your online IP on the Local Address column, it means that port is ONLY listening for connections from the Internet.

--> If it displays your local network IP on the Local Address column, it means that port is ONLY listening for connections from the local network.

Netstat Commands

1) netstat -a : will list all TCP and UDP connection information, including information about not only active connections but also ports that are currently open on the system.

2) netstat -n: tells netstat to show all results in numeric format. This displays IP addresses and ports as numbers rather than trying to convert them to some type of name.



3) netstat -o : shows the process identifier (PID) of the process that is bound to a listening port or that is using an established connection.This can be extremely useful in determining why a particular port is open.



4) netstat -ab : shows the same info as “netstat –a” plus it shows process names listening on these ports.


5) netstat -r : shows routing table on the device.


Md.Kareemoddin

CCIE # 54759

Understanding Cisco Switch Naming Convention

--> Cisco Switch Naming Convention


Sunday, 11 March 2018

Understanding IP Header

--> IP Address operates at Layer 3 of OSI reference model and Layer 2 of TCP/IP model.

--> IP uses Packets to carry the information throughout the network.

--> IP  is a connectionless protocol which does not require any acknowledgment from the destination after it has been sent.



1) Version  

--> This is the first field in IPv4 Protocol header.

--> The size of this field is of 4 bits.

--> The Version field indicates the current IP version being used(IPv4 or IPv6).


2) Internal Header Length 

--> Indicates the size of the IP header.

--> The minimum length of the IP header is 20 bytes and maximum length of 60 bytes.

3) Service Type or Type of Service 

--> This field is of 8 bits which are used in Quality of Service.

--> The first three bits of this field are known as precedence bits and are not used currently.

--> The next 4 bits define the type of service and the last bit is left unused.

-->  Devices use TOS filed to set various options, such as low delay, high throughput, or high reliability.


4) Packet Length 

--> Indicates the size of the packet including IP header.

--> The maximum size of the packet is 65,535 bytes because of the Packet Length field is 16 bits.

--> The minimum size of the packet is 20 bytes.

--> Router performs fragmentation if the size of the packet is more than 65,535 bytes.

5) Identification

--> This field is required when reassembling of IP Packets required.

--> This value is incremented every-time an IP datagram is sent from source to the destination.

--> These fields are used to fragment and reassemble packets.

--> This field is necessary to combine individual IP packets back into a single datagram.

6) Flag

--> The size of this field comprises of three bits.

-->  Devices only uses the last two bits of this field as first bit kept reserved.

-->  The second bit of this field is known as  ‘Don’t Fragment’ bit. If the value of this field is set to 1 then the IP Packet is never fragmented or divided into fragments.

--> The third bit of this field is known as the ‘More Fragment’ bit.If the value of this field is set to 1 then it represents fragmented IP packet and more fragmented IP packets need to come after this.

--> In case of the last fragment of an IP packet, ‘More Fragment’ bit is not set signifying that this is the last fragment of a particular IP datagram.

7)  Fragmented offset 

--> In case of fragmented IP datagrams, this field contains the offset from the start of IP datagram.

--> So again, this field is used in reassembly of fragmented IP datagrams.

8) Time to live

-->  This field represents the number of layer 3 devices or Routers that the IP datagram will go through before being dropped.

--> When the IP Packet arrives at a router, the router decrements the TTL field by one.

--> When the TTL field becomes zero, the router drops the packet by sending an ICMP Time Exceeded message to the sender.

--> The traceroute application uses these ICMP Time Exceeded messages to print the routers used by packets to go from the source to the destination.

9) Protocol

--> The Protocol field defines which application the data is from or which application the data.

--> This field does not identify the application but identifies a protocol that sits above the IP layer that is used for application identification.

--> For example, protocol number 1 = ICMP, 6 = TCP, 17 = UDP.

10) Header checksum 

--> Header Checksum contains the value that is calculated based on the data of the IP header.

--> This field is used to determine if any errors have been introduced during the process of sending the IP Packet from source to destination.

--> If the checksum value is same at both sender and receiver then the IP Packet was not corrupted else its assumed that IP Packet was received corrupted.

--> Basically this field is used to check the integrity of an IP Packet.

11) Source IP Address 

--> This field is of 32 bits used to define Sender IP Address.

12) Destination IP Address

--> This field is of 32 bits used to define Receiver IP Address.


--> This field is of 32 bits used to define Sender IP Address.

13) Options and padding

--> This field varies in length from 0 to a multiple of 32 bits. 

--> If the option values are not a multiple of 32 bits, 0s are added or padded to ensure that this field contains a multiple of 32 bits.

--> The options field is not often used. Note that the value in the IHL field must include enough extra 32-bit words to hold all the options.

Reference : Cisco & WikiPedia

Md.Kareemoddin

CCIE # 54759

Thursday, 1 March 2018

Difference between SFP, SFP+, QSFP, QSFP+, XFP and CFP Modules

SFP:

--> SFP stands for Small Form Factor Pluggable and it is also called as mini GBIC.

--> SFP transceiver modules support SONET, Fast Ethernet, Gigabit Ethernet, Fibre Channel, and other communications standards.

--> Copper cables and fiber cables can be used in SFP module.

--> SFP supports data rate up to 5 Gbps.



SFP+

--> SFP+ stands for small form factor pluggable plus.

-->  SFP+ transceiver modules support Gigabit Ethernet, Fibre Channel, and other communications standards.

--> Twinax cables, Copper Cables and fiber cables can be used in SFP+ module.

--> SFP+ supports data rate upto 10 Gbps.



QSFP and QSFP+

--> QSFP stands for Quad Small Form-factor Pluggable.

--> The QSFP transceiver module supports Ethernet, Fibre Channel, InfiniBand and SONET/SDH standards with different data rate options.

--> Quad-SFP (QSFP) ports use a single MTP connector supports up to four channels or ports. 

-->  QSFP+ stands for Quad Small Form-factor pluggable plus. The difference is only the data rate between the QSFP and QSFP+ 

--> QSFP has four-channel SFP interfaces which can transfer rates up to 4x1Gbps.

--> QSFP+ has four-channel SFP+ interfaces which can transfer rates up to 4x10Gbps.

--> QSFP28 is a four-channel QSFP+ module to carry 100 Gbps Ethernet.



XFP:

--> XFP stands for 10 Gigabit Small Form Factor Pluggable.

--> XFP transceiver modules support SONET, 10 Gigabit Ethernet, 10 Gigabit Fibre Channel, and other communications standards.

--> XFP is a slightly larger form factor than the popular small form-factor pluggable transceiver, SFP, and SFP+.

--> XFP modules are hot-swappable and protocol-independent. 

--> XFP supports data rate up to 10 Gbps.



CFP:

--> CFP stands for C form-factor pluggable.

--> The CFP is a multi-source agreement to produce a common form-factor for the transmission of high-speed digital signals.

--> CFP standard was primarily developed for 100 Gigabit Ethernet systems.

--> CFP supports data rate upto 100 Gbps.

Md.Kareem

CCIE 54759

Saturday, 14 October 2017

What is Blackhole network

--> Blackhole routes are the special type of static route that is used to drop all the traffic sent to it.

--> A black hole route is used to forward unwanted or undesirable traffic into a black hole.

--> Blackhole routes are also called as null 0 routes.

--> A null route may mainly be used to mitigate DoS attacks there are some other uses.

-->Any time you want to prevent a system from talking to another system you can simply use null routes.

--> Any traffic that has a destination address that has the best match of the black hole static route automatically is dropped.

--> this security solution should be used only for known destination addresses that you never want your router to forward traffic to.

Blackhole route or Null0 Configuration


Router(config)# ip route destination_network_# [subnet_mask] null0

--> When using the null0 interface for black hole routing, you will want to prevent your router from sending ICMP unreachable messages to the sender of the packet, like this:

Router(config)# interface null0

Router(config-if)# no ip unreachables


--> If you do not do this, a hacker can take advantage of this loophole in your configuration to create a DoS attack by flooding your router with black-holed addresses, causing your router to generate an ICMP unreachable message for each packet that the router drops.


--> Hackers like to use this type of DoS attack because many administrators forget to disable ICMP unreachables and inadvertently generate just as much traffic back to the source (which is typically a spoofed address), creating a second DoS attack. By preventing the generation of ICMP unreachable messages, your router silently drops the packets.

--> A DNS-based Blackhole List (DNSBL) or Real-time Blackhole List (RBL) is a list of IP addresses published through the Internet Domain Name System (DNS) either as a zone file that can be used by DNS server software, or as a live DNS zone that can be queried in real-time.

--> DNSBLs are most often used to publish the addresses of computers or networks linked to spamming; most mail server software can be configured to reject or flag messages which have been sent from a site listed on one or more such lists. The term "Blackhole List" is sometimes interchanged with the term "blacklist" and "blocklist".