Sayfalar

Friday, September 30, 2011

Sunday, February 27, 2011

GNS3 Topology: Any Transport over MPLS in VLAN Mode

Any Transport over MPLS (AToM) transports data link layer (Layer 2) packets over a Multiprotocol Label Switching (MPLS) backbone. AToM encapsulates Layer 2 frames at the ingress PE and sends them to a corresponding PE at the other end of a pseudowire, which is a connection between the two PE routers. The egress PE removes the encapsulation and sends out the Layer 2 frame.

AToM supports the following like-to-like transport types:
• ATM Adaptation Layer Type-5 (AAL5) over MPLS
• ATM Cell Relay over MPLS
• Ethernet over MPLS (VLAN and port modes)
• Frame Relay over MPLS
• PPP over MPLS
• High-Level Data Link Control (HDLC) over MPLS


BENEFITS of AToM

The AToM product set accommodates many types of Layer 2 packets, including Ethernet and Frame
Relay, across multiple Cisco router platforms, such as the Cisco 7200 and 7500 series routers. This
enables the service provider to transport all types of traffic over the backbone and accommodate all
types of customers.

Upgrading to AToM is transparent to the customer. Because the service provider network is separate from the customer network, the service provider can upgrade to AToM without disruption of service to the customer. The customers assume that they are using a traditional Layer 2 backbone.


PART 1 (Ethernet over MPLS VLAN Based Configuration)



PART 2 (EoMPLS Preferred Path using IP routing)



PART 3 (EoMPLS Preferred Path using MPLS TE and path protection using FRR)

AToM can use MPLS traffic engineering (TE) tunnels with fast reroute (FRR) support. AToM VCs can
be rerouted around a failed link or node at the same time as MPLS and IP prefixes.




http://fengnet.com/book/layer%202%20vpn%20architectures/ch09.html
http://www.cisco.com/en/US/docs/ios/mpls/configuration/guide/12_4t/mp_12_4t_book.html

Monday, February 21, 2011

GNS3 Topology: Layer 3 VPNs Over Multipoint L2TPv3 Tunnels

VPN services have been traditionally deployed over IP core networks by configuring MPLS or through L2TPv3 tunnels using point-to-point links. This feature introduces the capability to deploy layer 3 VPN services by configuring multipoint L2TPv3 tunnels over an existing IP core network. This feature is configured on only the PE routers and requires no configuration on the core routers. The L2TPv3 multipoint tunnel network allows layer 3 VPN services to be carried through the core without the configuration of MPLS. 

Border Gateway Protocol (BGP) is used to advertise the tunnel endpoints and the subaddress family indentifier (SAFI) specific attributes (which contains the tunnel type, and tunnel capabilities). This feature introduces the tunnel SAFI and the BGP SAFI-Specific Attribute (SSA) attribute. The tunnel SAFI defines the tunnel endpoint and carries the endpoint IPv4 address and next hop. The tunnel SAFI is identified by the SAFI number 64. The BGP SSA carries the BGP preference and BGP flags. It also carries the tunnel cookie, tunnel cookie length, and session ID. The BGP SSA is identified by attribute number 19. 

These attributes allow BGP to distribute tunnel encapsulation information between PE routers. VPNv4 traffic is routed through these tunnels. The next hop, advertised in BGP VPNv4 updates, determines which tunnel to use for routing tunnel traffic.

(2008,MPLS VPN over L2TPv3 Tunnels, retrieved from http://www.cisco.com/en/US/docs/ios/12_0s/feature/guide/cs_l3vpn.html, February 2011)



PART 1



PART 2



you can find this topology here

Thursday, February 3, 2011

GNS3 Topology: LAN Protocols over L2TPv3

PART 1 (port to port manual method)



PART 2 (port to port manual session with keepalives)

Monday, January 24, 2011

GNS3 Topology: MPLS Carrier Supporting Carrier Configuration

"Carrier supporting carrier is a term used to describe a situation where one service provider allows another service provider to use a segment of its backbone network. The service provider that provides the segment of the backbone network to the other provider is called the backbone carrier. The service provider that uses the segment of the backbone network is called the customer carrier. A backbone carrier offers Border Gateway Protocol and Multiprotocol Label Switching (BGP/MPLS) VPN services.

The customer carrier can be either:
• An Internet service provider (ISP)
• A BGP/MPLS VPN service provider"

PART 1 (backbone carrier configuration)



PART 2 (Customer Carrier configuration, Customer Carrier isn't running MPLS)



PART 3 (Customer Carrier running MPLS and Customer Carrier providing MPLS VPN service.)






"Lobo L, Lakshman U, 2005, MPLS Configuration on Cisco IOS Software, Cisco Press"

Cisco IOS MPLS Configuration Guide Release 12.4T, 2005, MPLS VPN Carrier Supporting Carrier Using LDP and an IGP,retrieved from http://www.cisco.com/en/US/docs/ios/mpls/configuration/guide/12_4t/mp_12_4t_book.html , jan 2011

Tuesday, January 18, 2011

GNS3 Topology: MPLS Traffic Engineering Fast ReRoute

Fast Reroute

Fast Reroute (FRR) is a mechanism for protecting MPLS TE LSPs from link and node failures by locally repairing the LSPs at the point of failure, allowing data to continue to flow on them while their headend routers attempt to establish new end-to-end LSPs to replace them. FRR locally repairs the protected LSPs by rerouting them over backup tunnels that bypass failed links or nodes. (1)

Prerequisites MPLS TE Fast ReRoute Link and Node Protection

Network must support the following Cisco IOS features:
• IP Cisco Express Forwarding
• Multiprotocol Label Switching (MPLS)

Network must support at least one of the following protocols:
• Intermediate System-to-Intermediate System (IS-IS)
• Open Shortest Path First (OSPF)

Features of MPLS TE FRR Link and Node Protection
  -Backup Tunnel Support
       -Backup Tunnels can terminate at the Next-Next-Hop to support FRR
       -Multiple Backup Tunnels Can Protect the Same Interface
       -Backup Tunnels can Provide Scalability
  -Backup Bandwidth Protection
       -Bandwidth Protection on Backup Tunnels
       -Bandwidth Pool Specifications for Backup Tunnels
       -Semidynamic Backup Tunnel Paths
       -Prioritizing Which LSPs Obtain Backup Tunnels with Bandwidth Protection
  -RSVP Hello





1- Cisco IOS Multiprotocol Label Switching Configuration Guide, Release 12.4T, 2008, retrieved from http://www.cisco.com/en/US/docs/ios/mpls/configuration/guide/12_4t/mp_12_4t_book.html , jan 2011

Friday, January 14, 2011

GNS3 Topology: MPLS Traffic Engineering

Traditional IP-forwarding leads to suboptimal use of available bandwidth between pair of routers in the SP network. The suboptimal paths are under-utilized in IP networks. To avoid packet drops because of inefficient use of available bandwidth, TE is employed to steer some of the traffic, and to enable better bandwidth management and utilization between pair of routers

TE tunnels configured on routers are unidirectional, which means we need to configure a pair of TE tunnel between routers if we want to implement bidirectional TE tunnel.

OSPF or IS-IS with extensions for TE is used to carry information pertaining to the tunnel configured on a router.In OSPF, the LSA type 10 provides information about resource and link status. The inspiration behind MPLS TE is Constraint Based Routing (CBR) and CBR requires IGP like IS-IS or OSPF (IGP must be link-state routing protocol) for its operation. Resource availability and link status information are calculated using a constrained SPF (CSPF) calculation in which factors such as the bandwidth, policies, and topology are taken into consideration to define probable paths from a source to destination.

"Lobo L, Lakshman U, 2005, MPLS Configuration on Cisco IOS Software, Cisco Press"



PART 1 (enabling MPLS and configuring routers for TE support)




PART 2 (configuring headend router, verification and unequal cost load balancing using TE)

Monday, January 10, 2011

GNS3 Topology: Inter Provider MPLS VPN (Back to Back VRF Method)

Inter-Provider VPN feature allows the VPN information to be redistributed between adjacent MPLS VPN entities so that client sites belonging to customer which is dispersed across multiple service provider backbones can communicate with each other.

To maintain the continuity of VPN services across multiple service providers, there are four different options to distribute VPNv4 information across the ASBR routers:

1- Back-to-Back VRF Method
2- Multiprotocol eBGP for VPNv4
3- Multi-hop MP-eBGP between Route-Reflectors
4- Non-VPN transit provider


In this approach, ASBRs are interconnected either via a single link consisting of logical subinterfaces or via multiple physical links. VRFs are configured on the ASBRs to collect VPN client routes. Each subinterface or interface connected between the ASBRs is dedicated to a single client VRF. The single client VRF can run eBGP, RIPv2, EIGRP, OSPF, or static routing to distribute the VPN routes to its adjacent peer.

"Lobo L, Lakshman U, 2005, MPLS Configuration on Cisco IOS Software, Cisco Press"

PART 1 (enabling MPLS and PE-PE routing configuration inside SP 1)



PART 2 (enabling MPLS and PE-PE routing configuration inside SP 2)



PART 3 (Configuring VRF instances and PE-CE routing configuration)



PART 4 (Verification of VPN)

Thursday, January 6, 2011

GNS3 Topology: MPLS VPN Hub and Spoke Topology Configuration

In certain circumstances, it may be desirable to use a hub-and-spoke topology so that all spoke sites send all their traffic toward a central site location. It can be achieved across MPLS VPN.

All traffic from the spoke sites, destined either for the central site services or for intersite connectivity, will flow via the central hub site. With this type of topology, the spoke sites export their routes to the hub site, and then the hub site re-exports the spoke site routes through a second interface (either physical or logical) using a different route target so that other spoke sites can import the routes. This causes the hub site to become a transit point for interspoke connectivity. (Guichard J, Pepelnjak I, 2001, MPLS and VPN Architectures, Cisco Press)

Here is the HUB and SPOKE MPLS VPN configuration. (this topology and configuration was taken from the book "MPLS Configuration On Cisco IOS Software"

PART 1



PART 2

Tuesday, January 4, 2011

GNS3 Topology: MPLS VPN (BGP PE-CE Routing)

In an MPLS VPN network, BGP attributes for a VPN site are transparently transported across the service provider backbone to another site in the same VPN. Because there is a single routing protocol used across the VPN between service provider core and customer sites, the concept of redistribution does not apply.

BGP PE-CE peering in an MPLS VPN environment can be performed in two different ways:

1-) BGP PE-CE VPN sites implementing unique AS numbers (in our example, CUSTOMER A between Site 1 and Site 2)

2-) BGP PE-CE VPN sites implementing same AS numbers   (in our example, CUSTOMER B between Site 1 and Site 2)

There will be no issue when implementing BGP PE-CE routing for customers which use unique AS in both VPN sites. However, using same AS number in both VPN sites causes an issue because of the BGP loop prevention mechanism. if both sites have same AS number, routing updates from one site would be dropped at the other site; therefore, connectivity cannot be established between the sites without additional configuration on PE routers.  ("neighbor XX.XX.XX.XX as-override" under bgp address-family configuration)

here is the configuration of MPLS VPN with BGP PE-CE Routing.

PART 1



PART 2

Tuesday, December 21, 2010

GNS3 Topology: Basic EIGRP Configuration

In these videos, you can find eigrp summarization, authentication, unequal-cost load balancing, other basic eigrp topics. I hope you enjoy it. There is no need to explain eigrp here because there is enough explanation in the videos.

PART 1



PART 2

Friday, December 17, 2010

GNS3 Topology: OSPF AREA TYPEs and LSA TYPEs

PART 1



PART 2





 I think I should begin this topic with OSPF router types. There are 4 types of routers in an OSPF. These are

a- Internal Router: This is a router which has all interfaces connected to same area.

b- Backbone Router: This is a router which has at least one interface connected to area 0.

c- ABR (Area Border Router): this is a router which has interfaces connected to multiple areas.

d- ASBR (autonomous system boundary router): this is a router which has at least one interface connected to an external internetwork.

One router can have multiple roles.


Although we saw only 6 types of LSA, there are 11 types of LSA 

LSA Type     Description

   1                 Router LSA
   2                 Network LSA
3 and 4          Summary LSAs
  5                 AS external LSA
  6                 Multicast OSPF LSA
  7                 Defined for not-so-stubby areas (NSSAs)
  8                 External attributes LSA for Border Gateway Protocol (BGP)
9, 10, 11       Opaque LSAs

Friday, December 10, 2010

GNS3 Topology: Basic iBGP and eBGP Configuration

PART 1

Actually, in this first part of the video, there is nothing about BGP Configuration, rather I tried to prepare my topology for BGP lab. But I wanted to put this video into the blog, because it still shows how to configure frame relay switch in GNS3, and Putty CM.



PART 2



PART 3

GNS Topology: MPLS VPN OSPF PE-CE Routing Configuration

Here is he configuration of MPLS VPN.

PART 1



PART 2



PART 3



PART 4

Tuesday, November 9, 2010

LAYER 2 ATTACKS using YERSINIA

This video is for information only. DO NOT use this in a production network. if you are new in this field like me, you can cause a big mess even if you have a permission.




What is DTP ?
DTP is a dynamic trunking protocol which automates 802.1Q and ISL (inter switch link) configuration. DTP gives switches an ability to to negotiate trunking method with other DTP capable devices. DTP state on switch ports can be set to
  1- Auto             : it does not initiate but it accepts and respond to trunking negotiation
  2- On               : it is manually configured to be a trunk
  3- Off               : it is manually configured to be a access port
  4- Desirable      : it initiates the trunking
  5- Nonegatiate  : no DTP packets are sent.

By default, administrative mode of the ports are not access (off) mode.If the port is in dynamic auto or desirable mode, and if it receives a DTP packet which says " I am a trunk or I want to be a trunk", the port becomes a trunk port. 

  Switchport Mode Access Dynamic Desirable Dynamic Auto Trunk
Access No Trunk No Trunk No Trunk No Trunk
Dynamic Auto No Trunk Trunk No Trunk Trunk
Dynamic Desirable No Trunk Trunk Trunk Trunk
Trunk No Trunk Trunk Trunk Trunk

By default trunk ports have access all VLANs. If an attacker's machine can spoof as a switch, the attacker then becomes a member of all VLANs.  

What is STP ?
STP is spanning tree protocol which is used to prevent loops in a switched networks. To provide loop-free switched networks, switches have to choose a root bridge and consider their ports' roles such as root, designated, or blocked. Root bridge is a switch with a smallest Bridge-ID (bridge-id has a two number 1-MAC address of the switch, and 2- configurable priority between 0 - 65535) After determining the root bridge, switches determines the least cost to reach the root bridge.

If the attacker spoof his/her system as a root bridge in the topology, the attacker can see variety of frames or can cause the network become down. To spoof, the attacker broadcast conf BPDU and tcn BPDU to force spanning tree recalculations. (BPDU: Bridge Protocol Data Unit)

What is CDP ?
"The Cisco Discovery Protocol (CDP) is a prapriotery  Layer2 network protocol which is implemented in most Cisco networking equipment. It is used to share information about other directly connected Cisco equipment, such as the operating system, device ID, version or IP address." (http://en.wikipedia.org/wiki/Cisco_Discovery_Protocol)


YERSINIA

Yersinia is a network tool designed to take advantage of some weakeness in different network protocols. It pretends to be a solid framework for analyzing and testing the deployed networks and systems. You can find more detailed information here and the man page here

 

GNS3 Topology: Basic Switch Configuration

Actually, the intention of this video is not to show how switch configuration is done. I was creating my playground to learn how YERSINIA works. If you are preparing for CCNA, this video may help you understand basics of VLAN and VLAN Trunking Protocol configurations. But in a real switch (not etherswitch module) configuring VLANs is a little bit different and easier. You should also see the video "Layer2 attacks using yersinia" to understand how important layer2 security is.


enjoy!

Friday, November 5, 2010

ARP POISONING

I haven't made any video for more than two weeks. This doesn't mean that I stopped studying for exams. After I finished to study about firewall, I tried to emulate Cisco IDS ( version 6.X). I found very useful articles about it on forums like 7200emu and of course wiki. Yes, now, I can emulate Cisco IDS using GNS3. (Some say that they emulates 6.x on vmware but I couldn't able to emulate it.) After I learned a little bit about IDS I tried to make video but I realized that I don't know anything about real world attacks to demonstrate how IDS works. To make long story short, I change my track and I decided to learn Linux (Because most of the security tools run on Linux) and some useful tools about security before I continue for CCSP IDS. (it is actually not good for me, because CCSP exams are going to be changed and I am not sure that I can find any platform to study new exam topics such as IDS v7)

This video is about ARP poisoning. It is simpler than I thought.     





How does Address Resolution Protocol work ?

Imagine we have computers Host A and Host B. We also assume that these computers have never previously communicated.
1- Host A would like to send Host B some data.
2-Host A looks in its ARP Cache and determines if an IP->MAC mapping exists.
3- Because they have never communicated before, a mapping does not exist.
4- Host A sends an ARP Request that says, "Who has the IP of Host B Tell Host A"
5- Host B is listening and replies, "IP B is MAC of B".
6- Host A updates it's ARP table with the IP->Mac mapping.

How does ARP Poisoning works
Well, you can find it in video.