**************** Cisco related Portals & Links *************** credly https://www.credly.com/earner/dashboard netacad https://www.netacad.com/portal/learning skillsforall https://skillsforall.com/dashboard# id.cisco.com https://id.cisco.com/ui/v1.0/profile-ui/home cisco_OpenCase https://certsupport.cisco.com/s/mycases Dashboard | CertMetrics https://cp.certmetrics.com/cisco/en/home/dashboard Pearson VUE Score Report https://wsr.pearsonvue.com/testtaker/authenticate/AuthenticateScoreReport.htm Pearson Dashboard https://wsr.pearsonvue.com/testtaker/registration/Dashboard/CISCOTESTING CCST http://cs.co/6046jZqO0 Netacad Discount Voucher https://www.netacad.com/portal/profile/3399329/discounts Certiport https://www.certiport.com/portal/DesktopDefault.aspx?sessionId=mAVI6MW05WUtE49W/3qoVUh5DYmR5u1zws4f1+ONw09OivwKaebAwUtK6s5lSIOR <<<<<<<<<<<<<< Routing software Operating systems & network operating systems >>>>>>>>>>>>> -------------------1. Linux-based ------------------- ````````` Entirely free ````````` Endian Floppyfw IPFire LEDE libreCMC OpenWrt VyOS Zeroshell ````````` Partly proprietary ````````` AirOS & EdgeOS Alliedware Plus DD-WRT ExtremeXOS FRITZ!Box RouterOS SmoothWall Tomato Vyatta ------------------- 2. FreeBSD-based ------------------- ````````` Entirely free ````````` m0n0wall OPNsense pfSense ````````` Partly proprietary ````````` Junos OS Juniper -------------------3. Proprietary ------------------- Cisco IOS cisco NX-OS cisco Cisco IOS XE cisco Cisco IOS XR cisco ExtremeWare TiMOS/OSWP Alcatel-Lucent VRP Huawei | Feature | TiMOS | OSWP | | -------------------- | ----------------------- | ----------------------- | | Vendor | Nokia (Alcatel-Lucent) | Nokia (Alcatel-Lucent) | | Used On | 7750 SR, 7450 ESS, 7950 | 1830 PSS (DWDM) | | Type | Router OS | Optical firmware bundle | | Routing Protocols | ✔ Yes | ❌ No | | MPLS / VPN | ✔ Yes | ❌ No | | DWDM / Optical | ❌ No | ✔ Yes | | Virtual Lab (EVE-NG) | ✔ Yes | ❌ No | | Equivalent | IOS-XR / JunOS | Optical shelf firmware | <<<<<<<<<<<<<<<<<<<< Cisco CLI or IOS BASIC Details >>>>>>>>>>>>>>>>>>>> ******************** Cisco OS types ******************* Cisco IOS Run on Catalyst switches and routers Cisco IOS XE Cisco IOS XR Cisco NX-OS Run on Nexus Switches *************** Cisco IOS *************** Cisco iOS OS not based on linux (it is monolithic OS with custom kernel) monolithic means = ios installed on Baremetal monlithic disadvantage: 1. if any component disturbed all functions will be disturbed 2. if any hardware gets faulty, whole device might get stuck ios issue resolved in iOS-XE Default User: NULL Default Pass: NULL *************** Cisco IOS XE *************** Cisco IOS monolithic operating system running directly on the hardware like Baremetal (Type 1) Hypeervisor vs IOS XE combination of a Linux kernel and a monolithic application (IOSd) that runs on top of this kernel Baremetal-->>Linux-->>Kernel-->>Sub-Packages Sub-Packages: RP-Base Takes care routing protoocols like BGP, IS-IS, OSPF, EIGRP etc RP-Control Route processor-control Plane RP-Access System Access/management like telnet, ssh RP-IOS takes care of OS, OS installed here ESP Base some special services like QoS, ACL, VPNs etc Supports next-generation platforms Runs as a single daemon within a modern Linux operating system Separates the data plane and control plane Improved services integration Catalyst 9000 family Enterprise Switches isco Catalyst 9500, 9400, 9300, 3850, and 3650 Catalyst 9800 Series Wireless controllers Catalyst 9100 Series Access points ASR 1000 Series Aggregation routers ASR1013, ASR1009-X, ASR1006-X, ASR1006, ASR1004-X, ASR1002-HX, ASR1001-HX, ASR1002-X, and ASR1001-X ASR 900 Series Aggregation routers NCS 4200 Series Aggregation routers Catalyst 8000 Edge Platforms Branch routers 4451 ISR, 4431 ISR, 4351 ISR, 4331 ISR, 4321 ISR, 4221 ISR, and 1000 ISR ISR 4000 Series Branch routers ISR 1000 Series Branch routers IR1100 Rugged Series Industrial routers IR1800 Rugged Series Industrial routers IR8100 Heavy Duty Series Industrial routers IR8300 Rugged Series Industrial routers Catalyst 8000V Edge Virtual Routing CRS 1000v, ISRv CBR Series Converged broadband routers ````````````Software releases```````````` Cisco IOS XE 17 Cisco IOS XE 16 *************** Cisco IOS XR *************** On the other hand, IOS XR is based on QNX since version 5.0 it's also based on LINUX Specialised for SERVICE PROVIDERS Designed for the dynamic network usage requirements of services Flexible programmability for dynamic reconfiguration NCS 5x0, NCS 5x00, 8000, ASR 9000 and XRv 9000 Series Routers ```````````` BGP on IOS ```````````` router bgp 109 no synchronization bgp log-neighbor-changes neighbor 203.0.113.1 remote-as 109 neighbor 203.0.113.1 update-source Loopback0 no auto-summary vs ```````````` BGP on IOS-XR ```````````` router bgp 109 neighbor 203.0.113.1 remote-as 109 update-source Loopback0 *************** Cisco NX-OS *************** Focused on DATA CENTERS Open, modular and programmable for an agile data center infrastructure Optimized for both physical and virtual data center deployments Highly reliable continuous system operation, optimizing uptime ````````````` Differences between IOS and NX-OS ````````````` NX-OS does not support the login command to switch users. NX-OS does not distinguish between standard or extended access lists, all lists are named and "extended" in functionality.[4] NX-OS did not support scp server prior to 5.1(1) release. In NX-OS, there is no "write" command to save the configuration like on IOS (one uses the "copy" command, instead). Instead, command aliases can be created to provide the "write" command. When accessing NX-OS, users authenticate directly to their assigned privilege level. SSH server is enabled while Telnet server is disabled by default in NX-OS. Switches running NX-OS Nexus B22 (HP, Dell, Fujitsu) Nexus 9000 series Nexus 7700 series Nexus 7000 series Nexus 6000 series Nexus 5000 series Nexus 4000 (for IBM BladeCenter) Nexus 2000 series Nexus 3000 Nexus 1000V MDS 9700 FC Directors MDS 9500 FC Directors[3] MDS 9250i FC Switch MDS 9222i FC Switch MDS 9100 FC Switches <<<<<<<<<<<<<<<<<<<<<<<<<<<< Upgrades/Downgrades >>>>>>>>>>>>>>>>>>>>>>>> *********************** UPGRADING IOS On CISCO 2950 ********************* Two Types: 1. Bundle Mode .bin file used 2. Install Mode packages.conf ------------ IOS Troubleshooting ------------ switch#show run switch#show ver switch#show flash switch#dir flash: COPYING or backup current IOS from switch to tftp server(PC) switch#int vlan Switch(config-if)#ip add 10.10.10.1 255.255.255.0 Switch(config-if)#no shut switch#ping 10.10.10.5______pinging pc on which tftp is running.. switch#copy flash tftp....ENTER source filename________fiel existing in the flash of switch(.bin)______ address or name of remote host___10.10.10.5...ENTER destinantin filename........... **************** COPYING new IOS from tftp server(PC) to the switch *************** switch#copy tftp flash....ENTER address or name of remote host___10.10.10.5 source filename________fiel existing on tftp server(.bin)______ destinatio file name....... switch(config)#boot switch(config)#boot system flash:______new file existing in the flash of switch(.bin)______ switch#show boot switch#copy run startup-config destination filename(startup config)? switch#reload switch#show ver switch#show run switch#show boot ********************** copying ios from usb to flash ********************** switch#copy usbflash0:iosfilename.bin flash ******************** compare md5 of installed ios file with file present in the usb or pc to check file corrupted or ok ******************* switch#verify /md5 flash:iosfilename.bin and verify with cisco MD5 or switch#verify /md5 bootflash:iosfilename.pkg ******************** IOS Upgrade on STACKED SWITCHES via USB Flash ******************** First of all configure Stack for switches then; go to MASTER Switch amd Plug USB in switch#install remove inactive remove unnecessary inactive files from switch flash to preserve space switch#copy usbflash0: flash switch#dir flash:*.bin show flash directory switch#verify /md5 flash:iosfilename.bin switch#boot system flash:packages.conf switch#no boot manual auto boot switch#write switch#show boot show next boot file switch#install add file flash:iosfilename.bin activate commit to copy ios file to stack memmbers now verify the versions ---------------- Copying Flash file from one STACK switch to another ----------------- OR ---------------- Upgrade or Downgrade IOS on STACKED Switches ----------------- switch#copy flash: iosfilename.bin flash-1: copy flash file from master switch to slaves switch#copy flash: iosfilename.bin flash-2: Note: delete unnecessary files if more space is required switch(config)#no boot sytem switch(config)#boot sytem switch all iosfilename.bin switch#write switch#reload ---------------- IOS Update on stack Trobleshooting ------------------ switch#show platform switch#show version switch#show switch switch#show boot switch#show boot system switch#show usbflash0 switch#show usbflash1 switch#dir flash: show flash of Master switch switch#dir flash-1: show flash of member/slave switch 1 switch#dir flash-2: show flash of member/slave switch 2 ********************************** Rom monitor version upgrade ********************************** Step 1. Download the Rom monitor "Rommon" version Step 2: Copy new image to flash, USB drive should be 2 - 8 GB Insert USB to Router Router# Show usb0: or usbflash0: You can see the image on the USB Step 2. Copy the Rommon file to your device "Bootflash" from USB Flash Router# copy usb0: bootflash:Image file.bin Step 3. verify the integrity of the file . Router# Verify /md5 bootflash:isr4200_4300_rommon_1612_2r_SPA.pkg Step 4. Example upgrade rom-monitorfilenamebootflash:isr4200_4300_rommon_1612_2r_SPA.pkg all Once finished, save changes, and reload the router by running the following commands: Router# write memory Router# reload - power cycle your device Step 5. After reloading device verify new Rommon version by running the command: Show platform ----------------------------- IOS-XE version Upgrade on Cisco Routers ----------------------------- Step 1. Download the IOS-XE version. Step 2. Copy the IOS XE file in your device Bootflash with USB Pendrive Router# Show usb0: or usbflash0: You can see the image on the USB Step 3. Once you have the IOS XE file in the bootflash, verify the integrity of the file by running the following commands. Verify /md5 bootflash: "IOS XE file" For example Verify Router# /md5 bootflash:isr4300-universalk9.17.03.05.SPA.bin Step 4. backup of running configuration: Router# copy running-config bootflash:backup Step 5. Running below commands on device to proceed with the IOS XE upgrade. Enable Configure terminal Command Router config# no boot system Router config# boot system flash bootflash: "IOS XE file" new image For example: Enable Configure terminal no boot system boot system flashbootflash:isr4300universalk9.17.06.03a.SPA.bin Once finished, save changes, and reload the router by running the following commands: Router# write memory Router# reload Step 6. After reloading the device verify the new IOS XE version by running the command: Router# Show version <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Resets/Deletes/Recovery >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> ******************** remove old and add new system Booting ******************** switch(config)#no boot sytem switch(config)#boot sytem switch all iosfilename.bin switch#write ********************* Deleting other/older IOS file from flash of switch ********************** switch#show flash and copy older ios file name switch#delete flash: (// may be)______older file existing in the flash of switch(.bin)______ delete filename....? delete flash....confirm? switch#show flash ******************** CISCO Switch recovery from XMODEM mode ******************** switch: set baud 115200....ENTER_______set serial port at 115200 as well switch: copy xmodem: flash:________file name (.bin) in the directory___________ENTER in Tera term go to file>transfer>xmodem>send.......slect ios file and ok......uploading.... switch:boot flash:____file name uploaded in the flash______ENTER switch#reload .............and press mode button on switch..... switch:set BAUD 9600...ENTER____set serial port at 9600 as well switch:reset....ENTER let the switch booting and .......ok ************ manual booting ************* Switch(config)#boot manual *********** Automatic booting ************ Switch(config)#no boot manual Switch#write memory ******************** CISCO Router recovery from ROMmon mode ******************** rommon 1>IP_ADDRESS=192.168.20.1 rommon 2>IP_SUBNET_MASK=255.255.255.0 rommon 3>DEFAULT_GATEWAY=192.168.20.10 rommon 4>TFTP_SERVER=192.168.20.10-----pc or tftp server address rommon 5>TFTP_FILE=IOS bin file name in tftp server rommon 6>tftpdnld....ENTER do you wish to continue?y/n: y.....ENTER..... rommon 7>reset...ENTER.......and ok or rommon 1>xmodem rommon 2>xmodem -c iosfilename.bin....ENTER do you wish to continue?y/n: y.....ENTER..... in Tera term go to file>transfer>xmodem>send.......select ios file and ok......uploading.... ******************************* reverting password on routers ******************************** power on router ctrl+shift+break OR ctrl+break OR ctrl+C OR break from putty to enter into the rommon mode....during booting rommon1> confreg 0x2142 modular routers rommon2> reset or rommon1> o/r 0x2142 fixed routers rommon2> i by doing this the router will not boot from startup-config file then router>enable router#show version router#copy startup-config running-config do not exit from privilege mode, otherwise have to repeat process Now first remove old passwords & secrets & configure new passwords if required router#conf t router(config)#no enable password remove enable credentials router(config)#no enable secret router(config)#line console 0 remove console credentials router(config-line)#no password router(config-line)#no secret router(config-line)#exit router(config)#line vty 0 15 remove telnet credentials router(config-line)#no password router(config-line)#no secret then router#copy running-config startup-config and changing register file back to 0x2102 so that on next bootup router load startup-configs router#config-register 0x2102..............or 2102 only without 0x router#show version router#copy running-config startup-config router#write ************************ Reverting Password on Cisco Switch ************************* press MODE button during boot to interrupt Boot Process OR HP Ctrl + Break/ Ctrl + Fn + Pause/ Ctrl + Fn + ScrLK Like HP ProBook 650 G2 Ctrl + Fn + Shift(Pause) On-Screen Keyboard Ctrl + ScrLK Dell/Lenovo Fn + B/ Fn + P Also Try Ctrl + B note: use Serial to USB converter or latop serial port instead of USB mini port from the switch note: press MODE Button when ios is LOADING only to interrupt BOOTING Process, otherwise it will not work Press Mode Button during Laoding & Verifying flash image switch:flash_init press ENTER one can use ? mark for help switch:load_helper press ENTER switch:dir flash: now rename the config.text to config.text.old switch:rename flash:config.text flash:config.text.old press ENTER swicth: swicth:dir flash: switch:boot this command will reboot the switch with IOS image switch>en swicth#sh flash swicth# rename flash:config.text.old flash:config.text Destination filename [config.text]? Switch#copy flash:config.text system:running-config to restore configurations Destination filename [running-config]? Now Configs restore but password are still there, it will ask for UN & PWD if reloaded the switch So we need to remove Passwords swicth#conf t swicth(config)#no enable password or secret switch(config)# line console 0 switch(config-line)# no password switch(config-line)#no login local switch# write mem we can create UNs & PWDs again if needed: switch1#conf t switch1(config)#line con 0 switch1(config-line)#password admin switch(config-line)#no login local switch1(config-line)#exit switch1(config)#username admin secret admin switch1(config)#show users switch# write mem you may reload now: switch#reload ************************* Reset the Switch/deleting flash, vlan and config files ************************* switch#write erase to delete configs from NVRAM other than VLANs(from flash) switch#delete vlan.dat to delete VLANs configs(from flash) OR switch#delete flash:vlan.dat to delete VLANs configs(from flash) switch#delete flash:fileName deleting files in the directory or folder: switch#delete dir:directory or folder name/fileName in that folder deleting directory: switch#delete /recursive /force flash:directory or folder name.......(usually in .SE file) switch#reload ************************* Reset the Router ************************* switch#write erase to delete configs from NVRAM switch#reload <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Cisco CLI Modes >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> Modes: Representation Command to go to mode 1. User Exec mode Switch> PRESS ENTER on startup 2. Privilage Exec/enable mode Switch# Switch> enable 2. Global Configuration mode /Priv. Config. Switch(config)# Switch# configure terminal 3. interface Configuration mode/Priv. Int. Switch(config-if)# Switch(config)# interface INTERFACE_NAME 4. VLAN Configuration mode switch(vlan)# switch# vlan database <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< SECURITY (username and passwords) >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> It is a very good security practice to lock-down all access lines of a switch with a password. Although it is much better to configure an external AAA server (for centralized Authentication Authorization and Accounting) ----------Access methods to be secured---------- 1. Enable 2. Line Consoole 3. Line Auxilliary 4. Line VTY or virtual terminal ----------password or key types---------- 1. password clear text 2. Secret encrypted ----------modes to be secured---------- enable mode ask password when we enter enable command login ask password when we login htrough console, aux or telnet or SSH ******************** Enable mode password ******************** switch(config)#enable password somestrongpass clear text switch(config)#sevrice password-encryption encrypted text switch(config)#enable secret somestrongpass Hash form encrypted for more security -----extra safety and security----- R1(config)# service password-encryption R1(config)# security passwords min-length 8 R1(config)# login block-for 120 attempts 3 within 60 deny logins for 2 minutes if 3 failed login attempts occur within 1 minute. ****************************** privilege levels ****************************** level 0 A> default level level 1 A> enable/enable 15 to level 15 Total Commands = 5 commands level 2-14 A# customised Total Commands = L1=5 + L2=custom command + L3 + L4 + L5....... + L14 level 15 A# Total Commands = L1=5 + L2=custom command + L3 + L4 + L5....... + L14 + L15 Level 0 – Zero-level access only allows five commands- logout, enable, disable, help and exit. Level 1 – User-level access allows you to enter in User Exec mode that provides very limited read-only access to the router. Level 15 – Privilege level access allows you to enter in Privileged Exec mode and provides complete control over the router. enable 1 to go to enable privilege level 1 enable 15 to go to enable privilege level 15 enable 2 to go to enable privilege level 2 enable 3 to go to enable privilege level 3 enable 8 to go to enable privilege level 8 en 15 conf t Router(config)#privilege exec level 5 conf t Router(config)#no privilege exec level 5 conf t Router(config)#privilege exec level 5 show running-config Router(config)#no privilege exec level 5 show run Router(config)#privilege exec level 5 show start Router(config)#no privilege exec level 5 show start ------------------- Set USERNAME & Password for Privilege Levels ------------------- Switch(config)# enable secret level 5 password 123sample only password not username Switch(config)# enable password level 5 secret 123sample to go to specific privilege level with both USERNAME & Password EXIT all back to login mode Switch(config)#username USERNAME privilege 8 password PASSWORD Password with username also Switch(config)#username USERNAME2 privilege 6 password PASSWORD Switch(config)#username USERNAME3 privilege 4 secret PASSWORD Switch(config)#username USERNAME4 privilege 1 secret PASSWORD ------------------- Privilege-Level Troubleshooting ------------------- show privilege to check Level number Switch#show users Switch#show run | b username Switch#show run | include UserNameToCheck Switch#show running-config | include password Switch#show running-config | include secret ------------------- Recommended Privilege-Level Changes ------------------- RouterOne#config terminal RouterOne(config)#privilege exec level 15 connect RouterOne(config)#privilege exec level 15 telnet RouterOne(config)#privilege exec level 15 rlogin RouterOne(config)#privilege exec level 15 show ip access-lists RouterOne(config)#privilege exec level 15 show access-lists RouterOne(config)#privilege exec level 15 show logging RouterOne(config)#privilege exec level 1 show ip *************** Role Based CLI Access *************** -------------- Create VIEW -------------- AAA need to configure AAA server first Router(config)#aaa new model run command at privilege level 15 Router(config)#enable secret ccna Router#enable view go to root user level Router#show parser view R1(config)parser view hamid R1(config-view)secret PASSWORD R1(config-view)command exec include sh run R1#enable view hamid to go to hamid view R1(config)parser view zohaib R1(config-view)secret abc123 R1(config-view)command exec include sh start R1#enable view zohaib to go to zohaib view -------------- Create SUPER VIEW -------------- enable view 2. configure terminal 3. parser view SUPERVIEW_NAME superview 4. secret 5 encrypted-password 5. view SUPERVIEW_NAME *************** remote AAA server*************** ACS cisco AAA server ISE cisco AAA server TACACS cisco proprietary protocol RADIUS industry standard protocol R1(config)#aaa authentication login default group tacacs+ R1(config)#tacacs-server host 10.1.1.1 key cisco *************** Local AAA server*************** R1(config)usename abc password abc123 R1(config)usename abc1 password abc123 aaa new model aaa authentication login default local ask password on login, default=all console, telnet etc Router(config)#aaa authentication login default local-case case-sensitive local username aaa authentication login default local none login without username/pass if username not in local database, default=all console, telnet aaa authentication login NN local none label NN for console, not ask Auth if NN called on line console, usually console kept unsecured aaa authentication login TT local label TTfor telnet, ask username/pass if TT is called on login via vty lines line console 0 login authentication NN call for NN label on line console so that it does not ask uname/pass on concole line vty 5 15 login authentication TT call for TT label on line vty R1(config)aaa authentication fail-message $ type message $ R1(config)aaa authentication username-prompt TYPE_ANYTHING to make hacker fool type Password: R1(config)aaa authentication password-prompt TYPE_ANYTHING to make hacker fool type Username: ------------------- delete AAA configs ------------------- R1(config)no aaa authentication login NN none R1(config)no aaa authentication login TT local no aaa new model ****************************** Local/Remote Access Configs for switch/Routers ****************************** ****************************** Telnet Configurations ****************************** Step 1. Configure Management IP in Management VLAN switch(config)# #Inter Vlan 1 switch(config-if)# #IP address 10.10.10.1 255.255.255.0 Step 2. Configure Telnet in VTY 0 15 Ports switch(config)# line vty 0 15 switch(config-line)# Transport Input Telnet can be input for telnet or all switch(config-line)# password strongtelnetpass switch(config-line)# login switch(config)#enable secret PASSWORD or ------------- For Telnet to prompt username also while logging in ------------- switch(config)#username NAME privillage 15 secret PASSWORD user with maximum privilege level of 15 or switch(config)#username NAME secret PASSWORD switch(config)# line vty 0 15 switch(config-line)# login local switch will promt for username while login switch(config-line)# exit switch(config)#enable secret PASSWORD ---------------- USERNAME Troubleshoot ---------------- Switch#show users Switch#show run | b username ******************************* Console password ******************************* switch(config)# line console 0 switch(config-line)# password strongconsolepass switch(config-line)# login -----extra safety and security----- switch(config-line)# exec-timeout 5 30 disconnect after 5 minutes of inactivity on any line console or line vty mode switch(config)# login block-for 100 attempts 3 within 100 *attempts 3 → If there are 3 failed login attempts *within 100 → Within 100 seconds *block-for 100 → The device will block all login attempts for 100 seconds ------------- For Console to prompt USERNAME also while logging in ------------- r1(config)#username NAME privillage 15 secret PASSWORD user with maximum privilege level of 15 or switch(config)#username NAME secret PASSWORD switch(config)#line console 0 switch(config-line)#login local promt for username while login ---------------- USERNAME Troubleshoot ---------------- Switch#show users Switch#show run | b username ******************************* AUX password ******************************* switch(config)# line aux 0 switch(config-line)# password strongauxpass switch(config-line)# login -----extra safety and security----- switch(config-line)# exec-timeout 5 30 disconnect after 5 minutes of inactivity on any line console or line vty mode ******************************* Configuring SSH ********************************* r1(config)#username NAME privillage 15 secret PASSWORD user with maximum privilege level of 15 or switch(config)#username NAME secret PASSWORD switch(config)#hostname abc abc(config)#ip domain-name abc.com abc(config)#crypto key generate rsa general-keys modulus 512 max 2048 for maximum encryption abc(config)# line vty 0 15 abc(config-line)#transport input ssh can be input for telnet or all abc(config-line)# login local promt for username while login abc(config)#enable secret PASSWORD now access SSH on linux ssh user@server-ip access SSH on windows ssh -l USERNAME IP and press ENTER ---------------- USERNAME Troubleshoot ---------------- Switch#show users Switch#show run | b username -----extra safety and security----- R1(config-line)# exec-timeout 5 30 R1(config)# ip ssh time-out 90 R1(config)# ip ssh authentication-retries 2 R1(config)#ip ssh version 2 enable SSH version 2 to enhance security -----SSH troubleshooting----- R1(config)#show ip ssh R1(config)#show ssh -----Delete RSA key pairs & SSH also----- R1(config)#crypto key zeroize rsa once RSA key pair is deleted, the SSH server is automatically disabled ********************************* Configure to LOG login activity ********************************* R1(config)# login on-success log Log every successful login R1(config)# login on-failure log every 2 Log failed login attempts after every 2 seconds R1(config)# exit R1(config)#do show login to show Login attempts and status (Failed or Succeeded) ****************************** removing/delete security Password and configurations ****************************** switch(config)#no username NAME removing username ------------- remove telnet password ------------- switch(config)# line vty 0 15 switch(config-line)# no password strongtelnetpass switch(config-line)#login ------------- remove console password ------------- switch(config)# line console 0 switch(config-line)# no password switch(config-line)#login ------------- removing enable secret ------------- switch(config)#no enable secret switch(config)#no enable password ****************** Network Time Protocol NTP/Clock/Time/Date Management Commands ******************* R1#clock set 22:10:22 22 apr 2024 R1(config)#clock timezone TIME_ZONE_NAME OFFSET_FROM_UTC Timezone name is like Pakistan standard time PST etc, offset in +5 or -5 etc R1(config)#clock summer-time ISB ? date Configure absolute summer time recurring Configure recurring summer time ------------ NTP Setting on Server Router ------------ NTP uses UDP port 123 R1(config-if)# ip address 192.168.10.2 255.255.255.0 R1(config)# ntp master 1 (STRATUM_NUMBER) Note: NTP uses a stratum to describe how many NTP hops away a machine is from an authoritative time source. A stratum 1 time server has a radio or atomic clock that is directly attached, a stratum 2 time server receives its time from a stratum 1 time server, and so on NTP Tool or NTP check Tool can be used o verify NTP settings ------------ NTP Setting on Client Router ------------ R2(config-if)# ip address 192.168.10.3 255.255.255.0 R2(config)# ntp server 192.168.10.2 (NTP_SERVER_IP) ------------ NTP Client on Switch ------------ SW1(config)# int vlan1 SW1(config-if)# no shut SW1(config-if)# ip address 192.168.10.4 255.255.255.0 SW1(config)# ntp server 192.168.10.2 (NTP_SERVER_IP) ------------ NTP/Time/Date troubleshooting ------------ Show clock show clock detail show ntp Associations show ntp status show ntp information show ntp packets ********************** SNMP configuration for monitoring ************************* switch(config)# snmp-server community "SWITCH MONITOR" ro switch(config)#exit Switch#write ********************* Warning Banner at switch startup ********************* A banner is a message which is used to give information about the devices to the user. ---------------- Banner Types in Cisco ---------------- LINE exec Set EXEC process creation banner motd Set Message of the Day banner login Set login banner config-save Set message for saving configuration Set EXEC process creation banner incoming Set incoming terminal line banne prompt-timeout Set Message for login authentication timeout slip-ppp Set Message for SLIP/PPP --------------To create short single line banner-------------- start & end with same letter (start & end letter/character called Delimiting character will not be displayed in message) switch# conf t switch(config)# banner motd # DESIGN YOUR BANNER WITH TEXT HERE # --------------To create detailed multi line banner-------------- start & end with same letter (start & end letter/character called Delimiting character will not be displayed in message) Switch(config)#banner motd ~ press ENTER Enter TEXT message. End with the character '~'. DESIGN YOUR DETAILED MULTI LINE BANNER WITH TEXT HERE ~ OR just copy bellow complete designed command including delimiting character " C"and paste in Global Configuration Mode banner motd ~ ################################################## WARNING : Unauthorized Access Is Prohibited, STAY ALERT!! ################################################## ~ switch(config)# no banner motd delete banner switch#show banner-motd switch#show run switch#show run | banner ----------------------------Sample Banner--------------------------- ########################################################################## ## AUTHORIZED ACCESS ONLY ## ## ## ## WARNING: This device is the property of STC. ## ## Unauthorized access is strictly prohibited. ## ## ## ## Do NOT attempt to log in without proper authorization. ## ## Strict legal action may be taken in case of illegal access. ## ## ## ## Please ensure you have been granted permission ## ## before accessing this device. ## ## ## ########################################################################## ============================= Login Banner ============================= Switch(config)# banner login ~ **************************************** WARNING: Authorized Access Only NESPk Networks - Secure Environment **************************************** ~ ___________________________________________________________________________________________________________ <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< BASIC COMMMANDS >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> *************** Terminal Buffer, Terminal Size, Terminal History, Command history Size *************** terminal commands history or Buffer size SIZE(0-256) increase the number of command lines that the history buffer records during the current terminal session only. ****************** logging synchronization, command not to be typed in logging information line ****************** switch(config)#line console 0 switch(config-line)#logging synchronous switch(config-line)#exit ****************** "DNS finding on wrong command entry" problem ****************** switch(config)#no ip domain-lookup ****************** switch port or layer 2 port as a layer 3 port ******************** assigning IP adrress to Switchport by "no switchport" command * by default the port of the switches are layer 2 port and work only on MAC address not on IP address * so in order to make the switchport a Layer 3 port so that IP address can be assigned follow any one of these methods switch(config)#int fa0/1 switch(config-if)#no switchport switch(config-if)#ip address 192.168.10.100 255.255.255.0 unassign IP address switch(config-if)#no ip address ****************************** IP addresses are allowed to access the switch via Telnet ****************************** switch(config)# ip access-list standard TELNET-ACCESS switch(config-std-nacl)# permit 10.1.1.100 switch(config-std-nacl)# permit 10.1.1.101 switch(config-std-nacl)# exit *Apply the access list to Telnet VTY Lines switch(config)# line vty 0 15 switch(config-line)# access-class TELNET-ACCESS in switch(config-line)# exit switch(config)# ***************************** Assign IP address to the switch for management ******************************** Management IP is assigned to Vlan 1 by default called SVIs (switch virtual interfaces) can be configured to other VLANs also can be configured to Physiacl interface also in L3 switches switch(config)# interface vlan 1 switch(config-if)# ip address 10.1.1.200 255.255.255.0 switch(config-if)# exit switch(config)# ************************* WebUI via http/https************************* Cisco SDM (security Devices Management) can be used to access GUI java and cisco configuration professional is required install java client on pc if required r1(config)#int fa0/1 r1(config-if)#ip address 192.168.100.1 255.255.255.0 r1(config)#username NAME privillage 15 secret PASSWORD r1(config)#ip http server r1(config)#ip http secure-server r1(config)#ip http authentication local r1(config)#line vty 0 4 r1(config-line)#privillage level 15 r1(config-line)#login local r1(config-line)#transport input telnet ssh cisco 3725 can be used to test GUI _________________________________________________________________________________________________________________________________ <<<<<<<<<<<<<<<<<<<<<<<<<<<<<< SHOW COMMANDS >>>>>>>>>>>>>>>>>>>>>>>>>>>> switch# show running-configurations (Displays the current running configuration) R1# show running-config | section line vty R1#show running-config interface gigabitethernet 0/0/0 R1#show terminal switch# show startup-configurations switch# show interfaces (Displays the configuration of all interfaces and the status of each one) switch# show vlan (Displays all vlan numbers, names, ports associated with each vlan etc) switch# show interface status (Displays status of interfaces, speed, duplex etc) switch# show mac address-table (Displays current MAC address table and which MAC address is learned on each interface) show ip interface brief show ip interface brief is a extremely useful command to get quick overview of all interfaces on switch. It lists their status including IP address and protocol. Router# show ip ports all Show TCP/UDP Ports show control-plane host open-ports switch#show user s1(config)#show port-security s1(config)#show port-security interface gig 0/0/0 switch#show interface stat switch#show flash switch#show switch switch#show switch details switch#show switch neighbourboard switch#show switch stack-ports switch#show switch stack-ring speed switch#show switch stack-power switch#show switch stack-power budgeting switch#show switch stack-power detail switch#show switch stack-power neighbours switch#show switch stack-power load-shedding switch#show spanning-tree switch#show spanning-tree root switch#show spanning-tree vlan switch#show spantree summary switch#show mac-address-table switch#show interface trunk switch#show vtp status switch#show vtp password switch#show cdp neighbours switch#show history switch#show etherchannel summary switch#show ip route switch#show ipv6 route switch#show ip eigrp neighbours switch# show version show ip dhcp snooping show running-config dhcp switch# show ip dhcp snooping binding s1#show port-security interface gigabitethernet 0/0 show port-security address r1#show ip oroute r1#show ip ospf neighbour r1#show ip ospf intreface r1#show ip protocol r1#show ip ospf database r1#show history show ipv6 interface <<<<<<<<<<<<<<<<<<<<<<<< Spanning Tree Protocol (STP) >>>>>>>>>>>>>>>>>>>>>>>> use for Loop free Layer-2 redundancy of switches and in network * priority value range 1-65536 * default priority =32768 * assigned manually in multiples of 4096 * lowest priority value wins for root switch *root ID = ID of the root switch in network running STP = priority value + no of vlan *Bridge ID = ID of the any particular switch in network runnning STP ----------- STP Timers ----------- 1. Hello Timer : The hello time is the interval between BPDUs. The default is 2 seconds but can be modified to between 1 and 10 seconds. 2. Forward Delay Timer : The forward delay is the time that is spent in the listening and learning state. The default is 15 seconds but can be modified to between 4 and 30 seconds. 3. Max Age Timer : The max age is the maximum length of time that a switch waits before attempting to change the STP topology. The default is 20 seconds but be modified to between 6 and 40 seconds. -----------Port States-STP vs RSTP----------- STP (IEEE 802.1D) RSTP (IEEE 802.1W) disabled= included disabled= discarded blocking= included blocking= discarded listening= included listening= discarded learnig= included learnig= included forwarding= included forwarding= included -----------Ports Roles-STP vs RSTP----------- STP (IEEE 802.1D) RSTP (IEEE 802.1W) Root Port Root Port Designated Port Designated Port Blocked Port Backup Port Blocked Port Alternate Ports ------------- Operational Details of Port State -------------- Port State BPDU MAC Address Table Forwarding Data Frames Blocking Rx Only No update No Listening Rx & Tx No update No Learning Rx & Tx Updating table No Forwarding Rx & Tx Updating table Yes Disabled No Rx Tx No update No -------------- Port Cost -------------- port cost STP RSTP 4mbps 250 5,000,000 10 100 2,000,000 16 62 1,250,000 100 19 200,000 1G 4 20,000 2G 3 10,000 10G 2 2,000 ----------------Steps to a Loop-Free Topology----------------- 1. Elect the root bridge : The STA designates a single switch as the root bridge and uses it as the reference point for all path calculations. BPDUs are sent every two seconds on Bootup BPDU frames contain the BID of the sending switch and the BID of the root bridge, known as the Root ID. At first, all switches declare themselves as the root bridge with their own BID set as the Root ID. Eventually, the switches learn through the exchange of BPDUs which switch has the lowest BID. The switch with the lowest BID will become the root bridge. Root Bridge Tie Brakers : 1. Priority Value (1-65536) 2. extended system ID (VLAN 1 assignment) 3. MAC Address 2. Elect the root ports : The root port is the port closest to the root bridge in terms of overall cost (best path) to the root bridge Paths with the lowest cost become preferred, and all other redundant paths are blocked 3. Elect designated ports : All ports on the root bridge are designated ports, as shown in the figure. This is because the root bridge has the lowest cost to itself. 4. Elect alternate (blocked) ports : If a port is not a root port or a designated port, then it becomes an alternate (or backup) port. Alternate ports and backup ports are in discarding or blocking state to prevent loops. ---------------- Different Versions of STP -------------- STP This is the original IEEE 802.1D version (802.1D-1998 and earlier) that provides a loop-free topology in a network with redundant links. Also called Common Spanning Tree (CST), it assumes one spanning tree instance for the entire bridged network, regardless of the number of VLANs. PVST+ Per-VLAN Spanning Tree (PVST+) is a Cisco enhancement of STP that provides a separate 802.1D spanning tree instance for each VLAN configured in the network. PVST+ supports PortFast, UplinkFast, BackboneFast, BPDU guard, BPDU filter, root guard, and loop guard. RSTP Rapid Spanning Tree Protocol (RSTP) or IEEE 802.1w is an evolution of STP that provides faster convergence than STP. 802.1D-2004 This is an updated version of the STP standard, incorporating IEEE 802.1w. Rapid PVST+ This is a Cisco enhancement of RSTP that uses PVST+ and provides a separate instance of 802.1w per VLAN. Each separate instance supports PortFast, BPDU guard, BPDU filter, root guard, and loop guard. MSTP Multiple Spanning Tree Protocol (MSTP) is an IEEE standard inspired by the earlier Cisco proprietary Multiple Instance STP (MISTP) implementation. MSTP maps multiple VLANs into the same spanning tree instance. MST Multiple Spanning Tree (MST) is the Cisco implementation of MSTP, which provides up to 16 instances of RSTP and combines many VLANs with the same physical and logical topology into a common RSTP instance. Each instance supports PortFast, BPDU guard, BPDU filter, root guard, and loop guard. ------------------PortFast and BPDU Guard------------------ When a device is connected to a switch port or when a switch powers up, the switch port goes through both the listening and learning states, each time waiting for the Forward Delay timer to expire. This delay is 15 seconds for each state, listening and learning, for a total of 30 seconds. This delay can present a problem for DHCP clients trying to discover a DHCP server. DHCP messages from the connected host will not be forwarded for the 30 seconds of Forward Delay timers and the DHCP process may timeout. The result is that an IPv4 client will not receive a valid IPv4 address. In a valid PortFast configuration, BPDUs should never be received on PortFast-enabled switch ports because that would indicate that another bridge or switch is connected to the port. This potentially causes a spanning tree loop. To prevent this type of scenario from occurring, Cisco switches support a feature called BPDU guard. When enabled, BPDU guard immediately puts the switch port in an errdisabled (error-disabled) state on receipt of any BPDU. This protects against potential loops by effectively shutting down the port. The BPDU guard feature provides a secure response to invalid configurations because an administrator must manually put the interface back into service. *********************** STP Configs *********************** method 1 switch#spanning-tree vlan 1 root primary defininig switch as primary root also can secondary method 2 switch#spanning-tree vlan 1 priority 8192 value should be increment/multiple of 4096 *********************** Per-VLAN Spanning Tree (PVST) *********************** In Per-VLAN Spanning Tree (PVST) versions of STP, there is a root bridge elected for each spanning tree instance. This makes it possible to have different root bridges for different sets of VLANs. STP operates a separate instance of STP for each individual VLAN. If all ports on all switches are members of VLAN 1, then there is only one spanning tree instance. Per-VLAN Spanning Tree (PVST+) is a Cisco enhancement of STP that provides a separate 802.1D spanning tree instance for each VLAN configured in the network. PVST+ supports PortFast, UplinkFast, BackboneFast, BPDU guard, BPDU filter, root guard, and loop guard. *********************** Rapid spanning-tree protocol config *********************** To make the STP convergence fast ----------- Features ---------- portfast uplinkfast backbone fast switch(config)#spanning-tree mode rapid-pvst ******************* STP & RSTP Troubleshooting ******************* switch#show version switch#show spanning-tree switch#show spanning-tree root switch#show spanning-tree vlan PVST-->> can create STP for every vlan switch#show spanning-tree summary ******************************* Ether channel ******************************* ------------------- Ether Channel Troubleshooting ----------------- switch#show etherchannel summary switch#show ip int brief switch#show int trunk switch#show run switch#show spanning-tree switch#show etherchannel switch#show cdp neighbours switch#show history PAgP port aggreggation protocol..............cisco proprietery LACP link aggregation control protocol.......industry protocol modes result ON PAgP and LACP disabled (negotiation disabled) Auto passively listen for PAgP........only RX PAgP info from opposite switch Desirable Actively listen for PAgP.........RX & TX PAgP info Passive passively listen for LACP........only RX LACP info from opposite switch Active Actively listen for LACP.........RX & TX LACP info successful combination of ether channel a. ON-ON b. Desirable-Desirable............PAgP c. Desirable-Auto d. Active-Active.............LACP e. Active-Passive ************************PAGP************************ 2 to 8 physical link can be aggreagated max 8 8*100 Mbps = 800 Mbps 8*1G bps = 8 Gbps 8*10 Gbps = 80 Gbps +++++++++++++ PAGP on switch 1 ++++++++++++++ switch1(config)#int range fa0/21 - 24 switch1(config-if-range)#channel-protocol pagp switch1(config-if-range)#channel-group ? <1-48> channel group number switch1(config-if-range)#channel-group 12 mode desirable switch1(config-if-range)#end ---------define ports or entire port-channel in trunk----------- method 1 switch(config)#int port-channel 12 Switch(config-if)#switchport trunk encapsulation Dot1q Switch(config-if)#switchport mode trunk method 2 switch1(config)#int range fa0/21 - 24 Switch(config-if)#switchport trunk encapsulation Dot1q Switch(config-if)#switchport mode trunk ++++++++++++++ PAGP on switch 2 ++++++++++++++ switch2#conf t switch2(config)#int range fa0/21 - 24 switch1(config-if-range)#channel-protocol pagp switch2(config-f-range)#channel-group 12 mode auto switch2(config-if-range)#end method 1 switch2(config)#int port-channel 12 Switch2(config-if)#switchport trunk encapsulation Dot1q Switch2(config-if)#switchport mode trunk method 2 switch2(config)#int range fa0/21 - 24 Switch2(config-if)#switchport trunk encapsulation Dot1q Switch2(config-if)#switchport mode trunk *************************** LACP *************************** 2 to 16 physical link can be aggregated max 16 16*100 Mbps = 1600 Mbps 16*1G bps = 16 Gbps 16*10 Gbps = 160 Gbps +++++++++++++++ LACP on switch 1 +++++++++++++++ switch1#conf t switch1(config)#int range fa0/21 - 24 switch1(config-if-range)#channel-protocol lacp switch1(config-f-range)#channel-group 12 mode active switch1(config-if-range)#end +++++++++++++++ LACP on switch 2 +++++++++++++ switch2#conf t switch2(config)#int range fa0/21 - 24 switch2(config-if-range)#channel-protocol lacp switch2(config-f-range)#channel-group 12 mode active switch2(config-if-range)#end *********** Removing Ether channel *********** switch2(config)#int range fa0/21 - 24 Switch2(config-if-range)#no channel-protocol Switch2(config-if-range)#no channel-group Switch2(config-if-range)#no switchport mode trunk Switch2(config-if-range)#no switchport encapsulation switch2(config)#int port-channel 12 Switch2(config-if)#no switchport mode _________________________________________________________________________________________________________ <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Neighbours Discovery Protocols >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> ******************* Cisco Discovery Protocol CDP configs ******************* used to share info about directly connected cisco devices Sends announcements to multicast destination MAC address 01-00-0c-cc-cc-cc to each connected interface this info is stored in table in RAM Switch(config)#cdp run enable cdp Switch(config-if)#cdp enable enable cdp on an interface Router(config)#no cdp run disable cdp Router(config-if)#no cdp enable disable cdp on an interface ------------------------ CDP Troubleshoot ------------------------ show cdp to show local cdp configs show cdp neighbors show cdp neighbours detail show cdp entry * show cdp interface all interfaces show cdp interface gigabitEthernet 0/1 ******************* Link Layer Discovery Protocol LLDP configs ******************* LLDP-MED used for voice ove IP info sharing Switch(config)# lldp run enable LLDP Switch(config)# int fa0/1 Switch(config-if)# lldp transmit Switch(config-if)# lldp receive Switch(config)# no lldp run disable LLDP Switch(config)# int fa0/1 Switch(config-if)# no lldp transmit Switch(config-if)# no lldp receive show lldp show lldp neighbours ________________________________________________________________________________________ <<<<<<<<<<<<<<<<<<<<<<<<< opening the folder in the flash >>>>>>>>>>>>>>>>>>>>>>>>>> switch#dir flash:/folder name.......(usually in .SE file) ________________________________________________________________________________________ <<<<<<<<<<<<<<<<<<<<<<<<<<< save/saving running configuration >>>>>>>>>>>>>>>>>>>>>>>>>>>>>> Switch keeps all running configuration in RAM. All data from RAM is erased when we turned off the device. To save running configuration use following command Switch#copy running-config startup-config or write memory command ________________________________________________________________________________________ <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< FACTORY RESET or CLEAR or ERASE >>>>>>>>>>>>>>>>>>>>>>>>>>>>> Reset Catalyst Switches Running CatOS This procedure applies to Catalyst 4500/4000, 5500/5000, and 6500/6000 series switches running CatOS. These switches store the configuration in NVRAM automatically, wherever users enter the commands in enable mode. clear config {mod | rmon | all | snmp | acl {nvram}} The clear config all command clears the system configuration, as well as the module configuration. This command does not, however, clear the boot variables, such as config-register and boot system settings. You can alter the boot variable settings with the set boot command. If your switch has any router cards, the clear config all command does not clear the Cisco IOS Software configuration on the router cards. (Examples of these router cards include WS-X4232-L3 modules on the 4000 switches, Route Switch Cat5k> (enable) clear config all This command will clear all configuration in NVRAM. This command will cause ifIndex to be reassigned on the next system startup. Do you want to continue (y/n) [n]? y After the configuration erase in CatOS, you do not need to reload the switch. The configuration takes effect immediately, and the switch returns to the factory default configuration. If you want to clear the configuration of a specific module on the switch, issue the clear config mod command, as shown here: Cat5k> (enable) clear config 5 This command will clear module 5 configuration. Do you want to continue (y/n) [n]? y ................................ Module 5 configuration cleared. Cat5k> (enable) Cat5k> (enable) Reset Switch Configuration To reset the switch to factory default, issue the erase startup-config or write erase command. This command does not clear the boot variables, such as config-register and boot system settings. You can alter the boot system parameters with the boot command. Cat2950# write erase Erasing the nvram filesystem will remove all files! Continue? [confirm]y[OK] Erase of nvram: complete Cat2950# Cat2950# reload or erase startup-config command or long press mode button until lights stop flashing <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< VIrtual Local Area Network VLAN configs >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> 2 Types basically: 1. Static 2. Dynamic ++++++++++++++ Static VLAN ++++++++++++++ Static VLAN provides port based VLAN membership. network engineer configure switch ports in a particular VLAN. When any device is connected to that port, it becomes part of a pre-defined VLAN. ++++++++++++++ Dynamic VLAN ++++++++++++++ 2 methods: ------------- 1. Via MAC Address ------------- VMPS is responsible for VLAN assignment based on MAC. But it was used in the past Dynamic VLAN provides VLAN membership based on the MAC address When any end device is connected with the switch, then switch learns the MAC address of end device After learning MAC, switch sends a request to VMPS (VLAN Management Policy Server) that - "I have a MAC. Tell me the VLAN ID for the MAC. ------------- 2. Via 802.1x or RADIUS Server ------------- In present time we use Dot1x and RADIUS server for dynamic VLAN, based on username and password of a user instead of MAC ************************** Static vlans configs **************************** creating vlan (static vlan....it is baesd on port numbers) method 1 switch#vlan database switch(vlan)#vlan 250 name UBL switch#show vlan...... method 2 switch(config)#vlan 250 switch(config)#name UBL switch#show vlan.......... S1(config)#vlan 100,102,105-107 create multiple vlans at once ****************************** static vlan and assign ports ************************* ---------switchport modes-------- access always access trunk always trunk dynamic auto listens to oppsoite port dynamic desirable for trunk = speaks/listens, for access = listens only Port mode-Switch 1 Port mode-Switch 2 Resultant Mode access access access access trunk Limited connectivity access Dynamic Auto access access Dynamic Desirable access Trunk access Limited connectivity Trunk trunk Trunk Trunk Dynamic Auto Trunk Trunk Dynamic Desirable Trunk Dynamic Auto access access Dynamic Auto trunk trunk Dynamic Auto Dynamic Auto Access Dynamic Auto Dynamic Desirable trunk Dynamic Desirable access access Dynamic Desirable trunk trunk Dynamic Desirable Dynamic Auto trunk Dynamic Desirable Dynamic Desirable trunk switchport mode syntax: switch(config-if)#switchport mode { access | dynamic { auto | desirable } | trunk } ----------------switcport Access vlans----------------- switch(config)# interface range fe 0/1 - 2 switch(config-if-range)# switchport mode access switch(config-if-range)# switchport access vlan 2 switch(config)# interface range fe 0/3 - 4 switch(config-if-range)# switchport mode access switch(config-if-range)# switchport access vlan 3 ----------------switcport Trunk vlans----------------- SW1(config)# interface range fe 0/5 SW1(config-if-range)# switchport mode trunk if SW1 VLAN also 10 but SW2 not have 10, then only allow 2 & 3 to reduce Bcast on trunk SW1(config-if-range)# switchport trunk allowed vlans 2,3 if again u want to add 10 also to pass over trunk then SW1(config-if-range)# switchport trunk allowed vlans add 10 pass all vlans over trunk SW1(config-if-range)# switchport trunk allowed vlans all pass all vlans over trunk except 10 SW1(config-if-range)# switchport trunk allowed vlans except 10 pass no vlans over trunk SW1(config-if-range)# switchport trunk allowed vlans none remove vlan 10 from trunk SW1(config-if-range)# switchport trunk allowed vlans remove 10 SW1#show interface trunk -----------------Deleting or unassign VLAN from Access or Trunk port----------------- switch(config-if-range)#no switchport access vlan 20 no switchport trunk allowed vlan to set trunk to default state no switchport trunk native vlan to set trunk to default state ------------------- Dynamic Trunking Protocol DTP configs ------------------ DTP is cisco propreitary, used to auto negotiate trunk links with neighbour port S1(config-if)# switchport mode trunk S1(config-if)# switchport mode dynamic desirable S1(config-if)# switchport mode dynamic auto -----------------Disable DTP----------------- S1(config-if)# switchport nonegotiate disable DTP, Device will not engage in negotiation protocol on interface switchport mode dynamic auto Re enable DTP -----------------Troubleshoot DTP----------------- show dtp interface fe0/1 show interface fe0/1 switchport Switch#show interfaces fastEthernet 0/1 switchport | include dynamic Switch#show interfaces fastEthernet 0/1 switchport | include access Switch#show interfaces fastEthernet 0/1 switchport | include trunk show interface trunk ****************************** Native VLAN **************************** The Native VLAN is the one VLAN on a trunk port which is allowed to remain untagged. By default, this is set to VLAN 1, but this can be changed by an administrator. Native VLAN is a VLAN service specifically designed to support devices that do not possess native VLAN tagging capabilities. Unlike other VLANs, the native VLAN does not carry a tag in the network, making it easily understandable by older devices. if a packet is received on a dot1q link, that does not have vlan tagged, it is assumed that it is belonged to native vlan. dot1q iss an IEEE open standard. that defines a trunk port a packet travel without a tag is assigned to an 802.1q trunk port Multiple Native VLANs can be configured on a switch but each on different Trunk Port Use scenarios: 1. can be used where multiple VLANs are configured and also an HUB is used on one of the the switches switch(config)# vlan 999 switch(config-vlan)# end switch(config)# interface fe 0/3 switch(config-if-range)# switchport mode trunk switch(config-if-range)# switchport trunk native vlan 999 switch#sh interfaces trunk to show native vlan and trunk information switch#sh interfaces fe 0/3 switchport *********************** (Extended vlans or 12-bits VLANs by VTP(cisco proprietery)) ************************* creating vlan above 1024 Extended range VLAN must be created in the configuration mode and not from the vlan database mode. Enable the extended-system ID feature on chassis that support 1024 MAC addresses: Switch#show spanning-tree summary Switch(config)#spanning-tree extend system-id *VTP does not propagate configuration information for extended-range VLANs (VLAN numbers 1006 to 4094). Hence, configure extended-range VLANs manually. *VTP should be in transparent or off mode Switch(config)#vtp mode transparent Now create the extended range VLAN: Switch(config)#vlan vlan-id ******************************************* VTP ******************************************** VTP modes 1. off 2. server 3. client 4. transparent VTP versions a. ver 2 b. ver 3 ------------------- VTP ver 3 Supports ------------------- a. extended vlans b. SERVER needed to be configured as PRIMARY server c. only primary server ables to configure and advertise VLANs d. 12-bits VLANs are advertised also i.e extended vlans e. private VLANS are also supported in server mode as well not only in transparent mode f. can be disabled globally or interface level g. encrypted password is supported ***************************** VTP ver 2 as a SERVER *************************** * Default mode * By Default every switch is SERVER * SERVER switch stores vlan information in its NVRAM * VLAN information is shared over trunk links only * SERVER also updates the other SERVERS in network * sends as well as forwards information to other severs and clients * Read and write previlliges * 10-bits VLANs are advertised only ---------Configurations---------- switch#conf t switch(config)#vtp domain ABCD switch(config)#vtp mode server switch(config)#vtp password cisco123 switch(config)#vtp version 2 switch(config)#do show vtp status switch#show vtp password switch(config)#vlan 10 switch(config)#vlan 20 switch(config)#vlan 30 switch(config)#do show vtp status switch(config)#do show vlan ***************************** VTP ver 2 as CLIENT ***************************** * not default mode * need to config as client * does not store vlan info, synch to server for vlan info * VLAN info receive from trunk links * receives and forward VLAN info to other switches * read only previlliages ---------Configurations---------- switch(config)#vtp mode client switch(config)#vtp domain ABCD switch(config)#vtp password cisco123 switch(config)#vtp version 2 switch(config)#do show vtp status switch(config)#do show vlan **************************** VTP ver 2 in Transparent mode ********************** topology: SERVER SW----->>>TRANSPARENT SW-------->>>>CLIENT SW * same as SERVER * only difference is that it does not SYNCH VLAN info from any SERVER or CLIENT * it only passes on the VLAN advertisements from SERVERS to CLIENTS * only configured when a. intended to do not share or receive any VLAN info b. intended to create extended VLANs. i.e 12-bits VLANs switch(config)#vtp domain ABCD switch(config)#vtp mode transparent switch(config)#vtp password cisco123 switch(config)#vtp version 2 ------------------- changing configuration revision number------------------- it is highly necessary to set config revision no to 0 before adding a new switch to network running VTP configuration revision no is checked by switch#show vtp status switch#delete vlan.dat switch#reload or swicth#erase startup-config switch#reload or change the new switch to transparent mode and back to client. because the in transparent mode the revision no is always 0. ***************************** Private VLANs **************************** only supported in VTP Transparent mode 1. primary 2. secondary a. isolated b. community ports modes 1. promiscious 2. host switch(config)#vlan 10 switch(config)#int range fastethernet 0/1 - 3,4,5,6,7 switch(config-if)#switchport mode access switch(config-if)#switchport access vlan 10 switch#vtp mode transparent switch(config)#vlan 10 switch(config-vlan)#private-vlan primary switch(config)#vlan 100 switch(config-vlan)#private-vlan community switch(config)#vlan 200 switch(config-vlan)#private-vlan community switch(config)#vlan 500 switch(config-vlan)#private-vlan isolated switch(config)#vlan 10 switch(config-vlan)#private-vlan association add 100,200,500 switch#sh vlan private-vlan switch(config)#int fa0/7 switch(config-if)#switchport mode private-vlan promiscious switch(config-if)#switchport private-vlan mapping 10 100,200,500 switch(config)#int range fa0/1 - 2 switch(config-if)#switchport mode private-vlan host switch(config)#int fa0/3 - 4 switch(config-if)#switchport mode private-vlan host switch(config-if)#switchport private-vlan host association 10 200 switch(config)#int range fa0/5 - 6 switch(config-if)#switchport mode private-vlan host switch(config-if)#switchport private-vlan host association 10 500 switch#sh vlan private-vlan ************************************ inter vlan routing IVR ************************************** router on stick method sub interfaces on single physical router inter-vlan router using different interface for each VLAN on separate single physical router method (Legacy IVR method) Multi layer switch No physical interface is used instead virtual interfaces used. --------------------------------------- router on stick method --------------------------------------- This is an acceptable solution for a small to medium-sized network. this practical inludes one router two switches -----------------Switch S1 configs----------------- S1(config)# vlan 10 S1(config-vlan)# name LAN10 S1(config)# vlan 20 S1(config-vlan)# name LAN20 S1(config)# vlan 99 S1(config-vlan)# name Management S1(config)#int range fa0/2-5 S1(config-if-range)#switchport mode access S1(config-if-range)#switchport access vlan 10 S1(config)#int range fa0/6-10 S1(config-if-range)#switchport mode access S1(config-if-range)#switchport access vlan 20 S1(config)# interface vlan 99 S1(config-if)# ip add 192.168.99.2 255.255.255.0 S1(config-if)# no shut S1(config-if)# exit S1(config)# ip default-gateway 192.168.99.1 configure trunk on switch port connected between two switches on both sides S1(config)#int fa0/1 port conected to S2 Fa0/1 S1(config-if)#switchport mode trunk -----------------Switch S2 configs----------------- S2(config)# vlan 10 S2(config-vlan)# name LAN10 S2(config)# vlan 20 S2(config-vlan)# name LAN20 S2(config)# vlan 99 S2(config-vlan)# name Management S2(config)# interface vlan 99 S2(config)#int range fa0/2-5 S2(config-if-range)#switchport mode access S2(config-if-range)#switchport access vlan 10 S2(config)#int range fa0/6-10 S2(config-if-range)#switchport mode access S2(config-if-range)#switchport access vlan 20 configure trunk on switch port connected between two switches on both sides S2(config)#int fa0/11 port conected to S1 Fa0/1 S2(config-if)#switchport mode trunk S2(config)#int fa0/12 port conected to R1 gig0/0 S2(config-if)#switchport mode trunk S2(config)#int vlan 99 S2(config-if)# ip add 192.168.99.3 255.255.255.0 S2(config-if)# no shut S2(config-if)# exit S2(config)# ip default-gateway 192.168.99.1 configure trunk on switch port connected between router and switch1 S2(config)#int fa0/11 S2(config-if)#switchport mode trunk -----------------Router R1 configs----------------- R1(config)# interface gig0/0 R1(config)# interface gig0/0.10 R1(config-subif)#encapsulation dot1Q 10(it is vlan) R1(config-subif)#ip address 192.168.10.1 255.255.255.0 Default Gateway for VLAN 10 R1(config)# interface gig0/0.20 R1(config-subif)#encapsulation dot1Q 20(it is vlan) R1(config-subif)#ip address 192.168.20.1 255.255.255.0 Default Gateway for VLAN 20 R1(config)# interface gig0/0.99 R1(config-subif)# description Default Gateway for VLAN 99 R1(config-subif)# encapsulation dot1Q 99 R1(config-subif)# ip add 192.168.99.1 255.255.255.0 R1(config-subif)# exit verify with ping and tracert --------------------------------------- MLS-Multi Layer Switch --------------------------------------- This is the most scalable solution for medium to large organizations. switch(config)# vlan 10 switch(config)# vlan 20 s1(config)#int range fa0/1 - 2 s1(config-if-range)#switchport mode access s1(config-if-range)#switchport access vlan 10 s1(config)#int range fa0/3 - 4 s1(config-if-range)#switchport mode access s1(config-if-range)#switchport access vlan 20 now configure SVI (Switch Virtual Interface) s1(config)#int vlan 10 s1(config-if)#ip address 192.168.10.100 255.255.255.0 s1(config)#int vlan 20 s1(config-if)#ip address 192.168.20.100 255.255.255.0 s1(config)#do show ip int brief s1(config)#ip routing s1(config)#do show ip route verify with ping and tracert **************************** VOICE VLANs **************************** switch(config)# vlan 5 switch(config-vlan)# name DATA switch(config)# vlan 15 switch(config-vlan)# name VOICE ------------------- in case of pc connected through IP Phone ------------------- CDP should be enabled on switch SW1(config)#interface Fa0/1 SW1(config-if)#switchport access vlan 5 SW1(config-if)#switchport voice vlan 15 switch(config)# vlan 15 switch(config-vlan)#mls qos trust cos enable QoS in voice VLAN ------------------- in case of IP Phone directly connected to switch ------------------- switch(config)#int fa0/1 switch(config-if)#switchport mode access switch(config-if)#switchport voice-vlan 15 switch(config)# vlan 15 switch(config-vlan)#mls qos trust cos enable QoS in voice VLAN ************************ deleting vlan *********************** switch#delete vlan.dat delete all vlans switch#confirmation........yes switch#write......yes or Switch#vlan database switch(vlan)#no vlan vlan-id delete selected vlans in vlan database mode (database mode disabled in some switches) Switch(vlan)#apply ---------in case of database mode disabled, global configuration mode is used to create an ddeleet vlans------------- Switch(config)#vlan 10 create vlan Switch(config)#no vlan 10 delete vlan ******************** Renaming vlans ******************** Switch(config)#vlan 20 Switch(config-vlan)#name adil ******************** Allow data of specific VLANs on trunk interfaces ******************** For 3560 Multilayer Switch, you must first set the trunk encapsulation type, like this: Switch(config-if)#switchport trunk encapsulation dot1q Switch(config)#int fa0/23 Switch(config-if)#switchport mode trunk Switch(config-if)#switchport trunk allowed vlan 10 ********************VLANs Troubleshooting******************** show vlan show vlan brief show vlan summary show vlan private-vlan show vlan brief show interfaces vlan 20 show interface trunk ___________________________________________________________________________________________________________________ <<<<<<<<<<<<<<<<<<<<<<<<< How to set duplex mode >>>>>>>>>>>>>>>>>>>>>>>>> Switch automatically adjust duplex mode depending upon remote device. We could change this mode with any of other supported mode. For example to force switch to use full duplex mode use Switch(config)# #interface fastethernet 0/1 Switch(config-if)#duplex full To use half duplex use Switch(config)# #interface fastethernet 0/1 Switch(config-if)#duplex half ************* Cisco Switch Port Configuration ************** Enter global configuration mode. S1# configure terminal Enter interface configuration mode. S1(config)# interface fastethernet 0/1 Configure the interface duplex mode. S1(config-if)# duplex full Configure the interface speed. S1(config-if)# speed 100 *************Cisco Switch Auto-MDIX Commands*************** Enter global configuration mode. S1# configure terminal Enter interface configuration mode. S1(config)# interface fastethernet 0/1 Configure the interface to automatically negotiate the duplex mode with the connected device. S1(config-if)# duplex auto Configure the interface to automatically negotiate speed with the connected device. S1(config-if)# speed auto Enable auto-MDIX on the interface. S1(config-if)# mdix auto **************** Support Third Party fiber SFPs on cisco switch( getting out of err disable mode ) or Loopback test on SFP & Ethernet ***************** 2 . Some SPFs need configuration and actions to be able to work in a Catalyst 3850 switch (mostly when they are manufactured by third-party). Try following actions: 3850(config)# no errdisable detect cause gbic-invalid 3850(config)# service unsupported-transceiver Remove SFP module, shutdown/no shutdown the port, insert back the SFP module. When entering the service unsupported-transceiver command, the switch will automatically throw a warning message as a last hope to prevent the usage of a 3rd party SFP. The no errdisable detect cause gbic-invalid command will help ensure the GBIC port is not disabled when inserting an invalid GIBC. Since the service unsupported-transceiver is undocumented, if you try searching for the command with the usual method (?), you won't find it: 3850(config-if)#no keep alive 3850(config)#no errdisable detect cause loopback any port will not go on error disable on loopback test Switch#show interfaces gigabitEthernet 2/0/1 status show interface speed and duplex **************** SFP & Optical Configs & Troubleshooting ***************** Switch#show interfaces transceiver Switch#show interfaces transceiver detail show interfaces Gi0/1/0 transceiver show interfaces Gi0/1/0 transceiver detail show interfaces Gi0/1/0 transceiver properties ----------------- DOM/DDM Support ----------------- SFP must be Complaint with Below Technologies to Show Parameters Digital Diagnostic Monitoring DDM Digital optical monitoring DOM ---------------- SFP vs eSFP & DOM/DDM Support ----------------- Compared with SFP, eSFP has added function. e.g. eSFP supports the monitoring of optical power, but traditional SFP optical module does not support it. ---------------- What is UNI/NNI interface types----------------- Network-to-Network Interface (NNI) User-to-Network Interface (UNI) Enhanced Network Interface (ENI) UNI/NNI is the classification of port types designed for the Metro Ethernet market. By labeling each port as UNI or NNI, the software can optimize each port for its role. NNI, Network Node Interface, is the interface that faces the service provider network. NNI can Talk with NNI and UNI port --> its similar like Private VLANS. NNI port will always be your Trunk or uplink port, it can also be your access port as well. NNI and Trunk ports are almost similar. UNI, User Network Interface, is the interface that faces the subscriber, UNI Cannot Talk with UNI Port --Either its Access or Trunk. Users from UNI to UNI cannot talk, its like Access with protected In UNI port you will connect your customers, and most probably it will be Access port. In NNI port you will connect your uplink, and most probably it will be your Trunk port or could be your access port. UNI port will not run STP as well as CDP and LCP. ---------------------------------- Copper Ports Ethernet Loop -------------------------------- ==================== CISCO (IOS / IOS-XE) ==================== ! 100M / 1G Copper (FastEthernet / GigabitEthernet) conf t interface gi0/0 no shutdown speed auto duplex auto negotiation auto exit ! Or force link (use if auto does not come up) conf t interface gi0/0 no shutdown speed 1000 duplex full exit ! 10G RJ-45 (10GBASE-T) conf t interface ten1/0/1 no shutdown speed auto negotiation auto exit ! Verify show interfaces gi0/0 show controllers ethernet-controller gi0/0 phy <<<<<<<<<<<<<<<<<<<<<< Power Commands >>>>>>>>>>>>>>>>>>>>>> reload restart a switch or router reload in 6 schedule reload in 6 minutes reload cancel cancel a scheduled reload show environment status Switch#show facility-alarm status Switch(config)#power-supply dual Cat9300 standalone switch: conf t power supply 1 slot a off power supply 1 slot b off Cat9300 two switch stack: conf t power supply 1 slot a off power supply 1 slot b off power supply 2 slot a off power supply 2 slot b off <<<<<<<<<<<<<<<<<<<<<< Power Over Ethernet (PoE) >>>>>>>>>>>>>>>>>>>>>> PoE 802.3af 15.4W 2 Pairs Power PoE+ 802.3at 30W 2 Pairs Power UPoE cisco proprietary 60W 4 Pairs Power UPoE+ cisco proprietary 90W 4 Pairs Power Cisco PoE Features: Fast PoE Provides power to end devices more quicker like in 25 seconds etc when switch is hot or cold start perpetual PoE devices do not power cycle (off then on again) while switch reboots switch9300(config)#int twoGigabitEthernet 1/0/5 switch9300(config-if)#power inline port perpetual-poe-ha Perpetual PoE (Power NOT interrupted during switch reload) switch9300(config-if)#power inline port poe-ha Fast PoE (Device boots immediately after switch power restore) Switch(config-if)#power inline auto Switch detects PD (Powered Device) and supplies power automatically. Switch(config-if)#power inline never never supply power interface TwoGigabitEthernet1/0/5 Set PoE Power Limit (Value is in milliwatts) power inline static max 30000 interface TwoGigabitEthernet1/0/5 Set Power Priority - Used when power budget is exceeded. power inline priority high ---------------- PoE Troubleshooting ----------------- switch9300(config)#show power inline show power inline FastEthernet 1/5 show power inline consumption Show Power Supply & Budget show environment power show controllers power inline Check if device detected correctly show logging | include Ieee|POWER|inline See PoE errors (overload, fault, short) <<<<<<<<<<<<<<<<<<<<<<<<<<<< stacking switches power >>>>>>>>>>>>>>>>>>>>>>>>>>> priority values 1-9 switches 10-18 high priority ports (PoE ports) 19-27 low priority ports (PoE ports that will shutdown first in case of power failure) max no of switches to be stacked for power = 3 switch(config)#stack-power stack STACKNAME mode power shared switch(config)#stack-power switch 1 switch(config)#stack STACKNAME switch(config)#power-priority switch 1 switch(config)#power-priority high 10 switch(config)#power-priority low 19 switch2(config)#stack-power switch 2 switch2(config)#stack STACKNAME switch2(config)#power-priority switch 2 switch2(config)#power-priority high 11 switch2(config)#power-priority low 20 switch3(config)#stack-power switch 3 switch3(config)#stack STACKNAME switch3(config)#power-priority switch 3 switch3(config)#power-priority high 12 switch3(config)#power-priority low 21 switch4(config)#stack-power switch 4 switch4(config)#stack STACKNAME switch4(config)#power-priority switch 4 switch4(config)#power-priority high 13 switch4(config)#power-priority low 22 -------------------Stacking Power Troubleshooting------------------ switch#show switch switch#show switch stack-ports switch#show switch stack-ring speed switch#show switch stack-power switch#show switch stack-power budgeting switch#show switch stack-power detail switch#show switch stack-power neighbours switch#show switch stack-power load-shedding ------------------ remove switch form stack ------------------ switch#show switch switch#no switch SWITCH_NO_IN_STACK provision ******************************** switch stacking for DATA *********************************** Stack swicthes conneced to each other via special stacking cable and module Cluster more than one stack in a network max no of switches in a stack = 8 switches are connected in Daisy-chain fashion switch in stack will set as master on the basis of a. MAC Address.........swicth with lower MAC address will be Slave b. switch priority.....higher priority switch will be master switch priority value <1-15> By default: priority is always set to 1 and switch will be elected as master on basis of MAC address s1(config)#switch 1 priority 15 s1(config)#switch 2 priority 14 s1#wr mem s1#reload s1(config)#switch 1 renumber NEW_SWICTH_NO change switch number in stack -------------------Stacking Troubleshooting------------------ switch#show switch switch#show switch stack-ports switch#show switch stack-ring speed switch#show platform summary of stacked switches show power supply slot X hw-module beacon slot X on ------------------ remove switch form stack ------------------ switch#show switch switch#no switch SWITCH_NO_IN_STACK provision <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< UID (Unit Identifier) button / LED >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> 🖥️ 1. Cisco Catalyst Switch (9300/9400/9500) Catalyst switches don’t call it “UID”, they call it Beacon LED. hw-module beacon slot 1 on Turn ON locator LED hw-module beacon slot 1 off Turn OFF locator LED show environment leds Check status On standalone C9300/C9500 → turns on LED for the entire switch On stack → turns on LED for that specific stack member 🧱 2. Cisco UCS Server (CIMC) Turn ON UID LED scope chassis set locator-led on commit Turn OFF set locator-led off commit <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< DHCP snooping >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> Parameters | Default ---------------------------------------------------------------- DHCP snooping feature | Disabled DHCP snooping globally enabled | No DHCP snooping VLAN | None DHCP snooping MAC address verification | Enabled DHCP snooping option-82 support | Disabled DHCP snooping trust | Untrusted DHCP snooping relay agent | Disabled DHCP snooping option-82 for relay agent Disabled DHCP server IP address | None switch(config)#feature dhcp show running-config dhcp switch(config)#no feature dhcp to disable dhcp snooping show ip dhcp snooping show running-config dhcp ************** dhcp snooping globally ************** switch(config)#ip dhcp snooping show running-config dhcp switch(config)#no ip dhcp snooping to disable dhcp snooping globally switch(config)# show running-config dhcp show ip dhcp snooping **************** DHCP Snooping on a VLAN *************** switch(config)# ip dhcp snooping vlan 100,200,250-252 switch(config)#no ip dhcp snooping vlan 100,200,250-252.......disable show ip dhcp snooping ******************* DHCP Snooping MAC Address Verification ************** switch(config)# ip dhcp snooping verify mac-address switch(config)# no ip dhcp snooping verify mac-address.......disable show ip dhcp snooping **************** Option-82 Data Insertion and Removal *************** switch(config)# ip dhcp snooping information option switch(config)# no ip dhcp snooping information option show ip dhcp snooping ****************** Interface as Trusted or Untrusted ***************** You can configure DHCP trust on the following types of interfaces: Layer 2 Ethernet interfaces Layer 2 port-channel interfaces 1. config t 2. interface ethernet slot/port interface port-channel channel-number 3. [no] ip dhcp snooping trust 4. show running-config dhcp show ip dhcp snooping <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Port security against MAC Flooding and as well as MAC spoofing >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> MAC spoofing is a Man In Middle Attack to enable port security the port shoould be access or trunk 1) To enable port security, use following commands s1(config)#show port-security s1(config)#interface gigabitethernet 0/0 s1(config-if)#switchport mode access or trunk if applicable s1(config-if)#switchport port-security 2) To specify maximum number of MAC addresses allowed on an interface, use following commands s1#clear mac-address table s1(config)#interface gigabitethernet 0/0 s1(config-if)#switchport mode access or trunk if applicable s1(config-if)#switchport port-security maximum 5 3) To define the MAC addresses of known secure devices statically, use following commands s1(config)#interface gigabitethernet 0/0 s1(config-if)#switchport mode access or trunk if applicable s1(config-if)#switchport port-security maximum 2 s1(config-if)#switchport port-security mac-address aaa.bbb.ccc s1(config-if)#switchport port-security mac-address aaa.bbb.ddd or s1(config-if)#switchport port-security mac-address sticky 4) To define the action required when a Port Security violation happened, use following commands s1(config)#interface gigabitethernet 0/0 s1(config-if)#switchport mode access or trunk if applicable s1(config-if)#switchport port-security violation shutdown or protect or restrict We can use the "show interface , as shown below to confirm the port is in Errdisable state. s1#show interfaces gigabitethernet 0/0 GigabitEthernet0/0 is down, line protocol is down (err-disabled) How to view the secure known MAC addresses configured for Port Security s1#show port-security address How to view the Port Security related settings of an interface s1#show port-security interface gigabitethernet 0/0 ------------Remove Port Sceurity--------------- s1(config)#interface gigabitethernet 0/0 s1(config-if)#no switchport port-security -----------Clear port-security Learnt MAC Addresses------------ s1(config)#clear port-security all or configured, dynamic or sticky <<<<<<<<<<<<<<<<<<<<<<<<<<<< Wide Area Network (WAN) connectivity >>>>>>>>>>>>>>>>>>>>>>>>>>>> <<<<<<<<<<<<<<<<<<<<<< WAN Protocols, virtaul Private Networks VPNs & Tunnels >>>>>>>>>>>>>>>>>>>>>> Accessing private network of the Public Network Client to Gateway Remote Access VPN Remote users get access to their organization network Gateway to Gateway Site to Site VPN two offices of an organization are connected to each other 1. MPLS: industry standard a. IP-MPLS b. MPLS-TP Multi protocol Label Switching-Transport Profile MPLS is a protocol which is used to improve forwarding speed of routers. used to exchange paths by eliminating IP complex function & Routing PR/LSR provider Router/Label Switched Router PE/LER provider Edge Router/Label Edge Router CE customer Edge Router MPLS-TP is a set of MPLS protocols that are being defined in IETF & ITU-T predictable traffic path MPLS-TP = MPLS + OAM - IP IP MPLS ATM Control Plane Connectionless Connection-oriented Forwarding Plane Connection-oriented Connection-oriented It is a simplified version of MPLS for transport networks with some of the MPLS functions turned off, such as Penultimate Hop Popping (PHP), Label-Switched Paths (LSPs) merge, and Equal Cost Multi Path (ECMP). Features MPLS MPLS-TP Penultimate Hop Popping (PHP) Yes - Label-Switched Paths (LSPs) merge Yes - Equal Cost Multi Path (ECMP) Yes - MPLS/PWE Architecture Yes Yes Label Forwarding Yes Yes Dynamic Control Plane Yes Yes Determnism - Yes Static Congruent Paths - Yes OAM - Yes c. MPLS TE Multi protocol Label Switching-Traffic Engineering 2. ATM A-synchronous Tranfer Module industry standard 3. frame relay industry standard 4. HDLC high level data link control protocol cisco prop 5. PPP point to point protocol industry standard ******************* Client VPN Application Softwares ******************* Wireguard ******************* Tunneling Protocol ******************* PPTP Point to Point Tunneling Protocol L2TP Layer 2 Tunneling Protocol SSTP Secure Socket Tunneling Protocol IPSec Internet Protocol Security unicast traffic is secured only not multicast nor Broadcast GRE Generic Routing Tunnel cisco Proprietary L2 VPN L2TP L3 VPN IPSec, GRE, BGP/MPLS VPN Features L2VPN L3VPN Security High Low Support for Layer 3 protocols Relatively flexible Limited Network user impact on the backbone network Little Great Compatibility with traditional WANs Good Poor Route management Users manage their own routes SPs manage the routes. Networking application Mainly at access & aggregation layer Mainly at the core layer In MPLS Layer 2 tunnel connection the private network messages of users are transmitted from one end CE to the other end CE, and the PE devices and P devices in the MPLS network do not keep any Layer 2 and Layer 3 information of users' networks. MPLS L3VPN, the PE device of the MPLS network needs to keep the Layer 3 routing information of the user, and for the private network messages of the user, it needs to look up the private network routing table on the PE device before it can forward them. ************************* HDLC ************************* Default same encapsulation should be on both side routers configs: r1#sh int se0/0 r1#sh ip int br ************************** PPP configs *************************** PPP Authentications PAP password authentication protocol CHAP challenge handshake authentication protocol ******************** CHAP configs: ******************** data is sent in a handshake format or encrypted unlike pap r1 configs: host name should be exact as remote host i.e r2 password should be same on both hosts create username for authentication on LOCAL HOST r1(config)#username NAME_OF REMOTE_HOST password PASSWORD........host name should be exact as remote host,aslo case sensitive i.e r2 r1(config)#int se0/0 r1(config-if)#encapsulation ppp r1(config-if)#ppp authentication chap r1(config-if)#exit r1(config)# r1(config)#debug ppp authentication r1#sh int se0/0 r1#sh ip int br r2 configs: host name should be exact as remote host i.e r1 password should be same on both hosts create username for authentication on REMOTE HOST r2(config)#username NAME_OF REMOTE_HOST password PASSWORD........host name should be exact as remote host i.e r1 r2(config)#int se0/0 r2(config-if)#encapsulation ppp r2(config-if)#ppp authentication chap r2(config-if)#exit r2(config)# r2(config)#debug ppp authentication r1#sh int se0/0 r1#sh ip int br -------------------- remove CHAP authentications ----------------------- r2(config)#int se0/0 r2(config-if)#no ppp authentication chap ********************************** PAP configs ************************************* data is sent in clear text host name should be exact as remote host also case sensitive i.e r2 password should be same on both hosts r1 configs: r1(config)#username NAME_OF REMOTE_HOST password PASSWORD r1(config)#int se0/0 r1(config-if)#encapsulation ppp r1(config-if)#ppp authentication pap r1(config-if)#ppp pap sent username r1 password PASSWORD..............username must be of local host r1(config-if)#exit r1(config)# r2(config)#debug ppp authentication r1#sh int se0/0 r1#sh ip int br host name should be exact as remote host also case sensitive i.e r1 password should be same on both hosts r2 configs: r2(config)#username NAME_OF REMOTE_HOST password PASSWORD r2(config)#int se0/0 r2(config-if)#encapsulation ppp r2(config-if)#ppp authentication pap r2(config-if)#ppp pap sent username r2 password PASSWORD.................username must be of local host r2(config)#debug ppp authentication r1#sh int se0/0 r1#sh ip int br ------------------------ remove PAP authentications ---------------------- r2(config)#int se0/0 r2(config-if)#no ppp authentication pap <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Frame Relay configs >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> LMI Local Management Interface, a signaling standard which is used between DCE and DTE connections in Frame relay a signaling standard which is used between Frame Relay Switch and Frame Relay Router in Frame relay 3 LMI stanadrds used: Cisco ANSI ITU-Q933A DLCI Data link connection identifier, a uniwue indentifier represented in numbers L2 Tech like L2 Ethernet Technology, Broadcast Multiple Access NBMA non broadcast multi access unlike BMA in ethernet DLCI Data link Connection Identifier, addressing scheme (number to identify connection) like MAC address in Ethernet Three Pre Requisite for Frame Relay Switch Router need to be configured as Switch Frame-Relay switching, no ip address commands are used No IP adress should be DCE manually configure Swicth Table Two Methods: Point to Point PtP Point to Multi point P2MP ******************************** Frame Relay Point to Point P2P Configs ****************************** -------------------------------Frame Relay P2P Topology 1-------------------------------- ------------------------Ring Topology Daisy chain pattern---------------------- AC Actual Circuit VC Virtual Circuit VC1 R1 * * * * * * * * * * * * * * R2 * * * * * * AC1 AC2* * * * FRSW * * VC2 * * * VC3 * * AC3 * * * * * * * R3 -------------Cloud Router Configuration------------- FRSW(config)#frame Relay switching FRSW(config)#int se0/0 FRSW(config-if)#no shutdown FRSW(config-if)#encapsulation frame-relay FRSW(config-if)#frame-relay lmi-type cisco FRSW(config-if)#frame-relay intf-type dce FRSW(config-if)#clock-rate 64000 FRSW(config-if)#frame-relay route 100{DLCI value} int se0/1 200{DLCI value} FRSW(config)#int se0/0 FRSW(config-if)#no shutdown FRSW(config-if)#encapsulation frame-relay FRSW(config-if)#frame-relay intf-type dce FRSW(config-if)#frame-relay route 200{DLCI value} int se0/0 100{DLCI value} -------------Edge Routers Configuration------------- R1 int se0/0.2 DLCI 103 20.0.0.1/8 <<<* * R1 int se0/0.1 DLCI 102 10.0.0.1/8 * R2 int se0/0.2 DLCI 201 10.0.0.2/8 * * R2 int se0/0.1 DLCI 203 30.0.0.1/8 * R3 int se0/0.2 DLCI 302 30.0.0.2/8 * * R3 int se0/0.1 DLCI 301 20.0.0.2/8 >>>* R1 int fa0/0 - 192.168.10.1/24 -------Branch 1 LAN R2 int fa0/0 - 192.168.20.1/24 -------Branch 2 LAN R3 int fa0/0 - 192.168.30.1/24 -------Branch 3 LAN do configuration on all three routers according to given topolgy R1(config)#int se0/0 R1(config-if)#encapsulation frame-relay R1(config-if)#frame-relay lmi-type cisco R1(config)#int se0/0.1 point to point R1(config-if)#no shut R1(config-subif)#frame-relay interface-dlci {DLCI value} configure DLCI according to design R1(config-if)#ip address 10.0.0.1 255.0.0.0 R1(config)#int se0/0.2 point to point R1(config-if)#no shut R1(config-subif)#frame-relay interface-dlci {DLCI value} configure DLCI according to design R1(config-if)#ip address 20.0.0.1 255.0.0.0 R1(config)#interface fastEthernet 0/0 R1(config-if)#no shutdown R1(config-if)#ip address 192.168.10.1 255.255.255.0 --------configure routing---------- R1(config)#router rip R1(config-router)#network 192.168.10.0 R1(config-router)#network 10.0.0.0 R1(config-router)#network 20.0.0.0 do routing on other routers also -----------------------------------------Frame Relay P2P Topology 2------------------------------------------- R1------>>>>>>> --------------- { se0/0 ----Frame Relay ISP Switch ---- se0/1 } ---------->>>>>>>>> R2 r1(config)#int se0/0 r1(config-if)#no shutdown r1(config-if)#ip address 10.0.0.1 255.0.0.0 r1(config-if)#encapsulation frame-relay r1(config)#interface serial 0/0 point-to-point same config on R2 with different IP but same Subnet ******************************* Frame Relay Point to Multi Point P2MP Configs******************************** -------------------------------Frame Relay P2P Topology 1-------------------------------- ------------------------Ring Topology-Daisy chain pattern---------------------- AC Actual Circuit VC Virtual Circuit VC1 R1 * * * * * * * * * * * * * * R2 * * * * * * AC1 AC2* * * * FRSW * * VC2 * * * VC3 * * AC3 * * * * * * * R3 -------------Edge Routers Configuration------------- R1 int se0/0.1 DLCI 103 10.0.0.1/8 <<<* DLCI 102 * * R2 int se0/0.1 DLCI 201 10.0.0.2/8 * DLCI 203 * * R3 int se0/0.1 DLCI 302 10.0.0.3/8 >>> * DLCI 301 R1 int fa0/0 - 192.168.10.1/24 -------Branch 1 LAN R2 int fa0/0 - 192.168.20.1/24 -------Branch 2 LAN R3 int fa0/0 - 192.168.30.1/24 -------Branch 3 LAN R1(config)#interface serial 0/0 R1(config-if)#no shut R1(config-if)#encapsulation frame-relay R1(config-if)#frame-relay lmi-type cisco R1(config)#interface serial 0/0.1 R1(config-if)#no shut R1(config-subif)#frame-relayinterface-dlci 102 R1(config-subif)#frame-relayinterface-dlci 103 R1(config-if)#ip address 10.0.0.1 255.0.0.0 R1(config)#interface fa 0/0 R1(config-if)#no shut R1(config-if)#ip address 192.168.10.1 255.255.255.0 R1(config)#router EIGRP 100 R1(config-router)#network 192.168.10.0 R1(config-router)#network 10.0.0.0 do routing on other routers also ------------------------------Removing Frame Relay Configs---------------------------- R3(config)#no router rip R3(config)#interface serial 0/0 R3(config-if)#no frame-relay lmi-type cisco R3(config-if)#no encapsulation R3(config-if)#no frame-relay interface-dlci {DLCI value} R3(config)#interface serial 0/0.1 R3(config-if)#no frame-relay interface-dlci {DLCI value} R3(config-if)#no ip address R3(config)#no interface se0/0.1 R3(config)#no interface se0/0.2 ------------------------------Troubleshooting Frame Relay Configs---------------------------- show frame relay lmi show frame relay pvc (permanent virtual circuit) show frame relay map ******************* Generic Routing Tunnel (GRE) ******************* used to create Tunnel between two remote sites Like VPN cisco Proprietary Generic Routing Encapsulation Encapsulate a wide variety of Network layer protocols Like IP, IPX, Apple Talk Virtual point-to-point links over Internetwork No security Provided normally IPSec is used to provide security for this purpose GRE tunnel is encapsulated in IPSec Tunnel topology: R1------------>>>>>R2--------->>>R3--------->>>>R4 after configuring IP addresses on all routers and also any Routing method configure GRE on R1 and R4 by creating tunnel interface on both Routers and Tunnel IP address also ---------------Local Router Configs i.e R1 --------------- R1(config)#interface tunnel 10{tunnel number any} R1(config-if)#ip address 192.168.10.1 255.255.255.0 R1(config-if)#tunnel source gigabitEthernet 0/0/0 local end WAN interface on ISP provided Router on R1 R1(config-if)#tunnel destination 30.0.0.2 Far end ISP router, customer facing Interface IP on R4 --------------Remote ISP end Router Configs i.e R4 --------------- R4(config)#interface tunnel 10{tunnel number same on R1} R4(config-if)#ip address 192.168.10.1 255.255.255.0 R4(config-if)#tunnel source gigabitEthernet 0/0/0 Far end ISP router, customer facing Interface on R4 R4(config-if)#tunnel destination 10.0.0.1 WAN interface IP on Customer Router R1 ---------------Troubleshooting & Testing --------------- sh ip int br sh ip route sh run ping ping IP repeat ANY_NUMBER(1000000) traceroute ---------------Removing Tunnel Interface --------------- R1(config)#no interface Tunnel 10{tunnel number} ---------------Removing Tunnel source and destination on Tunnel Interface --------------- R4(config)#interface tunnel 10{tunnel number} R4(config-if)#no tunnel source R4(config-if)#no tunnel destination R4(config-if)#no tunnel mode ************************* Internet Protocol Security IPSec VPN ************************* Provide Authentications Provide encryption Creates L3 VPN Tunnel ISAKMP IKE Phase 1 internet security association Key Management Protocol IPSec IKE Phase 2 encryption MD5, SHA authentication PSK, RSA encoding DES, 3DES, AES, SEAL encapsulation AH, ESP To achieve the goal of creating a secure tunnel, two peers needs to negotiate all the required parameters IPSec uses following protocols: Authentication Header (AH) It provides authentication and integrity Encapsulation Security Protocol (ESP) It provides authentication, integrity and confidentiality Internet Key Exchange (IKE) Key management protocol, used to negotiate Security Association (SA) --------------- Internet Key Exchange (IKE) --------------- IKE performs its jobs using ISAKMP framework using two phases --------------- Phase-1 --------------- used to negotiate ISAKMP policy by exchange 5 parameters referred to as HAGLE In this phase, Peers authenticate each other and calculate a shared secret key Phase-1 gives a secure tunnel to be used in IKE phase-2 --------------Phase-1 can run in two modes-------------- 1. Main mode identity of peers is protected using encryption 2. Aggressive mode identity of peers is not protected SA are security polices for communication between peers Five SAs to configure Hash Authentication Group Lifetime Encryption --------------- Phase-2 --------------- Phase-2 is used to negotiate IPSec security parameters [negotiate protocols and algorithm] Transform Set: Encapsulation protocol (AH, ESP) ESP Encryption, Hashing AH Hashing Tunnel mode (Transport or Tunnel) There are 5 steps to Configure IPSec VPN 1. Configure ISAKMP (Phase-1) 2. Create Extanded ACL 3. Create IPSec Transform Set 4. Create Crypto Map 5. Apply Crypto Map to Exit Interface. TOPOLOGY: LAN SIte A-------->>>>> R1------->>>>>(ISP CLOUD)-------->>>>>>>>R2-------->>>>>>LAN Site B --------------R1 Configs------------- R1(config)#crypto isakmp policy 2(AnyNumber) R1(config-isakmp) #encryption 3des encryption Ri (config-isakmp) #hash md5 R1(config-isakmp) #group 2 R1(config-isakmp) #authentication pre-share authentication R1(config-isakmp) #lifetime 86400 R1(config)#crypto isakmp key cisco123 address 1.1.1.2 Remote site (Site B) public IP address R1(config)#ip access-list extended siteA-SiteB{ACL name} R1(config-ext-nacl) #permit ip 150.1.1.0 0.0.0.255 160.1.1.0 0.0.0.255 LocalSitePrivate NetAddress & Wild card mask, RemoteSitePrivate NetAddress & Wild card mask R1(config)#crypto ipsec transform-set nespk123 esp-3des esp-md5-hmac R1(config)#crypto map NESPK 10 ipsec-isakmp R1(config-crypto-map) #set peer 1.1.1.2 Remote site (Site B) public IP address R1(config-crypto-map) #set transform-set nespk123 R1(config-crypto-map) #match address siteA-siteB{ACL name} R1(config)#interface f0/0 Local Site WAN interface R1(config-if)#crypto map NESPK --------------R2 Configs------------- R2(config)#crypto isakmp policy 2 R2(config-isakmp) #encryption 3des Ri (config-isakmp) #hash md5 R2(config-isakmp) #group 2 R2(config-isakmp) #authentication pre-share R2(config-isakmp) #lifetime 86400 R2(config)#crypto isakmp key cisco123 address 1.1.1.1 Remote site (Site A) public IP address R2(config)#ip access-list extended siteB-SiteA{ACL name} R2(config-ext-nacl) #permit ip 160.1.1.0 0.0.0.255 150.1.1.0 0.0.0.255 LocalSitePrivate NetAddress & Wild card mask, RemoteSitePrivate NetAddress & Wild card mask R2(config)#crypto ipsec transform-set nespk123 esp-3des esp-md5-hmac R2(config)#crypto map NESPK 10 ipsec-isakmp R2(config-crypto-map) #set peer 1.1.1.1 Remote site (Site A) public IP address R2(config-crypto-map) #set transform-set nespk123 R2(config-crypto-map) #match address siteB-SiteA{ACL name} R2(config)#interface f0/0 Local Site (Site B) WAN interface R2(config-if)#crypto map NESPK verify both site connectivity by ping 150.1.1.1 and 160.1.1.1 ------------IPSec Troubleshooting------------ show cypto isakmp sa show cypto isakmp policy show cypto ipsec sa to check vpn is working or not show cypto session clear crypto sa to refresh VPN Tunnel clear crypto iskamp ******************* IPSec on Cisco ASA Firewall******************* 6 Steps Step 1. enable ikev1 on outside interface Step 2. Configure ISAKMP (Phase-1) Step 3. Create Tunnel group and pre-share Step 4. Create IPSec Transform Set Step 5. Create Crypto Map Step 6. Apply Crypto Map to Exit Interface. ----------------Site-A Cisco ASA configs---------------- Site-A (config) crypto ikev1 enable outside Site-A(config)# crypto ikev1 policy 2 Site-A(config-ikev1-policy) encryption aes Site-A(config-ikev1-policy) hash sha Site-A(config-ikev1-policy) group 2 Site-A(config-ikev1-policy) authentication pre-share Site-A(config-ikev1-policy) lifetime 86400 Site-A(config)# tunnel-group 4.2.2.2 type ipsec-l2l Remote site (Site A) Site-A(config)# tunnel-group 4.2.2.2 ipsec-attributes Remote site (Site A) Site-A(config-tunnel-ipsec)# ikev1 pre-shared-key cisco123 Site-A(config)# access-list 1 extended permit ip 150.1.1.0 255.255.255.0 160.1.1.0 255.255.255.0 SourceNetAddress Subnet DestinationNetAddress Subnet R2(config)#crypto ipsec ikev1 transform-set IPSEC-VPN esp-aes esp-sha-hma Site-A(config)# crypto map site-a 10 match address 1 Site-A(config)# crypto map site-a 10 set peer 4.2.2.2 Site-A(config)# crypto map site-a 10 set ikevl transform-set ipsec-vpn Site-A(config)# crypto map site-a 10 set pfs Site-A(config)# crypto map site-a interface outside ----------------Site-B Cisco ASA configs---------------- Site-B (config) crypto ikev1 enable outside Site-B(config)# crypto ikev1 policy 2 Site-B(config-ikev1-policy) encryption aes Site-B(config-ikev1-policy) hash sha Site-B(config-ikev1-policy) group 2 Site-B(config-ikev1-policy) authentication pre-share Site-B(config-ikev1-policy) lifetime 86400 Site-B(config)# tunnel-group 4.2.2.1 type ipsec-l2l Remote site (Site A) Site-B(config)# tunnel-group 4.2.2.1 ipsec-attributes Remote site (Site A) Site-B(config-tunnel-ipsec)# ikev1 pre-shared-key cisco123 Site-B(config)# access-list 1 extended permit ip 160.1.1.0 255.255.255.0 150.1.1.0 255.255.255.0 SourceNetAddress Subnet DestinationNetAddress Subnet Site-B(config)#crypto ipsec ikev1 transform-set IPSEC-VPN esp-aes esp-sha-hma Site-B(config)# crypto map Site-b 10 match address 1 Site-B(config)# crypto map Site-b 10 set peer 4.2.2.1 Remote site IP (Site A) Site-B(config)# crypto map Site-b 10 set ikevl transform-set ipsec-vpn Site-B(config)# crypto map Site-b 10 set pfs Site-B(config)# crypto map site-b interface outside <<<<<<<<<<<<<<<<<<<<<<<<<<<< DHCP server >>>>>>>>>>>>>>>>>>>>>>>>>> R1(config)#int gigabitethernet 0/0 R1(config-if)#ip address 192.168.10.1 255.255.255.0 R1(config)#ip dhcp pool nespk R1(dhcp-config)#network 192.168.10.0 255.255.255.0 R1(dhcp-config)#default-router 192.168.10.1 R1(dhcp-config)#dns-server 8.8.8.8 R1(dhcp-config)#domain-name nespk.com R1(dhcp-config)#ip dhcp excluded-address 192.168.10.1 192.168.10.100 R1(dhcp-config)#lease 0 23 59 R1(dhcp-config)#next Server 192.168.10.60 can configured for UCM server for VoIP, for WLC for Wireless, IP Helper can also used for WLC R1(config)#int gigabitethernet 0/1 R1(config-if)#ip address 192.168.20.1 255.255.255.0 R1(config)#ip dhcp pool nespk2 R1(dhcp-config)#network 192.168.20.0 255.255.255.0 R1(dhcp-config)#default-router 192.168.20.1 R1(dhcp-config)#dns-server 8.8.8.8 R1(dhcp-config)#domain-name nespk.com R1(dhcp-config)#ip dhcp excluded-address 192.168.20.1 192.168.20.100 R1(dhcp-config)#lease 0 23 59 R1(dhcp-config)#next Server 192.168.20.60 can configured for UCM server for VoIP, for WLC for Wireless, IP Helper can also used for WLC Router# show ip dhcp binding Router# show ip dhcp pool Router# show ip dhcp server statistics *************** DHCP Relay Agent ************* Example config: no service dhcp R1(config)#int gigabitethernet 0/0 R1(config-if)#ip address 192.168.10.1 255.255.255.0 R1(config-if)# ip helper-address 192.168.50.1 DHCP_SERVER_ADDRESS Actual config: Topology: DHCP SERVER ------>>> Rtr-2 ------>>> Rtr-1 ----->>> SW-1 ----->>> PC1, PC2, PC3 ------------------- Switch configs ------------------- SW-1(config)#vlan 10 SW-1(config)#vlan 20 SW-1(config)#vlan 30 SW-1(config)#interface fastEthernet 0/1 SW-1 (config-if)#switchport mode access SW-1 (config-if)#switchport access vlan 10 SW-1 (config)#interface fastEthernet 0/2 SW-1 (config-if)#switchport mode access SW-1 (conflig-if)#switchport access vlan 20 SW-1 (config)#interface fastEthernet 0/3 SW-1 (config-if)#switchport mode access SW-1 (conflig-if)#switchport access vlan 30 SW-1 (config)#interface fastEthernet 0/4 SW-1 (config-if)#switchport mode trunk connected to Rtr-1 port gigabitEthernet 0/1 ------------------- Rtr-1 Configs ------------------- Rtr-1 (config)#interface gigabitEthernet 0/1.10 connected to SW-1 port fastEthernet 0/4 Rtr-1 (config-subif)#encapsulation dot1Q 10 Rtr-1 (config-subif)#ip address 192.168.10.1 255.255.255.0 Rtr-1(config-subif)#ip helper-address 192.168.50.100 DHCP_SERVER_ADDRESS Rtr-1 (config)#interface gigabitEthernet 0/1.20 Rtr-1 (config-subif)#encapsulation dot1Q 20 Rtr-1 (config-subif)#ip address 192.168.20.1 255.255.255.0 Rtr-1(config-subif)#ip helper-address 192.168.50.100 DHCP_SERVER_ADDRESS Rtr-1 (config)#interface gigabitEthernet 0/1.30 Rtr-1 (config-subif)#encapsulation dot1Q 30 Rtr-1 (config-subif)#ip address 192.168.30.1 255.255.255.0 Rtr-1(config-subif)#ip helper-address 192.168.50.100 DHCP_SERVER_ADDRESS also configure neccessary interconnectivity and routing on Rtr-1 and Rtr-2 ------------------- Rtr-2 Configs ------------------- Rtr-2 (config)#interface gigabitEthernet 0/1 Rtr-2 (config-if)#ip address 192.168.50.1 255.255.255.0 connected to DHCP SERVER also configure neccessary interconnectivity and routing on Rtr-1 and Rtr-2 ------------------- DHCP SERVER Configs ------------------- Pool 10 server IP=192.168.5.100 range=192.168.10.101-150 Deafult Gateway=192.168.10.1 = Rtr-1 sub interface gig 0/1.10 Pool 20 server IP=192.168.5.100 range=192.168.20.101-150 Deafult Gateway=192.168.20.1 = Rtr-1 sub interface gig 0/1.20 Pool 30 server IP=192.168.5.100 range=192.168.30.101-150 Deafult Gateway=192.168.30.1 = Rtr-1 sub interface gig 0/1.30 show running-config | dhcp <<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Internet Protocol IP Address configurations >>>>>>>>>>>>>>>>>>>>>>>>>>>>>> ****************** IPv4 configs ****************** IPv4 address: ip address ip-address subnet-mask 192.168.10.1 255.255.255.0 r1(config)#int se0/0 r1(config-if)#ip address 192.168.10.1 255.255.255.0 r1(config-if)# no shut r1(config)#int fa0/1 r1(config-if)#ip address 192.168.10.1 255.255.255.0 r1(config-if)# no shut -------------------------IPv4 /31 and /32 SUBNET configs---------------------- RFC-3021 Refference /31 subnet mask 255.255.255.254 2 addresses /32 subnet mask 255.255.255.255 1 addresses can be used with OSPF best way than the use of /30 address Because /30 wastes two extra IP addresses in terms of Net and Broadcast address Supported on cisco 7000 series Routers like 7250 7450 7750 Configured on Point-to-Point Links r1(config)#int se0/0 r1(config-if)#ip address 192.168.10.0/31 r1(config-if)# no shut r2(config)#int se0/0 r2(config-if)#ip address 192.168.10.1/31 r2(config-if)# no shut ping 192.168.10.0 S1(config)#ping IP repeat ANY_NUMBER(1000000) ping target address(x.x.x.x) source source address(x.x.x.x) sh ip route sh ip int br ****************** IPv6 configs ****************** r1(config)#ipv6 unicast-routing use this command to enable IPv6 on routers IPv6 GUA: ipv6 address ipv6-address/prefix-length IPv6 SUBNETS examples: 2001:db8:acad:1::/64 2001:db8:acad:2::/64 2001:db8:acad:3::/64 IPv6 HOSTS examples: 2001:db8:acad:1::1/64 2001:db8:acad:1::2/64 2001:db8:acad:1::3/64 2001:db8:acad:2::1/64 2001:db8:acad:2::2/64 2001:db8:acad:2::3/64 2001:db8:acad:3::1/64 2001:db8:acad:3::2/64 2001:db8:acad:3::3/64 *Note: there is no space between ipv6-address and prefix-length. -------------Some inmportant IPv6 Commands------------- r1(config-if)#ipv6 address eui-64 ipv6-prefix/prefix length or r1(config-if)#ipv6 address link-local ipv6-address or r1(config-if)#ipv6 address autoconf R1(config)#interface s0/1/0 R1(config-if)#ipv6 address fe80::3:1 link-local to configure LLA address R1(config-if)#ipv6 address 2001:db8:acad:3::1/64 to configure GUA address R1(config-if)#no shutdown r1(config-if)#ipv6 address dhcp to make a interface as an IPv6 client r1(config-if)#no ipv6 address dhcp to disable a interface as an IPv6 client ----------------------- IPv6 Route Configs ----------------------- ipv6 route ::/0 to config IPv6 static route ----------------------- Verify IPv6 ----------------------- r1(config-if)#show ipv6 dhcp interface fa0/0 ping ipv6 traceroute ipv6 ----------------------- Troubleshooting IPv6 ----------------------- show ipv6 interface GigabitEthernet 0/1 show hosts Display IPv4/IPv6 DNS server. show ipv6 interface interface-id Display IPv6 interface status and configuration. sh ipv6 int br show ipv6 neighbors Display IPv6 neighbor cache entries. show ipv6 prefix-list Display a list of IPv6 prefix lists. show ipv6 route Display the IPv6 route table entries. show ipv6 traffic Display IPv6 traffic statistics. <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Routing & Routers >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> Layers: Access 800 1000 1600 1700 2500 series Distribution 2600 3200 3600 3700 series Core 6400 7200 7300 7400 7500 7600 10K 12K series modular Fixed -------------------------------Hardware ----------------------------- *chassis/Frame/Module *Slots *Ports denoted as : 0/0, 0/1, 0/2 0/0/0, 0/0/1, 0/0/2 only one chassis more than one chassis 2-digit notation 3-digit notation digit 1 = Slot, digit 2 = Port digit 1 = chassis , digit 2 = Slot, digit 3 = Port ------------Ports/interfaces------------ Power ports WAN port: Ethernet, SFP Slots, EIA-232 serial (60 pins Female, 15 pins x 4 rows), smart serial (26 pins female) v.35 cable is used to connect ISP modem to router via Serial interface LAN port: Ethernet, SFP Slots, AUI ports (15 pin Female, TRX module used to convert AUI to Ethernet) HundredGigE hu1/0/12 TwentyFiveGigE Twe1/0/12 | Speed | Full Name | Short Form | Example | | -------- | -------------------------- | ---------- | ------------------------------------------------ | | 10 Mbps | Ethernet | e | `Ethernet0/0` | | 100 Mbps | FastEthernet | fa | `FastEthernet0/1` | | 1 Gbps | GigabitEthernet | gi | `GigabitEthernet1/0/1` | | 10 Gbps | TenGigabitEthernet | te | `TenGigabitEthernet1/0/1` | | 25 Gbps | TwentyFiveGigabitEthernet | twe | `TwentyFiveGigabitEthernet1/0/12` or `Twe1/0/12` | | 40 Gbps | FortyGigabitEthernet | fo | `FortyGigabitEthernet1/0/1` | | 100 Gbps | HundredGigabitEthernet | hu | `HundredGigabitEthernet1/0/12` or `Hu1/0/12` | | 400 Gbps | FourHundredGigabitEthernet | fh | `FourHundredGigabitEthernet1/0/1` | Slot/Port Format: // | Vendor | 1G | 10G | 25G | 40G | 100G | Example | | ----------- | -- | ---- | ---- | ----- | ----- | ------------- | | **Cisco** | Gi | Te | Twe | Fo | Hu | `Hu1/0/12` | | **Huawei** | GE | 10GE | 25GE | 40GE | 100GE | `100GE1/0/12` | | **Juniper** | ge | xe | et | xe/et | et | `et-0/0/12` | Stacking ports Consoel Ports: local dmninistration or configuration ports (DB-9, USB) Aux ports remote administration port via modem BRI/PRI ports ISDN ports (E1/T1 circuits) Grounding ---------Router System Components---------- ROM contains bootstrap program or BIOS RAM Runnning Configs located in it, volatile memory, info lost in case of power failure NVRAM Startup configs located in it, permanent storage Flash memory Cisco IOS is located in it Processor usually mootrolla 70 Mhz etc -----------Startup Procedure---------- Step 1: First, the switch loads a power-on self-test (POST) program stored in ROM. POST checks the CPU subsystem. It tests the CPU, DRAM, and the portion of the flash device that makes up the flash file system. Step 2: Next, the switch loads the boot loader software. The boot loader is a small program stored in ROM that is run immediately after POST successfully completes. Step 3: The boot loader performs low-level CPU initialization. It initializes the CPU registers, which control where physical memory is mapped, the quantity of memory, and its speed. Step 4: The boot loader initializes the flash file system on the system board. Step 5: Finally, the boot loader locates and loads a default IOS operating system software image into memory and gives control of the switch over to the IOS. POST Boot Loader = ROM IOS = Flash or TFTP Server startup-configs = NVRAM or TFTP Server running-configs = RAM ---------- Configuration Software ---------- Terminal emulators used like windows = Putty, Hyper terminal, tera term etc. Linux = minicom S ************** Routing Types ************** * static * Dynamic * Default ************** static routing *************** 4 Methods of Static Routing --------------- 1. Next Hop --------------- ip route r1(config)#ip route 192.168.20.0 255.255.255.0 10.0.0.1 OR r1(config)#ip route 0.0.0.0 0.0.0.0 [GATEWAY ADDRESS] default routing allow all networks access --------------- 2. Remote Single/Multiple Host --------------- *if we want to communictae with a SINGLE host in a remote network /32 subnet mask used ip route r1(config)#ip route 192.168.20.50 255.255.255.255 10.0.0.1 now we can communicate with only 192.168.20.50 *if we want to communictae with a RANGE of HOSTs in a remote network /30 subnet mask used r1(config)#ip route 192.168.20.48 255.255.255.252 10.0.0.1 now we can communicate with HOSTs who have 192.168.20.49 & 192.168.20.50 --------------- 3. Self Exit interface --------------- self exit interface is WAN interface of local router ip route r1(config)#ip route 192.168.20.0 255.255.255.0 fa0/1 sh ip route --------------- 4. Default routing --------------- two scenarios are given * internet * end locations Usually it is preffered to Define Default Routing on a STUB NETWORK A STUB NETWROK is a network which has only one way of exit or Gateway Also called Ponit or Gateway of Last Resort. if nothing is matched then route to given Gateway Not Recommended where multiple exit points available default routing allow all networks access i.e used to route traffic over the internet or to large no of networks behind a router(as a next hop) * default routing should be defind otherwise the router will drop the packet labeled with address of public ip(or unknown destination) * usually next hop is the ISP's router port address * BGP is also an option to route traffic over internet * applicable where only one common next hop is existed no more than one next hop. or a network has only one gateway. Topology: R1-fa0/0 (192.168.100.1)------->>> R1-Serial0/0 (10.0.0.1/8)-------->>> R2-Serial0/0 (10.0.0.2/8)-------->>> R3 Router 1 LAN-------------------->>>>> Router 1 WAN syntax: ip route r1(config)#ip route 0.0.0.0 0.0.0.0 10.0.0.2 r1(config)#do ping 192.168.100.1 r1(config)#ping IP repeat ANY_NUMBER(1000000) ping target address(x.x.x.x) source source address(x.x.x.x) r1(config)#do tracert 192.168.100.1 r1(config)#show ip route **************************************** Dynamic Routing **************************************** Classfication 1: IGP inter ASN OSPF, IGRP, EIGRP, IS-IS, RIPv1, RIPv2 EGP intra ASN BGP Classfication 3: * Classful do not carry subnet mask info RIPv1, IGRP FLSM or Default Mask * Classless carry subnet mask info i.e CIDR value RIPv2, EIGRP, OSPF, IS-IS FLSM, VLSM, Default Classfication 3: ****************************** Distance vector ******************************* Make use of Bellman Ford Algorithm makes decision based on HOP count tracks the record of HOP count entire routing table is sent as update after fixed defined interval i.e Periodic updates upadtes are broadcasted (not in RIPv2) updates sent to direclty connected or neighbour routers only routers do not have entire network visibility Based on local knowledge, since it updates table based on information from neighbours prone to routing loops Count of infinity problem. * RIPv1 Classful industry standard * RIPv2 Classless industry standard * IGRP Classful cisco proprietery * easy to configure * Broadcasts advertisements ************************** Link state ************************* makes decision based on LINK STATE & LINK COST uses short path algorithm Make use of Dijakstra’s algorithm Track the status and connection type of link i.e up or down, Link cost updates are sent after an event is occured not after a set interval updates multicasted updates are sent in entire network or group of routers routers are visible to all routers within an area Based on global knowledge, it have knowledge about entire network no routing loops No count of infinity problem. * OSPF Classless industry standard * IS-IS Classless industry standard * difficult to configure * multicasts advertisements ********************** Hybrid (Advanced/Enhanced Distance Vector protocol) ******************** Sends triggered/incremental updates unlike Distance Vector protocols' Periodic updates * Classless protocols * easy to configure * multicasts advertisements unlike Distance Vector protocols' broadcast * EIGRP Classless cisco proprietary <<<<<<<<<<<<<<<<<<<<<<<<< Quantities on which Routing Protocols make routing decisions >>>>>>>>>>>>>>>>>>>>>>>>>> *************** Prefix Length *************** Route having Higher Prefix Lenth will be preffered because they are more specific Like /32 will be preffered at /24 /30 will be preffered at /28 /28 will be preffered at /24 /24 will be preffered at /16 *************** Metric *************** the quantitative value used by routing protocols to determine the best path e.g RIP uses HOP count as a Metric OSPF uses Link cost as a Metric Matric used by BGP are called Path Attributes 1. AS Path 2. Next Hope 3. Local Preferences Used when ONLY ONE Routing protocol is configured Administrative distance AD value will be used as a Metric When Two or more protocols (which are using different Metrics) are configured Like RIP & OSPF or static or EIGRP configured Lower Metric Value will be preffered *************** Administrative Distance AD *************** Router(config-router)#distance 50 To set administrative distance (to set priority between different configured routing protocols) Lower AD value will be preffered AD values are re configurabale Administrative distance AD value will be used as a Metric When Two or more protocols (which are using different Metrics) are configured Like RIP & OSPF or static or EIGRP configured EIGRP 90/170 (internal/external) OSPF 110 RIP 120 Static 1 Connected 0 BGP 20/200 Unreachable 255 <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Routing Infromation Protocol RIP Configs >>>>>>>>>>>>>>>>>>>>>>>>>>>>> --------------------- versions --------------------- RIPv1: classful (FLSM only), broadcast (255.255.255.255), no authentication, no IPv6 RIPv2: classless (Supports VLSM), supports authentication (plain text, MD5), multicast (224.0.0.9), no IPv6 RIP-NG: RIPv2 extension, supports IPv6, UDP 521, multicast (FF02::9) uses UDP port 25 for routing updates matric = hop count max hop count = 15 default update interval = 30 sec in cisco send full routing table uses less CPU and ram than OSPF or EIGRP etc RIP router sends directly connected routes and next do same then next do same and so on -------- in case of RIPv1, only FLSM can be configured --------- Router(config)#router rip Router(config-router)#network 192.168.30.0 Router(config-router)#network 20.0.0.0 Router(config-router)#exit Router(config-router)#distance 50 To set administrative distance (to set priority between different configured routing protocols) OR --------in case of RIPv2, either FLSM or VLSM can be configured--------- To achieve RIPv2, just configure Subnetted IP on intended interfaces and configure RIP v2 also router rip version 2 no auto-summary network 192.168.10.0 network 192.168.20.0 no passive-interface default Auto-summary is a feature in RIPv1 and RIPv2 that automatically summarizes routes at classful boundaries. Example: If you advertise: 192.168.10.0/24 192.168.20.0/24 192.168.30.0/24 RIP with auto-summary ON will summarize all of them as: 👉 192.168.0.0/16 remove passive-interface for interfaces that should send/receive conf t router rip no passive-interface GigabitEthernet0/0/0 no passive-interface GigabitEthernet0/0/1 OR no passive-interface default end ----------RIP versions config------------ Router#show ip protocols show ip route ----------------RIP Timers----------------- *update timer 30 sec send updates after *invlaid timer 180 sec waits and considered unreachable if no update received *flush timer 240=180+60 sec after invalid time waits 60 more secs to delete enrty in table *holddown timer 180 sec a route cannot have entry for 180 secs in RT once considered invalid to avoid routing loops Router(config-router)#timers basic {update=40} {invalid=100} {holddown=100} {flush=150} *************** Routing Loops prevention in RIP ************** Route poisoning Split Horizon Poison Reverse and Triggered Updates Holddown Timer -------- Route poisoning ------- *revise some points like: full routing updates sent periodically max hop count 15 16th Hop is treated as infinity in this method router first remove this route entry from its routing table and update this as 16th matric value then will send update about unreachable or broken route with matric value 16 count to infinity Problem can occur in this case, usually this is not occured in distance vector routers due to split horizon rules --------Split Horizon--------- in distance vector routing Protocols upadtes are not sent to interfaces from which these updates are learnt --------Triggered updates--------- when a route fails router does not wait for next update timer instead sends update immediately --------Poison reverse--------- when a failed route is learnt, even split horizon rule is suspended and advertise a poisoned route ***************RIP v2 Authentication************** Configure following on both routers by creating key chains and apply to WAN/RIP interfaces R1 (config)#key chain R1(config-keychain) #key R1 (config-keychain-key) #key-string R1(config)#int sl/0 R1 (config-if)#ip rip authentication mode text text or MD5 R1 (config-if)#ip rip authentication key-chain ************Deleting Some RIP network Routes************ Router(config)#router rip Router(config-router)#no network 192.168.30.0 Router(config-router)#no network 20.0.0.0 ***************Delete RIP************** malik1(config)#no router rip --------RIP Troubleshooting--------- Router#show ip route Router#show ip route connected Router#show ip protocols Router#show ip int br Router#show ip rip database Router#debug ip rip to SHOW live RIP updates on any router Router#no debug ip rip to DISABLE live RIP updates on any router <<<<<<<<<<<<<<<<<<<<<<<<<<< Enahnced interior Gateway Routing Protocol EIGRP Configs >>>>>>>>>>>>>>>>>>>>>>>>>>> cisco proprietary successor of IGRP Hybrid (link state + distance vector) --------Metric-------- Bandwidth (Default) Delay (Default) Load Link Reliability Diffusing Update algorithm (DUAL) is used to find efficient routes DUAL determines the most efficeient and Lowest cost route to destination Reliable transport Protocol RTP is used to deliver packets Multicast over 224.0.0.10 EIGRP uses IP protocol number 88 Classless routing (VLSM supported) --------why EIGRP----------- have backup Routes, used when best route failed Fast convergence Summarization Load Balancing (Unequal cost unlike OSPF) Supports multiple routed protocols like IP, IPx, Apple talk ------EIGRP Tables-------- Neighbor table directly connected Routers Topology Table best routes info of neighbor routers is stored only not all network routers unlike OSPF Routing Table best path to destination like other Routing protocols -------Neighbors Discovery--------- hello message via multicast 224.0.0.10 are send to neighbors every 5 sec after authentication is passed check same Autonomous system check same subnet or not EIGRP K values test should be passed like K1 Bandwidth K2 Load K3 Delay K4 Reliability K5 MTU Default K1=K3=1 used as Matric K2=K4=K5=0 ************Command Line EIGRP configs************ ---------in case of FLSM--------- Router(config)#router eigrp 100 Router(config-router)#network 192.168.10.0 Router(config-router)#network 10.0.0.0 OR --------in case of VLSM--------- wild card mask is used wild card mask is inverse of subnet mask i.e if SM is 255.255.225.0 then WCM will be 0.0.0.255 if SM is 255.255.225.252 then WCM will be 0.0.0.3 Router(config-router)#network 192.168.10.0 {wild card mask} Router(config-router)#network 10.0.0.0 {wild card mask} Router#show ip route Router#show ip Protocols Router#show ip eigrp interfaces • show ip eigrp neighbors • debug eigrp packets ************Deleting Some EIGRP network Routes************ Router(config)#router eigrp 100 Router(config-router)#no network 192.168.10.0 Router(config-router)#no network 10.0.0.0 Router(config)#no router eigrp 100 <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Open Shortest Path First OSPF Configs >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> ---------------Some Terms--------------- Designated Router DR a router elected to coordinate topology updates in an area. backup DR BDR Internal Router IR A router which has all interfaces in same area (any except Backbone) Backbone Router BR/BIR A router which has all interfaces in Backone area Area Border Router ABR Router responsible for communication b/w Areas, it should be connected to Area 0 as well Autonomous System Boundary Router ASBR OSPF Priority Router ID Hello Timers Dead Timers Neighbour States Wild Card Mask OSPF Area Link State Advertisements LSA Link State Updates LSU Link State Database LSDB 1st router r1(config)#router ospf {PROCESS ID}10 r1(config-router)#network {WILDCARD MASK}10.0.0.0 0.255.255.255 area 0 IP configured on port1-r2-port1 r1(config-router)#network {WILDCARD MASK}192.168.10.0 0.255.255.255 area 0 IP configured on port2-LAN 2nd router r2(config)#router ospf {PROCESS ID}100 r2(config-router)#network {WILDCARD MASK}10.0.0.0 0.255.255.255 area 0 IP configured on port1-r1-port1 r2(config-router)#network {WILDCARD MASK}20.0.0.0.255.255.255 area 0 IP configured on port2-r3-port1 r2(config-router)#network {WILDCARD MASK}192.168.20.0 0.255.255.255 area 0 IP configured on port3-LAN 3rd router r3(config)#router ospf {PROCESS ID}1000 r3(config-router)#network {WILDCARD MASK}20.0.0.0 0.255.255.255 area 0 IP configured on port1-r2-port2 r3(config-router)#network {WILDCARD MASK}192.168.30.0 0.255.255.255 area 0 IP configured on port2-LAN -----------Router ID configuration------------- BY creating loopback inteface r3(config)#interface loopback 1 r3(config-if)#ip address 100.100.100.100 255.0.0.0 ->> this will be the Router ID r3(config)#clear ip ospf process -->> to force router to take manualy Configurd ID BY manual configuration r2(config)#router ospf {PROCESS ID}100 r2(config-router)#router ID 1.1.1.1 r3(config)#clear ip ospf process -->> to force router to take manualy Configurd ID r3(config-if)#do show ip int brief r3(config-if)#do show ip int protocol r3(config)#clear ip ospf process -->> to force router to take manualy Configurd ID r1(config)#interface ge0/0/1 r1(config-if)#ip ospf hello-interval 10 r1(config-if)#ip ospf dead-interval 10 ----------------OSPF Multi Area Configuration------------------ 1st router r1(config)#router ospf {PROCESS ID}10 r1(config-router)#network {WILDCARD MASK}192.168.10.0 0.255.255.255 area 0 Area 0, R1 LAN r1(config-router)#network {WILDCARD MASK}10.0.0.0 0.255.255.255 area 0 Area 0, connected to R2 2nd router r2(config)#router ospf {PROCESS ID}100 r2(config-router)#network {WILDCARD MASK}10.0.0.0 0.255.255.255 area 0 Area 0, connected to R1 r2(config-router)#network {WILDCARD MASK}192.168.20.0 0.255.255.255 area 0 Area 0, R2 LAN r2(config-router)#network {WILDCARD MASK}20.0.0.0.255.255.255 area 1 Area 1, connected to R3 3rd router r3(config)#router ospf {PROCESS ID}1000 r3(config-router)#network {WILDCARD MASK}20.0.0.0 0.255.255.255 area 1 Area 1, connected to R2 r3(config-router)#network {WILDCARD MASK}192.168.30.0 0.255.255.255 area 1 Area 1, R3 LAN ----------------------OSPF Authentication---------------------- --------------clear text--------------- r2(config)#interface fa0/2 r2(config-if)#ip ospf authentication r2(config-if)#ip ospf authentication-key {key-value}nespk@123 r3(config)#interface fa0/1 r3(config-if)#ip ospf authentication r3(config-if)#ip ospf authentication-key {key-value}nespk@123 ------------MD5 encryption------------ r2(config)#interface fa0/2 r2(config-if)#ip ospf authentication message-digest r2(config-if)#ip ospf authentication message-digest-key {key-number}1 {key-value}nespk@123 r3(config)#interface fa0/1 r3(config-if)#ip ospf authentication message-digest r3(config-if)#ip ospf authentication message-digest-key {key-number}1 {key-value}nespk@123 -----------------remove OSPF authentication------------------- r2(config)#interface fa0/2 r2(config-if)#ip ospf authentication null r3(config)#interface fa0/1 r3(config-if)#ip ospf authentication null -----------------remove OSPF------------------- r1(config)#no router ospf 10 ----------------- OSPF Troubleshooting ------------------- r1#show ip route r1#show ip ospf neighbor r1#show ip ospf interface r1#show ip int protocol <<<<<<<<<<<<<<<<<<<<<<<<<<<<< Border Gateway Protocol (BGP) >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> it is an Exterior Gateway Protocol (EGP) used Between Organizations (Autonomous Systems or AS) Called Protocol of internet Not a Link State nor Distance Vector Routing Protocol It is Path Vector Routing Protocol TCP port 179 Slowest Protocol ********BGP Terminologies********* BGP Peers = Neighbors = manually configured AS = Group of routers having same routing policies AS numbers = 1-65535 BGP NLRI (Network Layer Reachability Information) = advertises prefix /Length *********BGP Types********* Internal BGP (iBGP) = Neighbors Belong to same AS, these neighbour routers not needed to be directly connected. External BGP (eBGP) = Neighbors Belong to different AS, these neighbour routers needed to be directly connected. Matric used by BGP are called Path Attributes 1. AS Path 2. Next Hope 3. Local Preferences ********BGP message types********* Open Message Update Message Contains Route Updates Keep Alive Message this message keep the session b/w router running if update messages are not received Notification Message used to send Errors ********BGP States******** Idle Router not accepts any incoming BGP Connections, starts a TCP connection with BGP Peers by listening Connect listens for TCP connection, if successful then sends Open Message, if Unsuccesful goes to Active state Active Unable to establish TCP session, then again goes to Idle State OpenSent Established Connection Established ********BGP Routing Decision********* routing decision are made on the basis of Some Attributes ---------1. Weight---------- highest weightage path preferred from AS100 to AS200, if two or more paths exist like weight 100 or 50 -----------2. Local Preference---------- if same Weight is configured Highest LP (locally configured for Different paths) will be preferred as a best path like LP 100 and LP200 -----------3. Network or Aggregate Value---------- if same LP is configured then route originated by Local Router will be preferred -----------4. AS-path Attribute---------- if Above three values are tied in n/w then AS-Path Attribute takes place and a path which has Lowest AS numbers to destination will be preffered -----------5. Lowest Origin Type---------- if there are same number of AS in path to destination N/w or AS then Lowest Origin is preferred and lowest origin code be preffered Lowest Origin Types: a. IGP preferred first b. EGP preferred secondly c. Incomplete thirdly preferred -----------5. Multi-Exist Discriminator (MED)---------- if Lowest Origin code is also same Lowest MED value will be preferred Like if there are two paths to destination with MED 100 and MED150 then MED100 will be preferred -----------6. iBGP and eBGP---------- if Multi-Exist Discriminator (MED) are also Same then paths learnt from iBGP and eBGP are preferred and also Paths learnt from eBGP are preferred instead of iBGP -----------7. Lowest iBGP Metric---------- if there is Tie b/w the routes iBGP and eBGP then Lowest iBGP Metric is preferred and preffer the route thta can be reached through the closest IGP neighbour (Lowest iBGP Metric) ----------8. External Paths----------- if above all values are same when both paths are external then it prefers the path was received first (oldest path) ----------9. Lowest Router ID------------- if above all values are same then preffers the route come from BGP router with Lowset Router ID -----------10. Lowest Neighbor Address----------- if above all values are same then prefers the route come from BGP router with Lowset neighbour address ---------------BGP Routing Decision Summary--------------- Prefer highest weight (local to router) Prefer highest local preference (within the AS) Prefer routes originated by the local router Prefer shortest AS-path Prefer lowest origin code (IGP < EGP < incomplete) Prefer lowest MED (from other AS) Prefer eBGP path over iBGP path Prefer the path through the closest IGP neighbor Prefer oldest.route for eBGP paths Prefer the path with the lowest neighbor BGP routes ID Prefer the path with the lowest neighbor IP address **************eBGP (external BGP) Configurations*************** eBGP is configured b/w different ASs like AS100, AS200 and AS300 -----------Router 1------------ R1(config)#interface serial 0/0 R1(config-if)#no shutdown R1(config-if)#ip address 10.10.10.1 255.255.255.0 R2(config-if)#clock rate 64000 R1(config)#router bgp 100 R1(config-router)#bgp router-id 1.1.1.1 R1(config)#interface loopback 0 R1(config-if)#no shutdown R1(config-if)#ip address 100.100.100.1 255.255.255.0 R1(config)#interface loopback 1 R1(config-if)#no shutdown R1(config-if)#ip address 101.101.101.1 255.255.255.0 R1(config)#interface fastEthernet 0/0 R1(config-if)#no shutdown R1(config-if)#ip address 25.25.25.1 255.255.255.0 -----------Router 2------------ R2(config)#interface serial 0/1 R2(config-if)#no shutdown R2(config-if)#ip address 10.10.10.2 255.255.255.0 R2(config)#router bgp 200 R2(config-router)#bgp router-id 2.2.2.2 R2(config)#interface serial 0/0 R2(config-if)#ip address 20.20.20.1 255.255.255.0 R2(config-if)#no shutdown R2(config-if)#clock rate 64000 -----------Router 3------------ R3(config)#interface serial 0/1 R3(config-if)#no shutdown R3(config-if)#ip address 20.20.20.2 255.255.255.0 R3(config)#router bgp 300 R3(config-router)#bgp router-id 3.3.3.3 R3(config)#interface fastEthernet 0/0 R3(config-if)#ip address 50.50.50.1 255.255.255.0 R3(config-if)#no shutdown now two commands will be executed 1. Network Commands to advertise the networks configured on local routers 2. Neighbor Commands to give info of neighbours to local router --------Neighbors Info Update in Local Router--------- R1(config)#router bgp 100 R1(config-router)#neighbor 10.10.10.2 remote-as 200 R2(config)#router bgp 200 R2(config-router)#neighbor 10.10.10.1 remote-as 100 R2(config-router)#neighbor 20.20.20.2 remote-as 300 R3(config)#router bgp 300 R3(config-router)#neighbor 20.20.20.1 remote-as 200 --------Local Networks Advertisement--------- R1(config)#router bgp 100 R1(config-router)#network 100.100.100.0 mask 255.255.255.0 R1(config-router)#network 101.101.101.0 mask 255.255.255.0 R1(config-router)#network 25.25.25.0 mask 255.255.255.0 R3(config)#router bgp 300 R3(config-router)#network 50.50.50.0 mask 255.255.255.0 **************iBGP (internal BGP) Configurations*************** iBGP is configured on routers which are in same ASs like AS100, AS200 and AS300 R1 = AS100 R2 = AS100, AS200 part of both ASs, both iBGP and eBGP will be configured R3 = AS200 R1(config)#router bgp 100 R1(config-router)#neighbor 10.10.10.2 remote-as 100 R1(config-router)#network 100.100.100.0 mask 255.255.255.0 R1(config-router)#network 101.101.101.0 mask 255.255.255.0 R2(config)#router bgp 100 R2(config-router)#neighbor 10.10.10.1 remote-as 100 R2(config-router)#neighbor 20.20.20.2 remote-as 200 R3(config)#router bgp 200 R3(config-router)#neighbor 20.20.20.1 remote-as 100 -----------Transit AS------------ When traffic originates from outside your autonomous system and is destined for a network outside your As is permitted to route through your As Transit peering If an As has multiple BGP speakers The most common use of this is when an ISP allows their customers using BGP to access all their other customers using BGP -----------BGP Troubleshooting------------ sh ip bgp sh ip bgp summary sh ip route sh run | section bgp ----------- Delete or Remove BGP configs ------------ no router bgp AS-NUMBER <<<<<<<<<<<<<<<<<<<< Network Address Translation (NAT) >>>>>>>>>>>>>>>>>>>> 3 Types Static NAT Dynamic NAT NAT/PAT (Port Address Translation) *********************Static NAT********************* a static fixed Public IP address from Pool is assigned to every host in LAN like; 10.0.0.1---->>>>>122.1.1.1 10.0.0.2---->>>>>122.1.1.2 Single Public IP = Single Private IP = Statically assigned No. of Public IPs = No. of Private IPs Topology: 2 PCs in LAN LAN IPs 10.0.0.1, 10.0.0.2 one ISP WAN router Public IPs 122.1.1.1, 122.1.1.2 R1(config)#ip nat inside source static {1st LAN IP} {1st WAN IP} R1(config)#ip nat inside source static {2nd LAN IP} {2nd WAN IP} sh ip nat translations ----------on LAN Port------------ R1(config)#int gigabitethernet 0/1 R1(config-if)#ip nat inside ----------on WAN Port------------ R1(config)#int gigabitethernet 0/0 R1(config-if)#ip nat outside -----------removing Static NAT-------------- R1(config)#no ip nat inside source static {1st LAN IP} {1st WAN IP} R1(config)#no ip nat inside source static {2nd LAN IP} {2nd WAN IP} sh ip nat translations ***********************Dynamic NAT********************** LAN hosts are configured to have a Public IP address from given IP pool dynamically Public IP addresses in a Pool => Hosts in a LAN Multiple Public IPs = Multiple Private IPs = Dynamically assigned No. of Public IPs => No. of Private IPs R1(config)#access-list {create List Name}1 permit {LAN n/w address}10.0.0.0 {netmask wildcard} 0.255.255.255 now create Public IP Pool R1(config)#ip nat pool {pool name}NESPK_POOL {start IP}122..1.1.1 {END IP}122.1.1.4 {netmask}255.255.255.248 R1(config)#ip nat inside source list {list name created above}1 pool {pool name created above} NESPK_POOL ----------on LAN Port------------ R1(config)#int gigabitethernet 0/1 R1(config-if)#ip nat inside ----------on WAN Port------------ R1(config)#int gigabitethernet 0/0 R1(config-if)#ip nat outside *********************** NAT/PAT *********************** LAN hosts are configured to have a Public IP address from given single Public IP dynamically via TCP ports Public IP addresses in a Pool => Hosts in a LAN Single Public IP = Multiple Private IPs = Dynamically assigned R1(config)#access-list {create List Name}1 permit {LAN n/w address}10.0.0.0 {netmask wildcard} 0.255.255.255 now create Public IP Pool R1(config)#ip nat pool {pool name}NESPK_POOL {start IP}122..1.1.1 {END IP}122.1.1.1 {netmask}255.255.255.248 R1(config)#ip nat inside source list {list name created above}1 pool {pool name created above} NESPK_POOL overload **overload keyword is used to convert dynamic NAT to NAT PAT ----------on LAN Port------------ R1(config)#int gigabitethernet 0/1 R1(config-if)#ip nat inside ----------on WAN Port------------ R1(config)#int gigabitethernet 0/0 R1(config-if)#ip nat outside -----------NAT Troubleshooting-------------- sh ip nat translations clear ip nat translation* ======================================================================================= <<<<<<<<<<<<<<<<<<< Router Redundancy Protocols (HSRP, VRRP, GLBP) >>>>>>>>>>>>>>>>>> ======================================================================================= these are First Hop Redundancy Protocols FHRP ********************* Hot Standby Router Protocol HSRP ********************* cisco proprietary hello timer=3 sec, hold/dead timer= 10 sec Active-Passive scheme is used r1(config)#interface range fa0/1-4 r1(config-if-range)#switchport mode access r1(config-if-range)#switchport mode access r1(config-if-range)#switchport access vlan 10 r1(config)#interface vlan 10 r1(config-if)#ip address 192.168.10.10 255.255.255.0 r1(config-if)#standby {group=1-255 anyone, we set 8} ip 192.168.10.1 (this is virtual router IP as a gateway) r1(config-if-range)#no shut --------------set priority and preemption--------------- default priority=100 r1(config)#interface vlan 10 r1(config-if)#standby group 8 priority 150 router having higher priority value will be active r1(config-if-range)#standby group 8 preempt if premption is enabled the router will again go active if it got shutdown in any case ----------------HSRP Timers configs----------------- r1(config)#interface vlan 10 r1(config-if)#standby timers {hello timer e.g 2} {holddown timer e.g 6} on 2nd router also Same on 2nd Router ----------------HSRP Tracking/Scanning/Monitoring WAN configs----------------- tracking is configured to avoid outage when both routers are working but an uplink is down on active router in this case if uplink is down active router will be standby and vice versa 1st configure preemption on both routers and configure both routers as above so that one is active and other is standby & one is prior to another then configure uplink on active higher priority router as r1(config)#interface fa0/6 which is already configured as uplink r1(config-if)#ip addr 200.200.200.20 255.255.255.252 uplink/public IP provided by ISP r1(config-if)#no shut r1(config-if)#int vlan 10 go to vlan 10 as configured r1(config-if)#standby 8 {uplink interface i.e fa0/6} {priority decrement value in case of uplink down e.g 60} this decrement value will be subtracted from priiority value of active router and this acctive router will go standby due to its uplink failure set a value, once which is subtracted the priiority value should go less than than priority value of standny router -------------------Troubleshooting----------------- sh standby sh standby brief *********************Gateway Load Balancing Protocol GLBP********************* cisco propritary Active-Active scheme used means redundancy with load balancing *********************Virtual ROuter Redundancy Protocol VRRP********************* IETF design it industry standard faster than HSRP hello timer=1 sec, hold/dead timer= 3 sec inter vendor usage possibe r1(config)#interface vlan 10 r1(config-if)#vrrp 8 ip 192.168.10.1 ---------------VRRP priority and preemption----------------- r1(config)#interface vlan 10 r1(config-if)#vrrp 8 priority r1(config-if)#vrrp 8 priority r1(config-if)#vrrp 8 preempt ---------------VRRP Timers----------------- r1(config)#interface vlan 10 r1(config-if)#vrrp 8 timers advertise 3 dead timers will be 3 times advertise timer ---------------VRRP Troubleshootig----------------- show VRRP <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Casting modes in Network >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> Unicast multicast 224.0.0.0 to 239.255.255.255 Broadcast Limited BC = 255.255.255.255 Directed BC = 192.168.10.255 ---------control directed Broadcast--------- R4(config)#no ip directed-broadcasts. ############################################################################### <<<<<<<<<<<<<<<<<<<<<<<<<<< Access Control List ACL >>>>>>>>>>>>>>>>>>>>>>>>>> ############################################################################### 1. Standard ACLs General, Source Address 1-99, expanded access-list for Standard ACL = (1300-1999) 2. Extended ACLs Specific, Source Address, destination Address, Protocol, Port 100-999 Actions: Deny IN Deny OUT Permit IN Permit OUT # ============================ ACL OVERVIEW =================================== ACL (Access Control List) # Filters traffic based on rules Standard ACL # Filters SOURCE IP only Extended ACL # Filters Source + Destination + Protocol + Port Named ACL # ACL with custom name (recommended) Implicit Deny # Hidden "deny ip any any" at end Processing Order # Top-down (first match wins) Standard ACL Placement # Near DESTINATION Extended ACL Placement # Near SOURCE One ACL Rule # One ACL per interface per direction ========================================================================= ----------------------Deny Web Access------------------- Router(config)#interface fastEthernet 0/0 Router(config-if)#no shutdown Router(config-if)#ip address 192.168.10.1 255.255.255.0 Router(config)#interface fastEthernet 1/0 Router(config-if)#no shutdown Router(config-if)#ip address 192.168.20.1 255.255.255.0 Router(config-if)#router rip Router(config-router)#network 192.168.10.0 Router(config-router)#network 192.168.20.0 Router(config)#access-list 100 deny tcp host {source}192.168.10.10 host {destination web server}192.168.20.10 eq {port}80 Router(config)#access-list 100 permit ip any any --->>>command is given otherwise access will be denied on all hosts Router(config)#interface fastEthernet 0/0 Acess rule applied to LAN gateway Router(config-if)#ip access-group 100 in ----------------------Deny Telnet Access------------------- Router(config)#access-list 100 deny tcp host {source}192.168.10.10 host {destination telnet}192.168.20.10 eq {port}23 Router(config)#access-list 100 permit ip any any --->>>command is given otherwise access will be denied on all hosts Router(config)#interface fastEthernet 0/0 Acess rule applied to LAN gateway Router(config-if)#ip access-group 100 in ========================================================================= # ============================ STANDARD ACL (1-99) ============================ # Purpose: Filter traffic using Source IP only access-list 10 deny 192.168.1.10 0.0.0.0 # Block specific host access-list 10 permit any # Allow all remaining traffic interface g0/0 # Select interface ip access-group 10 in # Apply ACL inbound ----------------------Access List Troubleshooting------------------- show access lists 105 show access-lists # View ACL entries show run | include access-list # Show configured ACL lines show ip interface g0/0 # Verify ACL applied on interface # ============================ EXTENDED ACL (100-199) ========================= # Purpose: Filter Source + Destination + Protocol + Port # Best Practice: Place near SOURCE access-list 100 deny tcp 192.168.1.0 0.0.0.255 host 10.10.10.10 eq 80 # Block HTTP traffic access-list 100 permit ip any any # Allow remaining traffic interface g0/1 ip access-group 100 in # ============================ NAMED EXTENDED ACL ============================= ip access-list extended BLOCK_HTTP deny tcp 192.168.1.0 0.0.0.255 host 10.10.10.10 eq 80 # Block HTTP permit ip any any # Allow rest exit interface g0/1 ip access-group BLOCK_HTTP in # ============================ COMMON CCNA EXAMPLES =========================== access-list 101 permit tcp any host 10.10.10.10 eq 22 # Allow SSH only access-list 101 deny tcp any any eq 23 # Block Telnet access-list 101 deny icmp any any # Block Ping access-list 101 permit ip 192.168.2.0 0.0.0.255 any # Allow specific subnet access-list 101 deny ip 192.168.3.0 0.0.0.255 any # Block entire subnet # ============================ WILDCARD MASK TABLE ============================ 255.255.255.255 0.0.0.0 255.255.255.0 0.0.0.255 255.255.0.0 0.0.255.255 255.0.0.0 0.255.255.255 # Formula: # 255 - Subnet Mask = Wildcard Mask # ============================ TROUBLESHOOTING ================================ show access-lists # Check ACL + hit count show ip interface # Verify applied ACL debug ip packet # Advanced debugging (careful in production) no access-list 10 # Delete ACL no ip access-group 10 in # Remove ACL from interface # ============================ ENTERPRISE BEST PRACTICES ====================== # Always add permit ip any any (if required) # Use Named ACLs (easier management) # Use sequence numbers for editing # Document every ACL rule # Test in lab before production # ============================ ADVANCED (SEQUENCE NUMBERS) ==================== ip access-list extended BLOCK_HTTP 10 deny tcp 192.168.1.0 0.0.0.255 host 10.10.10.10 eq 80 20 permit ip any any no 10 # Remove specific sequence ############################### END OF GUIDE ################################## ######################### ACL FOR COMMON PROTOCOLS ############################ # ============================ MANAGEMENT ACCESS =============================== # Allow SSH (Port 22) access-list 110 permit tcp any host 10.10.10.10 eq 22 # Allow Telnet (Port 23) access-list 110 permit tcp any host 10.10.10.10 eq 23 # Block Telnet Everywhere (Security Best Practice) access-list 110 deny tcp any any eq 23 # Apply ACL to VTY lines (Restrict Router Access) ip access-list standard VTY_ONLY permit 192.168.1.0 0.0.0.255 line vty 0 4 access-class VTY_ONLY in transport input ssh # ============================ WEB TRAFFIC ==================================== # Allow HTTP (Port 80) access-list 120 permit tcp any any eq 80 # Allow HTTPS (Port 443) access-list 120 permit tcp any any eq 443 # Block HTTP but Allow HTTPS access-list 120 deny tcp any any eq 80 access-list 120 permit tcp any any eq 443 access-list 120 permit ip any any # ============================ FILE TRANSFER ================================== # Allow FTP (Port 21 Control) access-list 130 permit tcp any any eq 21 # Allow FTP Data (Port 20) access-list 130 permit tcp any any eq 20 # Allow TFTP (UDP 69) access-list 130 permit udp any any eq 69 # ============================ EMAIL PROTOCOLS ================================ # Allow SMTP (Port 25) access-list 140 permit tcp any any eq 25 # Allow POP3 (Port 110) access-list 140 permit tcp any any eq 110 # Allow IMAP (Port 143) access-list 140 permit tcp any any eq 143 # Allow Secure SMTP (Port 465) access-list 140 permit tcp any any eq 465 # Allow Secure IMAP (Port 993) access-list 140 permit tcp any any eq 993 # ============================ NETWORK SERVICES =============================== # Allow DNS (UDP 53) access-list 150 permit udp any any eq 53 # Allow DNS TCP (Zone Transfer) access-list 150 permit tcp any any eq 53 # Allow DHCP (UDP 67 & 68) access-list 150 permit udp any any eq 67 access-list 150 permit udp any any eq 68 # Allow SNMP (UDP 161) access-list 150 permit udp any any eq 161 # Allow SNMP Trap (UDP 162) access-list 150 permit udp any any eq 162 # Allow NTP (UDP 123) access-list 150 permit udp any any eq 123 # ============================ REMOTE ACCESS ================================== # Allow RDP (Port 3389) access-list 160 permit tcp any any eq 3389 # Allow VPN (IPSec) access-list 160 permit udp any any eq 500 # ISAKMP access-list 160 permit udp any any eq 4500 # NAT-T access-list 160 permit esp any any # ESP Protocol # ============================ ICMP CONTROL =================================== # Allow Ping access-list 170 permit icmp any any echo # Allow Ping Reply access-list 170 permit icmp any any echo-reply # Block All ICMP access-list 170 deny icmp any any access-list 170 permit ip any any # ============================ BLOCK SPECIFIC PORT ============================= # Block Social Media Port Example (Example 5222 - WhatsApp) access-list 180 deny tcp any any eq 5222 access-list 180 permit ip any any # ============================ APPLY ACL TO INTERFACE ========================= interface g0/1 ip access-group 120 in # ============================ IMPORTANT NOTES ================================ # eq = equal to port # gt = greater than # lt = less than # range = port range # Example Port Range (Block 1000-2000) access-list 190 deny tcp any any range 1000 2000 access-list 190 permit ip any any ############################################################################### ############################ COMMON PORT QUICK LIST ############################ ############################################################################### # 20 FTP Data # 21 FTP Control # 22 SSH # 23 Telnet # 25 SMTP # 53 DNS # 67-68 DHCP # 69 TFTP # 80 HTTP # 110 POP3 # 123 NTP # 143 IMAP # 161 SNMP # 162 SNMP Trap # 443 HTTPS # 500 ISAKMP # 993 IMAPS # 3389 RDP ############################################################################### ############################### END ############################################ ############################################################################### S1(config)# spanning-tree portfast bpduguard default S1(config-if)# spanning-tree bpduguard enable Q. What is the function provided by CAPWAP protocol in a corporate wireless network? A. CAPWAP provides the encapsulation and forwarding of wireless user traffic between an access point and a wireless LAN controller WLC Cisco 3504 WLC Which two Cisco solutions help prevent DHCP starvation attacks? (Choose two.) The ip helper-address command Which type of static route is configured with a greater administrative distance to provide a backup route to a route learned from a dynamic routing protocol? floating static route default static route summary static route standard static route LLDP TACACS+ RADIUS IP-PBX router 2600, 2900 series ----------------------------------------CRC Input errors”---------------------------------------- is the sum of all errors in datagrams that were received on the interface being examined. This includes runts, giants, CRC, no buffer, frame, overrun, and ignored counts. The reported input errors from the show interfaces command include the following: Runt Frames - Ethernet frames that are shorter than the 64-byte minimum allowed length are called runts. Malfunctioning NICs are the usual cause of excessive runt frames, but they can also be caused by collisions. Giants - Ethernet frames that are larger than the maximum allowed size are called giants. CRC errors - On Ethernet and serial interfaces, CRC errors usually indicate a media or cable error. Common causes include electrical interference, loose or damaged connections, or incorrect cabling. If you see many CRC errors, there is too much noise on the link and you should inspect the cable. You should also search for and eliminate noise sources. ----------------------------------------CRC Output errors”---------------------------------------- is the sum of all errors that prevented the final transmission of datagrams out the interface that is being examined. The reported output errors from the show interfaces command include the following: Collisions - Collisions in half-duplex operations are normal. However, you should never see collisions on an interface configured for full-duplex communication. Late collisions - A late collision refers to a collision that occurs after 512 bits of the frame have been transmitted. Excessive cable lengths are the most common cause of late collisions. Another common cause is duplex misconfiguration. For example, you could have one end of a connection configured for full-duplex and the other for half-duplex. You would see late collisions on the interface that is configured for half-duplex. In that case, you must configure the same duplex setting on both ends. A properly designed and configured network should never have late collisions. ----------------------------------------Store-and-Forward Switching---------------------------------------- Store-and-forward switching, as distinguished from cut-through switching, has the following two primary characteristics: Error checking - After receiving the entire frame on the ingress port, the switch compares the frame check sequence (FCS) value in the last field of the datagram against its own FCS calculations. The FCS is an error checking process that helps to ensure that the frame is free of physical and data-link errors. If the frame is error-free, the switch forwards the frame. Otherwise, the frame is dropped. Automatic buffering - The ingress port buffering process used by store-and-forward switches provides the flexibility to support any mix of Ethernet speeds. For example, handling an incoming frame traveling into a 100 Mbps Ethernet port that must be sent out a 1 Gbps interface would require using the store-and-forward method. With any mismatch in speeds between the ingress and egress ports, the switch stores the entire frame in a buffer, computes the FCS check, forwards it to the egress port buffer and then sends it. ----------------------------------------Cut-Through Switching---------------------------------------- The store-and-forward switching method drops frames that do not pass the FCS check. Therefore, it does not forward invalid frames. By contrast, the cut-through switching method may forward invalid frames because no FCS check is performed . However, cut-through switching has the ability to perform rapid frame switching. This means the switch can make a forwarding decision as soon as it has looked up the destination MAC address of the frame in its MAC address table, as shown in the figure. shows a diagram of an ethernet frame, and highlights the fact that in cut through switching the switch can forward the frame once it reads the destination MAC address __________________________________________________________________________________________________________ <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< Software Defined Networking >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> ************************ SD-Access ************************ Terminologies: WLC Wireless LAN controller LWAP Light weight Access Point CAPWAP control and provisioning of Wireless AP ------------------ CAPWAP-control and provisioning of Wireless AP ------------------ IEEE standard protocol UDP 5246 control UDP 5247 data IPv4, IPv6 enabled DTLS datagram Transport Layer Security Protocol provide security b/w WLC and AP Topology: WLC----------CAPWAP-------->>>LWAP SA61521#show run Building configuration... Current configuration : 17377 bytes ! ! Last configuration change at 04:30:18 KSA Sat Aug 17 2024 ! version 15.2 no service pad service tcp-keepalives-in service tcp-keepalives-out service timestamps debug datetime msec service timestamps log datetime localtime service password-encryption service sequence-numbers ! hostname SA61521 ! boot-start-marker boot-end-marker ! logging buffered 99999 no logging console enable secret 5 $1$Gb9b$1RjYTen1LL4/HLAMx058R0 enable password 7 04481F055E354840591C0143115B015539 ! username stc1tdn0tg1n privilege 15 secret 5 $1$aEMw$an4PboGeYcaLJOfjTDFVi1 aaa new-model ! ! aaa authentication login default local enable aaa authentication login vty group tacacs+ enable aaa authentication login console group tacacs+ enable none aaa authorization config-commands aaa authorization exec default group tacacs+ local if-authenticated aaa authorization commands 0 default group tacacs+ local if-authenticated aaa authorization commands 1 default group tacacs+ local if-authenticated aaa authorization commands 15 default group tacacs+ local if-authenticated aaa accounting exec default stop-only group tacacs+ aaa accounting commands 1 default stop-only group tacacs+ aaa accounting commands 15 default start-stop group tacacs+ aaa accounting connection default start-stop group tacacs+ aaa accounting system default start-stop group tacacs+ ! ! ! ! ! ! aaa session-id common clock timezone KSA 3 0 switch 1 provision ws-c2960x-24ts-l switch 2 provision ws-c2960x-24ts-l no ip source-route ip options drop ! ! ip domain-list stc.com.sa ip domain-name stc.corp ! ! ! ! ! ! ! crypto pki trustpoint TP-self-signed-2653423488 enrollment selfsigned subject-name cn=IOS-Self-Signed-Certificate-2653423488 revocation-check none rsakeypair TP-self-signed-2653423488 ! ! crypto pki certificate chain TP-self-signed-2653423488 certificate self-signed 01 quit spanning-tree mode pvst spanning-tree extend system-id ! ! ! ! vlan internal allocation policy ascending ! ! ! ! ! ! ! ! ! ! ! interface FastEthernet0 no ip address shutdown ! interface GigabitEthernet1/0/1 description Link to RZ61560 on Port **Gig0/0** spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/2 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/3 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/4 ! interface GigabitEthernet1/0/5 description Connected to Ericsson Server (IP: 172.22.30.145) spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/6 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/7 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/8 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/9 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/10 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/11 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/12 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/13 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/14 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/15 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/16 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/17 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/18 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/19 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/20 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/21 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/22 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/23 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/24 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/25 ! interface GigabitEthernet1/0/26 ! interface GigabitEthernet1/0/27 ! interface GigabitEthernet1/0/28 ! interface GigabitEthernet2/0/1 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/2 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/3 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/4 ! interface GigabitEthernet2/0/5 ! interface GigabitEthernet2/0/6 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/7 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/8 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/9 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/10 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/11 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/12 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/13 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/14 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/15 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/16 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/17 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/18 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/19 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/20 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/21 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/22 description BLK as WinXP use , ip 172.22.30.138 Vlan 1 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/23 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/24 spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet2/0/25 ! interface GigabitEthernet2/0/26 ! interface GigabitEthernet2/0/27 ! interface GigabitEthernet2/0/28 ! interface Vlan1 ip address 172.22.30.155 255.255.255.224 no ip unreachables no ip proxy-arp no ip route-cache shutdown ! ip default-gateway 172.22.30.158 no ip http server no ip http secure-server ! ip ssh version 2 ip tacacs source-interface Vlan1 ! ip access-list extended NTP permit ip any host 172.20.236.19 permit ip host 172.20.236.19 any permit ip any host 172.20.165.11 permit ip host 172.20.165.11 any permit ip any host 172.20.165.12 permit ip host 172.20.165.12 any logging trap notifications logging source-interface Vlan1 logging host 172.20.10.21 logging host 172.20.149.191 logging host 172.20.149.197 logging host 172.20.149.208 logging host 172.20.10.252 logging host 172.20.149.209 logging host 172.21.5.35 logging host 10.28.7.199 access-list 1 permit 10.32.1.10 access-list 1 permit 172.26.36.183 access-list 1 permit 172.26.36.184 access-list 1 permit 172.20.151.101 access-list 1 permit 172.20.10.252 access-list 1 permit 172.20.10.53 access-list 1 permit 10.32.1.162 access-list 1 permit 10.32.1.165 access-list 1 permit 10.32.1.164 access-list 1 permit 172.20.10.2 access-list 1 permit 172.20.8.2 access-list 1 permit 172.20.5.7 access-list 1 permit 172.20.6.2 access-list 1 permit 172.20.4.2 access-list 1 permit 172.30.98.7 access-list 1 permit 172.30.98.8 access-list 1 permit 172.20.150.244 access-list 1 permit 172.20.150.245 access-list 1 permit 172.20.4.80 access-list 1 permit 172.20.10.54 0.0.0.1 access-list 1 permit 172.20.10.56 0.0.0.1 access-list 1 permit 172.20.10.8 0.0.0.7 access-list 1 permit 172.20.10.16 0.0.0.7 access-list 1 permit 172.20.11.8 0.0.0.7 access-list 1 permit 172.20.11.16 0.0.0.7 access-list 1 permit 10.32.1.12 0.0.0.3 access-list 1 permit 10.160.208.220 0.0.0.3 access-list 1 permit 10.96.210.220 0.0.0.3 access-list 1 permit 172.21.5.32 0.0.0.31 access-list 2 permit 172.20.148.1 access-list 2 permit 172.20.10.252 access-list 2 permit 10.33.95.1 access-list 2 permit 172.20.149.189 access-list 2 permit 172.20.149.188 access-list 2 permit 172.20.149.190 access-list 2 permit 172.20.148.139 access-list 2 permit 172.20.149.205 access-list 2 permit 172.20.149.204 access-list 2 permit 172.20.149.203 access-list 2 permit 172.20.149.196 access-list 2 permit 172.20.149.199 access-list 2 permit 172.20.149.195 access-list 2 permit 172.20.149.194 access-list 2 permit 172.21.5.32 0.0.0.31 access-list 3 permit 172.20.10.252 access-list 3 permit 172.20.149.168 access-list 3 permit 172.21.5.32 0.0.0.31 access-list 19 permit 10.20.49.25 access-list 19 permit 10.20.49.20 access-list 19 permit 10.29.34.70 access-list 19 permit 10.17.25.124 access-list 19 permit 10.29.34.74 access-list 19 permit 10.17.25.129 access-list 19 permit 10.21.230.36 access-list 19 permit 172.21.5.32 0.0.0.31 access-list 19 permit 10.32.1.0 0.0.0.255 access-list 19 permit 172.20.0.0 0.0.255.255 access-list 19 permit 10.1.0.0 0.0.255.255 access-list 19 permit 10.1.1.0 0.0.0.255 access-list 19 permit 10.1.2.0 0.0.0.255 access-list 19 permit 10.33.17.0 0.0.0.255 access-list 19 permit 10.33.22.0 0.0.0.255 access-list 19 permit 172.20.149.0 0.0.0.255 access-list 19 permit 10.33.133.0 0.0.0.255 access-list 19 permit 0.0.0.0 255.255.252.0 access-list 19 permit 10.32.96.0 0.0.1.255 access-list 19 permit 10.32.112.0 0.0.1.255 access-list 19 permit 10.32.98.0 0.0.1.255 access-list 19 permit 10.32.135.0 0.0.0.63 access-list 19 permit 10.32.114.0 0.0.1.255 access-list 29 permit 172.20.0.53 access-list 29 permit 10.32.1.0 0.0.0.255 access-list 29 permit 172.20.10.0 0.0.1.255 access-list 29 permit 172.20.114.0 0.0.0.255 access-list 29 permit 10.90.0.0 0.0.255.255 access-list 29 permit 10.255.0.0 0.0.255.255 access-list 29 permit 10.245.0.0 0.0.255.255 access-list 29 permit 10.248.0.0 0.0.255.255 access-list 29 permit 10.1.0.0 0.0.0.255 access-list 29 permit 10.1.1.0 0.0.0.255 access-list 29 permit 10.1.2.0 0.0.0.255 access-list 29 permit 10.33.17.0 0.0.0.255 access-list 29 permit 10.33.22.0 0.0.0.255 access-list 29 permit 172.20.149.0 0.0.0.255 access-list 29 permit 10.33.133.0 0.0.0.255 access-list 29 permit 172.21.5.32 0.0.0.31 access-list 67 permit 172.20.10.21 access-list 68 permit 172.20.10.252 access-list 68 permit 172.20.149.168 access-list 68 permit 172.20.149.209 access-list 68 permit 172.20.149.208 access-list 68 permit 172.21.5.32 0.0.0.31 ! snmp-server group NMS v3 priv snmp-server group GROUP v3 priv snmp-server trap-source Vlan1 snmp-server tftp-server-list 68 snmp-server contact DNOS snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart snmp-server enable traps transceiver all snmp-server enable traps call-home message-send-fail server-fail snmp-server enable traps tty snmp-server enable traps license snmp-server enable traps auth-framework sec-violation snmp-server enable traps cluster snmp-server enable traps config-copy snmp-server enable traps config snmp-server enable traps config-ctid snmp-server enable traps trustsec-sxp conn-srcaddr-err msg-parse-err conn-config-err binding-err conn-up conn-down binding-expn-fail oper-nodeid-change binding-conflict snmp-server enable traps energywise snmp-server enable traps fru-ctrl snmp-server enable traps entity snmp-server enable traps event-manager snmp-server enable traps ike policy add snmp-server enable traps ike policy delete snmp-server enable traps ike tunnel start snmp-server enable traps ike tunnel stop snmp-server enable traps ipsec cryptomap add snmp-server enable traps ipsec cryptomap delete snmp-server enable traps ipsec cryptomap attach snmp-server enable traps ipsec cryptomap detach snmp-server enable traps ipsec tunnel start snmp-server enable traps ipsec tunnel stop snmp-server enable traps ipsec too-many-sas snmp-server enable traps power-ethernet police snmp-server enable traps cpu threshold snmp-server enable traps vstack snmp-server enable traps bridge newroot topologychange snmp-server enable traps stpx inconsistency root-inconsistency loop-inconsistency snmp-server enable traps syslog snmp-server enable traps vtp snmp-server enable traps vlancreate snmp-server enable traps vlandelete snmp-server enable traps flash insertion removal snmp-server enable traps port-security snmp-server enable traps envmon fan shutdown supply temperature status snmp-server enable traps stackwise snmp-server enable traps bulkstat collection transfer snmp-server enable traps errdisable snmp-server enable traps mac-notification change move threshold snmp-server enable traps vlan-membership snmp-server host 10.33.95.1 COMISemcro_02 snmp-server host 172.20.148.1 COMISemcro_02 snmp-server host 172.20.148.139 COMISemcro_02 snmp-server host 172.20.149.188 COMISemcro_02 snmp-server host 172.20.149.189 COMISemcro_02 snmp-server host 172.20.149.190 COMISemcro_02 snmp-server host 172.20.149.194 COMISemcro_02 snmp-server host 172.20.149.195 COMISemcro_02 snmp-server host 172.20.149.196 COMISemcro_02 snmp-server host 172.20.149.203 COMISemcro_02 snmp-server host 172.20.149.204 COMISemcro_02 snmp-server host 172.20.149.205 COMISemcro_02 snmp-server host 172.20.149.208 COMISemcrw_68 snmp-server host 172.20.149.209 COMISemcrw_68 snmp-server host 172.20.10.10 COMISnms_01 snmp-server host 172.20.10.8 COMISnms_01 snmp-server host 172.20.10.9 COMISnms_01 snmp-server host 10.160.208.221 EDNnms_01 snmp-server host 10.32.1.13 EDNnms_01 snmp-server host 10.96.210.221 EDNnms_01 snmp-server host 10.17.25.124 version 3 priv NMS snmp-server host 10.17.25.129 version 3 priv NMS snmp-server host 10.20.49.20 version 3 priv NMS snmp-server host 10.20.49.25 version 3 priv NMS snmp-server host 10.29.34.70 version 3 priv NMS snmp-server host 10.29.34.74 version 3 priv NMS snmp-server host 172.20.10.252 version 3 priv NMS snmp-server host 172.20.149.188 version 3 priv NMS snmp-server host 172.20.149.189 version 3 priv NMS snmp-server host 172.20.149.190 version 3 priv NMS snmp-server host 172.20.149.194 version 3 priv NMS snmp-server host 172.20.149.195 version 3 priv NMS snmp-server host 172.20.149.196 version 3 priv NMS snmp-server host 172.20.149.198 version 3 priv NMS snmp-server host 172.20.149.199 version 3 priv NMS snmp-server host 172.20.149.200 version 3 priv NMS snmp-server host 172.20.149.201 version 3 priv NMS snmp-server host 172.20.149.202 version 3 priv NMS snmp-server host 172.20.149.203 version 3 priv NMS snmp-server host 172.20.149.204 version 3 priv NMS snmp-server host 172.20.149.205 version 3 priv NMS snmp-server host 172.20.149.208 version 3 priv NMS snmp-server host 172.20.149.209 version 3 priv NMS snmp-server host 172.21.5.35 version 3 priv NMS snmp-server file-transfer access-group 68 protocol tftp tacacs-server host 172.20.10.6 tacacs-server host 172.20.114.6 tacacs-server timeout 3 tacacs-server key 7 06051C244F5B1B1C160311 ! ! no vstack banner exec ^CC you are logged in to one of the Saudi Telecom Company network Devices All your activities on this device are logged Node Name: sa61521.stc.com.sa District: Qassim City: buraidah Site: Long Distance Building RACK: 0A Last Change: ^C banner login ^CC Saudi Telecom Company - Data Network ************************************ * * * ##### ####### ##### * * # # # # # * * # # # * * ##### # # * * # # # * * # # # # # * * ##### # ##### * * * ************************************ Unauthorized Access is Prohibited, Access for authorized users only Please enter your username and password.^C ! line con 0 session-timeout 5 exec-timeout 5 0 privilege level 15 password 7 03174F08571B25421E0C1D511442065D17 line vty 0 4 session-timeout 5 access-class 19 in vrf-also exec-timeout 5 0 privilege level 15 password 7 15011F0F553E2F2A7836317610571B5212 logging synchronous login authentication vty transport input ssh transport output all line vty 5 15 session-timeout 5 access-class 19 in vrf-also exec-timeout 5 0 privilege level 15 password 7 15011F0F553E2F2A7836317610571B5212 logging synchronous transport input ssh transport output all ! ntp source Vlan1 ntp access-group peer NTP ntp server 172.20.236.19 ntp server 172.20.165.11 ntp server 172.20.165.12 ntp server 10.97.254.253 end RA12162 con0 is now available Press RETURN to get started. C Saudi Telecom Company - Data Network Unauthorized Access is Prohibited Username: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1) Technical Support: http://www.cisco.com/techsupport Copyright (c) 2006 by cisco Systems, Inc. Initializing memory for ECC . c2811 platform with 262144 Kbytes of main memory Main memory is configured to 64 bit mode with ECC enabled Readonly ROMMON initialized program load complete, entry point: 0x8000f000, size: 0xcb80 program load complete, entry point: 0x8000f000, size: 0xcb80 program load complete, entry point: 0x8000f000, size: 0xef3d74 Self decompressing the image : ########################################################################################################################################################### [OK] monitor: command "boot" aborted due to user interrupt rommon 1 > confreg 0x2142 You must reset or power cycle for new config to take effect rommon 2 > reset c2811 platform with 262144 Kbytes of main memory Main memory is configured to 64 bit mode with ECC enabled Readonly ROMMON initialized program load complete, entry point: 0x8000f000, size: 0xcb80 program load complete, entry point: 0x8000f000, size: 0xcb80 program load complete, entry point: 0x8000f000, size: 0xef3d74 Self decompressing the image : ########################################################################################################################################################### [OK] Smart Init is enabled smart init is sizing iomem ID MEMORY_REQ TYPE 0003E7 0X003DA000 C2811 Mainboard 0X000021B8 Onboard USB 0X002C29F0 public buffer pools 0X00211000 public particle pools TOTAL: 0X008AFBA8 If any of the above Memory Requirements are "UNKNOWN", you may be using an unsupported configuration or there is a software problem and system operation may be compromised. Rounded IOMEM up to: 10Mb. Using 3 percent iomem. [10Mb/256Mb] Restricted Rights Legend Use, duplication, or disclosure by the Government is subject to restrictions as set forth in subparagraph (c) of the Commercial Computer Software - Restricted Rights clause at FAR sec. 52.227-19 and subparagraph (c) (1) (ii) of the Rights in Technical Data and Computer Software clause at DFARS sec. 252.227-7013. cisco Systems, Inc. 170 West Tasman Drive San Jose, California 95134-1706 Cisco IOS Software, 2800 Software (C2800NM-IPBASE-M), Version 12.4(3i), RELEASE SOFTWARE (fc2) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2007 by Cisco Systems, Inc. Compiled Wed 28-Nov-07 21:09 by stshen Image text-base: 0x400A265C, data-base: 0x415402C0 Port Statistics for unclassified packets is not turned on. Cisco 2811 (revision 49.46) with 251904K/10240K bytes of memory. Processor board ID FCZ122370DZ 2 FastEthernet interfaces 2 Channelized E1/PRI ports DRAM configuration is 64 bits wide with parity enabled. 239K bytes of non-volatile configuration memory. 62720K bytes of ATA CompactFlash (Read/Write) --- System Configuration Dialog --- Would you like to enter the initial configuration dialog? [yes/no]: no Press RETURN to get started! *Aug 28 14:57:59.259: %LINK-3-UPDOWN: Interface FastEthernet0/0, changed state to up *Aug 28 14:57:59.259: %LINK-3-UPDOWN: Interface FastEthernet0/1, changed state to up *Aug 28 14:58:00.259: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to down *Aug 28 14:58:00.259: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down *Aug 28 14:58:04.019: %SYS-5-RESTART: System restarted -- Cisco IOS Software, 2800 Software (C2800NM-IPBASE-M), Version 12.4(3i), RELEASE SOFTWARE (fc2) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2007 by Cisco Systems, Inc. Compiled Wed 28-Nov-07 21:09 by stshen *Aug 28 14:58:04.023: %SNMP-5-COLDSTART: SNMP agent on host Router is undergoing a cold start *Aug 28 14:58:05.575: %LINK-5-CHANGED: Interface FastEthernet0/0, changed state to administratively down *Aug 28 14:58:05.575: %LINK-5-CHANGED: Interface FastEthernet0/1, changed state to administratively down Router> Router> Router>en Router# Router# Router# Router#sh Router#show ru Rou