Ojo aqui les envio algo sencillo , como guia para que tengan al momento de repasar cosas sencillas.. Blog, no voy a saturar esto , por lo menos una vez a la semana comparto alguna guia o documento..
CCNA Study Guide
Network Basics (INTRO)
Network Models
|
| OSI |
|
| TCP/IP |
| PDU7 | Application | Closest to user |
|
|
| PDU6 | Presentation | Formatting |
| Application |
| PDU5 | Session | Application communication |
|
|
| Session | Transport | End-to-end establishment |
| Transport |
| Packet | Network | Data delivery |
| Internet |
| Frame | Data Link LLC MAC | Access to media Framing Error detection |
| Network Access |
| Bit | Physical | Binary Transmission |
|
|
Benefits of OSI Model:
- Reduces complexity
- Standardizes interfaces
- Facilitates modular engineering
- Ensures interoperability
- Accelerates evolution
- Simplifies teaching and learning
LLC sub-layer functions: transmission to the upper layers. Frames have a “type” field that passes the type of protocol (data) its data carries. E.g. IEEE 802.2
MAC sub layer functions: define the physical media access; in particular: addressing. E.g. IEEE 802.3
Basic TCP/IP protocols description:
- IP:
- Operates at L3
- Connectionless
- Packets transmitted independently
- Best effort
- Hierarchical addressing
- No data-recovery
- UDP:
- Operates at L4
- Connectionless
- Limited error checking
- No overhead to upper layers
- No data recovery
- TCP:
- Operates in L4
- Connection-oriented
- Error Checking
- Sequencing of packets
- Reliable
Transport Layer Functions:
- Session Multiplexing
- Segmentation
- Flow Control (TCP)
- Connection Oriented (TCP)
- Reliability (TCP)
Port Numbers of some protocols (Application Layer):
| FTP | Telnet | HTTP | SMTP | DNS | TFTP | SNMP |
| 20, 21 | 23 | 80 | 25 | 53 | 69 | 161 |
LAN
Functions of a LAN:
- Data and Applications
- Resources
- Communication path to other networks
MAC Address of an Ethernet Frame:
· Total length: 48 bits or 6 bytes
· OUI Part: Manufacturer assigned
· Vendor Assigned: random number unique to the device.
Ethernet Frame
| 8B | 6B | 6B | 2B | 48B-1500B | 4B |
| Preamble | Destination MAC Addr | Source MAC Addr | Type | Data | FCS |
| L1 | L2 | L2 | L2 |
| L2 |
Ethernet Media Requirements
| Standard | 10BaseT | 100BaseTx | 100BaseFx | 1000BaseT |
| Speed | 10 Mbps | 100 M | 100 M | 1 G |
| Max Length | 100 m | 100 m | 400 m | 100 m |
| Connector | RJ45 | RJ45 | MIC ST | RJ45 |
Types of Cable (Ethernet)
| Straight-Through | Cross Over |
| 1 –1 2 –2 3 – 3 6 – 6 | 1 –3 2 –6 3 – 1 6 – 2 |
Collisions happen when you have hubs working in half-duplex. When a switch works in Full-Duplex, the loop back is disabled in the interface, so CSMA/CD is inactive. There aren’t collisions in switches.
Connectivity Hierarchy:
- Access Layer: connections to users. i.e. per floor
- Distribution Layer: aggregation of access layer. i.e. per building
- Core Layer: aggregation of distribution layer. i.e. per campus.
Basic IP
Simplified IP Packet
| 8B | 1B | 1B | 4B | 4B |
|
| Header flags | TTL | Protocol | Source Address | Destination Address | Options + Data |
| L3 | L3 | L3 | L3 | L3 |
|
Protocol Field:
- TCP: 6
- UDP: 17
- ICMP: 1
- EIGRP: 88
Subnetting
| Decimal | 128 | 64 | 32 | 16 | 8 | 4 | 2 | 1 |
| Power | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 |
| Mask | 128 | 192 | 224 | 240 | 248 | 252 | 254 | 255 |
| Binary | 10000000 | 11000000 | 11100000 | 11110000 | 11111000 | 11111100 | 11111110 | 11111111 |
| Increments | 128 | 64 | 32 | 16 | 8 | 4 |
|
|
Classes of IP Addressing
|
| First Octet | Range (First Octet) | Default Mask |
| Class A | 0xxxxxxx | 1 – 126 | 255.0.0.0 |
| Class B | 10xxxxxx | 128 – 191 | 255.255.0.0 |
| Class C | 110xxxxx | 192 – 223 | 255.255.255.0 |
| Class D | 1110xxxx | 224 – 239 | Multicast |
| Class E | 1111xxxx | 240 – 255 | Research |
Private IP Addresses
| Class A | 10.0.0.0 to 10.255.255.255 |
| Class B | 172.16.0.0 to 172.31.255.255 |
| Class C | 192.168.0.0 to 192.168.255.255 |
Number of Subnets = 2N ; Where N: number of bits borrowed
Number of Hosts = 2N-2; Where N: number of host bits still available
Basic TCP
Three-way-handshake is used for exchanging sequence numbers.
- Host A sends: CTL=SYN, SEQ=100
- Host B responds: CTL=SYN ACK, SEQ=200, ACK=101
- Host B sends: CTL=ACK, SEQ=101, ACK=201
Flow Control is administered through Sliding Window Protocol
The receiver acknowledges the last received packet, and reduces the size of the window according to the number of packets received last.
Switching
Basic Switching
Functions of a Switch
A switch is a Layer 2 device
The functions of a switch are:
- Learn the MAC Address based on the source
- Forwarding frames based on destination address
- Avoid the creation of loops
Switching modes:
- Store and Forward: switch has buffers, and forwards, once the frame is received
- Cut-through: forward the frame as soon as possible
- Fragment free: forward after receiving the first 64 bytes
Switches and bridges increase available bandwidth of a network by creating several collision domains.
MAC Address learning (ARP)
Steps for frame forwarding/switching (PC A, sends unicast frame to PC B)
1. Switch compares destination MAC address with its MAC Address Table.
1.1. If found: send frame to appropriate port
1.2. If not found: flood frame thru all ports
2. Add source MAC address to the MAC Address table.
When a PC wants to send an IP packet to a destination PC, it looks for its MAC address on its ARP or MAC table. If is not present, it sends an ARP request. If it is, it is able to construct the IP packet. ARP is a Layer 3 protocol.
An ARP request is an Ethernet frame with:
|
| L2 DA: | FFFF-FFFF-FFFF |
|
|
| L2 SA: | |
|
|
| L3 DA: | |
|
|
| L3 SA: | |
|
Advanced Switching
Spanning-Tree Protocol
Problems that may arise by Redundant Topologies:
- Broadcast Storms: flood of broadcast frames endlessly
- Multiple Frame Transmission: multiple copies of a frame arrive at a host
- MAC Address Table instability: multiple copies of a frame arrive on different ports
STP provides a loop-free redundant network topology by creating a logical non-redundant network. STP is enabled by default in Catalyst switches.
Every bridge/switch has a bridge ID composed of the concatenation of the Bridge Priority and the Bridge BIA MAC Address. This is broadcasted in the form of BPDUs every 2 seconds. The smallest Br-ID is the root bridge.
Steps:
- Select one root bridge. The bridge with the smallest Bridge-ID. Everyone starts thinking that he is the Root bridge until he receives a BPDU with a smaller Br-ID. The root bridge has all ports in forwarding mode. They are called designated ports.
- Every non-root bridge selects a root port. This is the port that has the lowest-cost path to reach the root bridge. The cost is calculated using the bandwidth.
- Select the designated port on each segment. On each segment, there will be a designated port (in forward mode) that belongs to the bridge with the lowest-cost path to the root (again calculated with bandwidth).
- The rest of the ports are in blocking state.
Every bridge puts its ports in 4 states:
- Blocking – loss of BPDUs for 20 secs
- Listening – forward delay 15 secs
- Learning – forward delay 15 secs
- Forwarding
[Total delay (50 seconds)]
Setting a port that’s connected to clients as FastPort Mode, causes the port to go directly to forwarding. Do this, only for access mode ports to PCs.
Path costs:
| Link Speed | Old Cost | Revised Cost |
| 10 Gbps | 1 | 2 |
| 1 Gbps | 1 | 4 |
| 100 Mbps | 10 | 19 |
| 10 Mbps | 100 | 100 |
VLAN definitions
VLAN: separate broadcasts domain.
Trunk mode: put an interface so that it forwards traffic from all VLANs (All traffic)
Benefits of VLANs:
- Segmentation (Broadcast Domains)
- Flexibility (single switch, multiple broadcast domains)
- Security
Ways a port can become a member of a VLAN:
- Static: an administrator assigns a port to a VLAN
- Dynamic: Using an external VLAN Management Policy Server (VMPS)
Trunk Standards
| 802.1Q | ISL |
| Adds only a header with VLAN ID Supports a STP instance per VLAN (PVST+) VLAN 1 has no header (native VLAN). | Fully encapsulates frames (with trailer) Supports STP per VLAN Cisco proprietary. |
VTP (VLAN Trunking Protocol)
L2 messaging protocol that maintains VLAN configuration consistency by managing “moves adds and changes”.
- Advertises VLAN configuration information to other switches every 5 minutes or with a change.
- Maintains VLAN config consistency
- Sends advertisements thru trunk ports only
- Can configure pruning to save bandwidth.
- There is a Revision Number per domain. When there is a change/update, the revision number is incremented by one (i.e. rev_number++).
VTP Pruning is used to save bandwidth by advertising VLANs only in those switches that are pertinent.
VTP Modes
| Server | Client | Transparent |
| Default mode Changes here, replicate across the domain (not by default because you have to set a domain name first)
| Cannot make changes to the configuration. Only receives info. | Like disabling VTP Will not receive configurations. Changes affect the local switch only. It forwards VTP adverts from other switches Always have a revision number of 0. |
CDP and VTP advertisement are sent via the native VLAN
To add or delete VLANs, the switch must be server or transparent. You can’t add VLANs in client mode!
If you connect a Switch (any mode) with a revision number greater than the current one in a network, all switches VLAN DB’s will be updated!. Even if it is a client switch!. Highest revision number always wins.
Routing
Basic Routing
To route a packet, the following is necessary:
- Destination Address
- Identify sources of routing info
- Identify routes
- Select best route
- Maintain and verify routing info
Admin Distance: is an integer from 0 to 255. It’s used to set priorities to sources of routing info.
Metric: is used by the dynamic routing protocol to determine the best route to a destination.
| Routing Info Source | Default Admin Distance | Metrics used |
| Directly Connected | 0 |
|
| Static Route | 1 |
|
| EIGRP | 90 | Bandwidth, Delay, Load, Reliability, MTU |
| IGRP | 100 | Bandwidth, Delay, Load, Reliability, MTU |
| OSPF | 110 | Bandwidth |
| RIPv1; RIPv2 | 120 | Hop Count |
| Unknown | 255 |
|
Dynamic Routing Protocols
Types of Dynamic Routing Protocols (per IP addressing mode used)
| Classless | Classfull |
| Include subnet mask with advertisement Support VLSM Can manually control summarization | Don’t include the subnet mask with advert. Summary routes are exchanged
|
| E.G.: RIPv2, EIGRP, OSPF | E.G.: RIPv1, IGRP |
Types of Dynamic Routing Protocols (per routing table exchange mode)
| Distance Vector | Link State | Hybrid |
| Advertises “How Far”, and “in which direction” to all neighbors. | Advertises a Topology Map, and the routing table is computed per router based on that. | Mix of both. Mainly using Distance Vector features |
| Algorithm: Bellman-Ford | Algorithm: Djkstra | Algorithm: DUAL |
| E.G.: RIPv1, RIPv2, IGRP | E.G.: OSPF | E.G.: EIGRP |
Distance Vector
Issues and Solutions with Distance Vector protocols
| Issues | Solution | Description |
| Multiple Routes to same subnet with equal metric | Putting multiple routes to the same net on the table |
|
| Routing Loops over a single link | Split horizon Split horizon with poison reverse | SH: Do not send an update out of a receiving interface. SH/PR: If a route fails, advertise out of all interfaces. |
| Routing loops through alternative paths | Route Poisoning | Advertise with infinite distance when a route fails. Overrides Split Horizon. |
| Counting to Infinity | Hold-Down Timers Triggered Updates | Wait a certain time before believing something else about the failed route. |
Hold down timer works as follow:
- When a router receives an update to indicate inaccessibility of a network, the router marks it as “possibly down” and starts the hold-down timer
- If an update is received with a better metric before the time out, the route becomes “accessible” and stops the hold-down timer.
- If an update is received with a poorer or same metric before the time out, it is ignored.
- While it is “possibly down”, the router still attempts to route packets.
- If timer times-out, the route is removed from the table.
Examples of Distance Vector: RIPv1, RIPv2, IGRP
RIP characteristics
- Updates every 30 seconds
- RIPv1 is classful, no VLSM. RIPv2 is classless, supports VLSM
- Max 15 hops
IGRP characteristics
- Cisco proprietary
- Metric: Bandwidth, Delay, Load, Reliability, MTU
Link State
Link State protocols collect routing information from all other routers (not just neighbors) After all information is received, a topology map is generated, and then routing info is extracted from there (calculated). Typically they pertain to an Autonomous System (AS), but splits it in different Areas.
Benefits:
- Faster convergence
- Changes communicated immediately
- Segment the network.
- No routing loops can occur.
Link state protocols use:
- Link State Advertisements (LSA) – this is what is exchanged between routers.
- Topology database
- SPF algorithm (djkstra for OSPF)
- SPF tree
- Routing table.
Examples of Link State: OSPF.
Link State: OSPF
Characteristics:
- IEEE Standard – Link State
- Metric: Bandwidth (cost is computed as 108/BW = 100Mbps/BW)
- Cost of 64kbps: 1562
- Cost of T1: 64
- Ability o create areas within an AS
- Types of Packets:
- HELLO
- Database Descriptor (DBD)
- Link State Request (LSR)
- Link State Update (LSU)
- Link State Ack (LSACK)
- Assigns a Designated Router (DR) and a Backup Designated Router (BDR)
- Only if the routers is on a “Broadcast” or “Non-Broadcast” Network.
- A Broadcast network is Ethernet
- A Non-Broadcast network is Frame Relay or ISDN with the broadcast option on the mapping command.
- DR are elected based on three tests: (if 1 not present, go to 2; if not 2, go to 3)
1. The router ID command
2. Loopback interface has an IP assigned
3. The highest IP address
- If the network is “point-to-point” or “point-to-multipoint”, there is no DR.
- Examples of these are “point-to-point” and “multipoint” frame relay.
- Uses multicasts to send packets
- 224.0.0.5: for all SPF routers
- 224.0.0.6: for Designated Router and Backup DR only
OSPF States
| INIT | Initial State right after boot. |
| 2-WAY | HELLO gets the router here |
| EX-START | DBD gets the router here |
| EXCHANGE | DBD gets the router here |
| LOADING | LSR, LSU, LSACK get the router here |
| FULL | Once it is Loaded, it becomes FULL |
OSPF routers have three tables:
- Neighbors Table
- Topology Map
- Routing Table
Hybrid (EIGRP)
EIGRP characteristics
- Cisco proprietary
- Metric: Bandwidth, Delay, Load, Reliability, MTU
- Sort of Distance Vector
- Algorithm used: DUAL
- Capable of routing multiple layer 3 protocols (e.g. Appletalk, IPX, etc)
Security
ACLs
ACLs are meant to (1) Manage IP traffic as network traffic grows, and (2) filter packets as they pass thru a router.
ACL uses:
- Permit or deny traffic
- Permit or deny vty (telnet) access to/from a router
- Custom Queuing
- Dial-on-Demand Routing (i.e. ISDN)
- Routing protocol filtering.
Types of ACL
| Standard | Extended |
| Checks source address only Generally permits or denies entire protocol Ranges: 1-99 and 1300-1999 | Checks source and destination Permits or denies specific protocols Can also compare TOS field Ranges: 100-199 and 2000-2699 |
You can set an ACL Inbound (before the routing decision) or Outbound (after the routing decision).
General recommendation: Place Standard ACLs closest to the destination, and place Extended ACLs closest to the source.
NAT & PAT
NAT is used for “hiding” local/Internal/Inside IP addresses.
Types of NAT:
| Static NAT | Dynamic NAT | Overloading |
| Maps an unregistered IP to a registered IP (one-to-one) | Maps an unregistered IP to a registered IP (one-to-several) | Maps multiple unregistered IPs to a registered IP (many-to-one) |
Benefits of NAT:
- [Static] Eliminates the need to readdress all internal servers
- [Dynamic] Conserves address
- [Overloading] Protects the network
Remote Access and WANs
Basic Concepts
WAN Connection Types
- Leased Lines: dedicated point-to-point line. Very costly.
- Circuit Switched: dedicated point-to-point for the duration of the call (e.g. ISDN)
- Packet Switched: shared connection (e.g. Frame Relay, ATM)
WAN Encapsulation Protocols
| For Leased Lines | For Circuit Switched | For Packet Switched |
| HDLC PPP SLIP | HDLC PPP SLIP ISDN | X.25 Frame Relay ATM |
HDLC
It is the default serial port encapsulation on a Cisco router. However, Cisco Routers run a proprietary version of HDLC, not compatible with the ISO standard. HDLC specifies a data encapsulation method on synchronous serial links using frame characters and cheksums. Cisco’s version uses a type filed to indicate the protocol carried.
PPP
You can run PPP on the following point-to-point physical interfaces:
- Asynchronous serial
- Synchronous serial
- High-Speed Serial Interface (HSSI)
- ISDN
PPP Main Components:
| NCP | LCP |
| Used to encapsulate and negotiate options for several protocols | Negotiate and set up control options on the WAN Link |
PPP (LCP) configuration options:
- Authentication: E.g. CHAP and PAP
- Compression: increase the effective throughput. E.g Stacker and Predictor
- Error Detection: E.g. Quality and Magic Number
- Multi-Link PPP (MLP): load balancing. E.g. MLP
- Call Back
PPP Session establishment has the following steps:
- Link establishment phase
- Authentication phase (optional)
- Network layer protocol phase
Authentication Protocols
| PAP | CHAP |
| Two way handshake. Done at the beginning only. Password sent in clear text. Peer in control of attempts. Password can be different in both peers | Thee way handshake. Periodically verifies identity. Hashed (MD5) challenge used Local router in control of attempts. Password must be the same in both peers |
There’s a third supported Authentication scheme: MSCHAP (MSFT Proprietary)
Frame Relay
It operates in L1 and L2 of OSI. It’s a connection oriented data-link technology (virtual circuits). Requires clocking provided by a DCE, to a DTE.
DLCI: The local physical address of a connection. Size: 10 bits.
Access Link: the link between the router and the DTE or DCE.
LMI: is the signaling protocol used to establish the communication. Used between the router and the local Frame Relay switch (i.e. Access Link).
LMI Functions:
- Perform a keep alive between DTE and DCE. Indicates a link up.
- Signal whether a PVC is active or inactive.
LMI Protocols Standards supported by Cisco Routers:
- cisco – proprietary
- ansi – ANSI standard T1.617
- q933a – ITU-T Q.933 Annex A
LMI Information passed to the router:
- DLCI number
- DLCI status
- Active
- Inactive
- Deleted
Inverse-ARP: mapping of local layer-2 address (DLCI) and the remote layer 3 address (IP).
Encapsulation: defines the headers used by the DTE to communicate information to the DTE on the other end of the Virtual Circuit. It’s different than LMI!
Encapsulation for Layer-3 packets is defined by the LAPF (Link access procedure frame bearer services).
Types of Encapsulation:
- cisco
- ietf
CIR: is the committed information rate, stated on the contract.
Inverse ARP: is the method used to map IP addresses to DLCIs.
Types of topologies:
- Star topology (Hub-and-Spoke)
- Full Mesh
- Partial Mesh (hybrid)
Types of FR configuration
- Physical Interface: all configuration parameters (DLCI, Clock, etc) are given by the FR switch to the router through the LMI. A single interface with a single IP. It is ultimately point-to-point
- Point-to-Point: 99% of implementations out there. A physical interface is divided in sub-interfaces (with its respective IP address). IPs don’t typically are in the same subnet. You have to configure the DLCI with the ‘frame-relay interface-dlci 101’.
- Multipoint: Very rare. A single subnet; all sub-interfaces and routers are in the same segment. Need to map the IP to a DLCI (override inverse-ARP)
Flow Control (Congestion): Frame Relay uses the BECN and FECN bits in the Frame Relay frame to indicate congestion. The FR Switch sens frames with the BECN bit set if there is congestion. The router sees that and slows down.
ISDN
ISDN is used for Dial-on-Demand link connections. Goes over the PSTN network!.
Types/Forms of ISDN
| BRI (2B+D) | PRI (23B+D || 30B+D) |
| Basic Rate Interace. Has only two DS0 as bearer channel, and one signaling channel. Used for single lines of voice, video and data. | Primary Rate Interface. Has 23 bearer channels in US (Total of DS1/T1), or 30 bearer channels in EU (total of an E1). Used for |
| B = 64 Kbps D = 16 Kbps | B = 64 Kbps D = 64 Kbps |
BRI Reference Points:
- NT-1: converts two wire (from PSTN) to four wire (Inside router)
- NT-2: controls the traffic. Decides where to send traffic
- T/A: Converts digital to analog or digital to Ethernet.
- S/T and U: types of interface. U includes NT1, S/T needs an external NT-1.
Terminal End Points:
- TE1: ISDN connector goes directly to this type of device. i.e. router with a BRI-U nic.
- TE2: Needs an external box (CSU/DSU) to make the conversion. i.e. a regular PC
DDR: Dial on demand routing. It is a technique where a router can automatically initiate and close a circuit-switched session as transmitting stations demand. The router spoofs keep alives so that end users treat the session as active. DDR permits routing over ISDN.
D Channel Layers:
| Q931 | Analog to Dialing. It is end-to-end (using SS7) and is used for (1) call setup, and (2) call tear down. |
| Q921 | Analog to Dialtone. Operates between the Router and the ISDN switch (last mile). Has keep-alives every 10 seconds. |
|
| Bits. Layer 1. |
Note: The D Channel layers do not match the bottom layers of the OSI model.
Key concepts/steps for legacy DDR:
- Route packets out interface to be dialed. Router must chose to dial when traffic is directed out the “dial interface”.
- Determine subset of the packets that trigger the dialing process. How to trigger the dial (with an ACL).
- Dial (signal). Make the connection.
- Determine when the connection is terminated. End the connection when there is a time-out on the clocks.
Four possible situations:
| Router w/ ISDN BRI-U nic | Router w/ ISDN BRI-S/T nic | Router w/ Serial int, and providing TE2 | Router w/ Serial int only |
| Directly to cloud | Connected to an external NT1 | Connect to a terminal adapter (TA) and then an NT1. | Use external ISDN TA (NT2) and then connect to the NT1. |
SPID: It is the phone number of the router.
Others
CDP
Cisco Discovery Protocol, CDP, is used for transmitting information to directly connected neighboring Cisco devices.
Summary information:
- Hostname
- Address list
- Port identifier or interface description
- Capabilities list
- Platform
NBMA
Some protocols are NBMA (do not pass broadcasts originated in the router; i.e. Routing Updates from Routing Protocols). Some of these protocols are: ISDN, Frame Relay.
You can overcome this by:
- On ISDN: Using the broadcast option on the dialer-map command
- On FR: Using the broadcast option on the frame-relay map command for Multipoint. Point-to-Point is not NBMA by default. So it passes broadcasts.
Configurations
Cisco IO Boot sequence:
- POST
- Load and run bootstrap code
- Find and load IOS image
- Find, load and run configuration
Router and Switches memories:
- FLASH: Stores IOS compressed image
- NVRAM: Stores startup-config
- RAM: Stores running-config
The configuration register (e.g. 0x2102) includes information where to locate the Cisco IOS image in FLASH.
Configure Catalyst Switch
Default Values:
- IP Address: 0.0.0.0
- CDP: Enabled
- 100baseT ports: autonegotiate duplex mode
- Spanning-Tree: Enabled
- Console Password: none
| Task | Command Steps | Comments |
| Basic | ||
| Gain Privileged Mode access | S>enable |
|
| Exit to user mode access | S#disable |
|
| Assign Management IP to VLAN 1 | S#Config t S(config)# interface VLAN1 S(config-if)# ip address 10.10.10.10 255.255.255.0 S(config-if)# no shutdown | In interface config mode |
| Assign default gateway to switch | S#Config t S(config)# ip default-gateway 10.10.10.1 | In Global config |
| Configure console password | S#Config t S(config)# line console 0 S(config-line)# login S(config-line)# password MyConPassword |
|
| Configure telnet password | S#Config t S(config)# line vty 0 4 S(config-line)# login S(config-line)# password MyTelPassword |
|
| Configure enable secret | S#Config t S(config)# enable secret MySecret |
|
| Configure Port Security on interface | S#Config t S(config)# interface range FA0/0 - 12 S(config-if)# Switchport mode access S(config-if)# Switchport security S(config-if)# Switchport port-security maximum 1 S(config-if)# Switchport port-security mac-address aaa-aaa-aaa S(config-if)# Switchport port-security violation shutdown | (1) Use the interface config mode for a range (2) Put interface as access (no trunk) (3) Activate security (4) Indicate a max of 1 MAC for that interface (5) Specify static MAC address (6) What action to take on violation |
| Configure duplex mode to full duplex | S#Config t S(config)# interface range FA0/0 - 12 S(config-if)# duplex full | Options are: auto, full, half |
| Clean a device | S#Config t S# erase startup-config S# reload | Have to reply NO when asked to save configuration |
|
|
|
|
| VLAN | ||
| Create a VLAN (old) | S# vlan database S(vlan)# vlan 100 name MyVlan100 S(vlan# exit | (1) Enter VLAN Database mode (2) Name is optional (3) have to exit to commit changes to DB |
| Create VLAN (new) | S#Config t S(config)#vlan 100 S(config-vlan)# name MyVlan100
| (1) Enter Global Config (2) Create VLAN (3) Name that VLAN |
| Delete VLAN | S#Config t S(config)# interface range FA0/0 - 12 S(config-inter)# no VLAN 100 | Simply unassign interface to it. |
| Assign interface to VLAN | S#Config t S(config)# interface range FA0/0 - 12 S(config-if)#switchport access vlan 100 |
|
| Configure port as access (for VLAN) | S#Config t S(config)# interface range FA0/0 - 12 S(config-if)#switchport mode access |
|
| Configure port as trunk (for VLAN) on 802.1Q encapsul. | S#Config t S(config)# interface FA0/12 S(config-if)#switchport mode trunk S(config-if)#switchport trunk encapsulation dot1q
| (1) Enter global config (2) Enter interface config (3) Put interface as trunk. Can also be “dynamic auto”, “dynamic desirable” (4) Specify encapsulation. Can also be ISL or negotiate |
| Configure VTP w/Pruning | S#Config t S(config)# vtp mode server S(config)# vtp domain MyDomain S(config)# vtp password MyPassword S(config)# vtp pruning | (1) Enter global config (2) VTP mode: server, transparent, client (3) Have to have domain (4) Password is optional (5) pruning mode is optional |
| Reset the VTP revision number | S#Config t S(config)# vtp mode transparent S(config)# vtp mode server
| Simply change mode to transparent, and then set it back to client or server |
|
|
|
|
| Remote Access (Telnet) | ||
| Suspend a session | S# | Go back to originating device until hitting enter twice, or inputing the resume command |
| Resume a particular session | S#resume 3 | After looking at the existing sessions, you can resume to a particular one by passing the session id to the command |
| Close a session to me | S#clear line 11 | This kills a session by other user to me. Must get the line number from the “show users” command. |
|
|
|
|
Debug Catalyst Switch
| Task | Command Steps | Comments |
| Basic | ||
| Display IOS version | S#show version | Running version, RAM memory avail., up time |
| Display statistics for interfaces | S#show interfaces | up/down, MAC address, Half/Full – Duplex mode |
| Display port security | S#show port-security FA0/12 | Interface parameter not necessary |
| Display STP info | S#show spanning-tree | Show root bridge, and this bridge status, and interface states |
|
|
|
|
| VLAN | ||
| Display VLAN information | S#show vlan brief |
|
| Display interface trunk configuration | S#show interface FA0/12 trunk |
|
| Show VTP status | S#show vtp status | Shows revision number |
| Show if pruning is set | S#show interface trunk |
|
|
|
|
|
| CDP | ||
| Display neighbors | S#show cdp neighbors S#show cdp neighbors detail | Details show hardware information. It is the same as S#show cdp entry * |
|
|
|
|
| Remote Access (Telnet) | ||
| Display sessions | S#show sessions | Telnet sessions originated from this device to other devices |
| Display connected users | S#show users | Telnet sessions connected to me (this device) |
|
|
|
|
Configure Cisco Router
Default Values:
- IP Address: none set
- CDP: Enabled
- Console Password: none
- WAN Encapsulation: HDLC
| Task | Command Steps | Comments |
| Basic | ||
| Gain Privileged Mode access | R>enable |
|
| Exit to user mode access | R#disable |
|
| Assign IP to Interface | R#Config t R(config)# interface FA0/0 R(config-if)# ip address 10.10.10.1 255.255.255.0 R(config-if)# no shutdown | In interface config mode |
| Set Bandwidth on interface | R#Config t R(config)# interface S0/0 R(config-if)# bandwidth 64 | Used for dynamic routing protocols only. |
| Set clock rate for serial interfaces | R#Config t R(config)# interface S0/0 R(config-if)# clock rate 2000000 | Applies on DCE only |
| Configure console password | R#Config t R(config)# line console 0 R(config-line)# login R(config-line)# password MyConPassword |
|
| Configure telnet password | R#Config t R(config)# line vty 0 4 R(config-line)# login R(config-line)# password MyTelPassword |
|
| Configure enable secret | R#Config t R(config)# enable secret MySecret |
|
| Add a description to interface | R#Config t R(config)# interface FA0/0 R(config-if)# description I simply describe |
|
| Add MOTD Banner | R#Config t R(config)# banner motd # hello # | # is the delimiter character |
| Set console timeout | R#Config t R(config)# line console 0 R(config-line)# exec-timeout 20 30 |
|
| Redisplay interrupted console | R#Config t R(config)# line console 0 R(config-line)# logging synchronous |
|
|
|
|
|
| Cisco IOS loading | ||
| Change configuration registry | R#Config t R(config)# config-register 0x2104 | Use: 0x2100 for ROMMON (use boot command) 0x2101 for ROM 0x2102 to 0x210F for NVRAM Default is 0x2102 |
|
|
|
|
| Static Routing | ||
| Assign default route | R#Config t R(config)# ip route 0.0.0.0 0.0.0.0 10.10.2.1 |
|
| Add a static route (IP) | R#Config t R(config)# ip route 10.12.0.0 255.255.0.0 10.10.2.10 |
|
| Add a static route (interface) | R#Config t R(config)# ip route 10.13.0.0 255.255.0.0 S0/1 |
|
|
|
|
|
| VLAN Trunk | ||
| Configure Router-on-stick (802.1Q) | R#Config t R(config)# interface FA0/0.1 R(config-if)# ip address 10.1.1.1 255.255.255.0 R(config-if)# encapsulation dot1q 1 R(config)# interface FA0/0.2 R(config-if)# ip address 10.1.2.1 255.255.255.0 R(config-if)# encapsulation dot1q 2 | (1) Enter global config (2) Create Subinterface (3) Add IP address (4) specify encapsulation and VLAN ID (can use ISL) (5) repeat for other subinterface
|
|
|
|
|
| RIP | ||
| Enable RIP | R#Config t R(config)# router rip R(config)# network 10.0.0.0 | (1) Enter global config (2) Enable RIP (3) Specify which networks and interfaces to advertise. In this case, all interfaces with IPs in the 10.0.0.0 class A network will be advertised. |
|
|
|
|
| IGRP | ||
| Enable IGRP | R#Config t R(config)# router igrp 100 R(config)# network 10.0.0.0 | (1) Enter global config (2) Enable IGRP for an AS (3) Specify which networks and interfaces to advertise. In this case, all interfaces with IPs in the 10.0.0.0 class A network will be advertised. |
|
|
|
|
| EIGRP | ||
| Enable EIGRP | R#Config t R(config)# router eigrp 100 R(config)# network 10.0.0.0 | (1) Enter global config (2) Enable EIGRP for an AS (3) Specify which networks and interfaces to advertise. In this case, all interfaces with IPs in the 10.0.0.0 class A network will be advertised. Note: you can also specify wildcard mask for the network command. |
|
|
|
|
| OSPF | ||
| Enable OSPF | R#Config t R(config)# router ospf 100 R(config)# network 10.1.1.0 0.0.0.255 area 0 R(config)# network 10.1.2.0 0.0.0.255 area 0 | (1) Enter global config (2) Enable OSPF , and specify process ID (no need to be the same) (3 - 4) Specify which networks and interfaces to advertise, using wildcard mask notation (0=Match, 1=ignore). Also, to which area they belong. |
|
|
|
|
| Security | ||
| Configure Standard ACL | R#Config t R(config)# access-list 10 permit 172.16.0.0 0.0.255.255 R(config)# access-list 10 deny 0.0.0.0 255.255.255.255 R(config)# interface FA0/0 R(config-if)# ip access-group 10 out | (1) Enter global config (2) Create standard ACL number 10 (3) Create standard implicit ACL (4) Go to the interface config mode (5) Attach ACL to that interface as outbound. |
| Configure Extended ACL | R#Config t R(config)# access-list 101 permit tcp 172.16.0.0 0.0.255.255 any eq 80 R(config)# access-list 101 permit 172.16.0.0 0.0.255.255 10.10.10.10 255.255.255.255 eq 23 R(config)# interface FA0/0 R(config-if)# ip access-group 101 out | (1) Enter global config (2) Create extended ACL number 101 to allow HTTP out (3) Create extended ACL that allows Telnet to a host (4) Go to the interface config mode (5) Attach ACL to that interface as outbound. |
| Configure Static NAT to a server | R#Config t R(config)#ip nat inside source static 172.16.22.10 200.44.32.1 R(config)# interface FA0/0 R(config-if)# ip nat inside R(config)# interface S0/0 R(config-if)# ip nat outside |
|
| Configure Dynamic NAT on a pool | R#Config t R(config)#ip nat pool MyPool 200.44.32.1 200.44.32.10 R(config)# access-list 10 permit 172.16.0.0 0.0.255.255 R(config)# ip nat inside source list 10 pool MyPool R(config)# interface FA0/0 R(config-if)# ip nat inside R(config)# interface S0/0 R(config-if)# ip nat outside |
|
| Configure Overloading NAT for a single IP | R#Config t R(config)# access-list 10 permit 172.16.0.0 0.0.255.255 R(config)# ip nat inside source list 10 interface S0/0 overload R(config)# interface FA0/0 R(config-if)# ip nat inside R(config)# interface S0/0 R(config-if)# ip nat outside | This uses the IP on S0/0 (outside) to hide the internal IPs |
|
|
|
|
| Frame Relay | ||
| Configure Physical Interface Frame Relay | R#Config t R(config)# interface S0/0 R(config-if)# ip address 10.10.10.1 255.255.255.0 R(config-if)#encapsulation frame-relay
| (1) Enter global config (2) Go to interface Serial (3) Set IP (4) Set encapsulation |
| Configure Point-to-Point Frame Relay | R#Config t R(config)# encapsulation frame-relay R(config)# interface S0/0.1 point-to-point R(config-if)# ip address 10.10.10.1 255.255.255.0 R(config-if)# frame-relay interface-dlci 100 R(config-if)# interface S0/0.2 point-to-point R(config-if)# ip address 10.10.11.1 255.255.255.0 R(config-if)# frame-relay interface-dlci 101
| (1) Enter global config (2) Set Encapsulation globally (3) Go to sub-interface Serial (4) Set IP (5) Set the DLCI for the sub-interface |
| Configure Multipoint | R#Config t R(config)# encapsulation frame-relay R(config)# interface S0/0.1 multipoint R(config-if)# ip address 10.10.10.1 255.255.255.0 R(config-if)# frame-relay map ip 10.10.10.2 101 | (1) Enter global config (2) Set Encapsulation globally (3) Go to sub-interface Serial (4) set the mapping of IPs to local DLCIs.
|
|
|
|
|
| ISDN | ||
| Configure ISDN (interesting traffic: all) | R#Config t R(config)#dialer-list 1 protocol ip permit R(config)# username OtherRouter password MyPasswd R(config)# interface bri 0/0 R(config-if)# isdn switch-type basic-5ess R(config-if)#ip address 1.1.1.1 255.255.255.0 R(config-if)#dialer-map ip 1.1.1.2 name OtherRouter 5551234 R(config-if)#dialer-group 1 R(config-if)# encapsulation ppp R(config-if)# ppp authentication chap | (1) Enter global config (2) Set dialer-list (rules that trigger the dial) (3) Set username and password if you want to authenticate with CHAP (4) Go to the BRI interface (5) set the ISDN switch type (not required) (6) set an ip for the BRI (7) set the phone number where to dial, and IP (8) attaches the dialer-list to this BRI interface (the rules for dialing) (9) set PPP.
|
| Configure ISDN (interesting traffic: by ACL) | R#Config t R(config)# dialer-list 1 protocol ip list 101 R(config)# username OtherRouter password MyPasswd R(config)# R(config)# interface bri 0/0 R(config-if)# isdn switch-type basic-5ess R(config-if)# ip address 1.1.1.1 255.255.255.0 R(config-if)# dialer-map ip 1.1.1.2 name OtherRouter 5551234 R(config-if)# dialer-group 1 R(config-if)# encapsulation ppp R(config-if)# ppp authentication chap | Same as above, but with specification of ACL on the sialer-list |
|
|
|
|
Debug Cisco Router
| Task | Command Steps | Comments |
| Basic | ||
| Display IOS version | R#show version | Running version, RAM memory avail., up time |
| Display statistics for all interfaces | R#show interfaces | Up/down, MAC address, Half/Full – Duplex mode, MTU, line protocol, Bandwidth, encapsulation, etc. |
| Display statistics for a particular interface | R#show interfaces S0/1 | Up/down, MAC address, Half/Full – Duplex mode, MTU, line protocol, Bandwidth, encapsulation, etc. |
| Display serial cable type (DCE or DTE) | R#show controller S0/0 |
|
| Display routing table | R#show ip route | D=EIGRP I=IGRP R=RIP O=OSPF C=Directly Connected S=Static Route |
| Disply interfaces information | R#show ip interface brief | Displays IPs on all interfaces, and routing protocol information such |
|
|
|
|
| Routing Protocols | ||
| Verify routing protocols | R#show ip protocols | Displays routing protocols activated (all) |
| Debug RIP | R#debug ip rip R#no debug all | (1) Activate debug in console for RIP (2) Deactivate all debug messages |
| Debug IGRP events | R#debug ip igrp events R#no debug all | (1) Activate debug in console for updates (2) Deactivate all debug messages |
| Debug IGRP transactions | R#debug ip igrp transactions R#no debug all | (1) Activate debug in console for IGRP specific info. (2) Deactivate all debug messages |
| Display EIGRP neighbors | R#show ip eigrp neighbors |
|
| Display EIGRP topology | R#show ip eigrp topology |
|
| Debug EIGRP | R#debug ip eigrp R#no debug all |
|
| Display OSPF neighbors | R#show ip ospf neighbor | Displays the table |
|
|
|
|
| Security | ||
| Clear NAT Table | R# clear ip nat translation * | Clears all dynamic NAT entries. |
| Show NAT table | R# show ip nat translations |
|
|
|
|
|
| Frame Relay | ||
| Display if there is congestion on the Frame Relay WAN | R#show frame-relay pvc | Check the BECN and FECN reception |
|
|
|
|
|
|
|
|
No hay comentarios:
Publicar un comentario