13 janv. 2012

[rbak-nsp] Internal icmp ratelimiting?

Show card X icmp  

12 janv. 2012

PTA

lac:



hostname R1 

! 
no ip domain lookup 
! 
ip cef 
vpdn enable 
! 
vpdn-group pppoetest 
 accept-dialin 
  protocol pppoe 
  virtual-template 1 
! 
interface Loopback0 
 ip address 1.1.1.1 255.255.255.255 
! 
interface FastEthernet0/0 
 ip address 10.10.10.1 255.255.255.0 
 pppoe enable 
! 
interface Virtual-Template1 
 mtu 1492 
 ip unnumbered FastEthernet0/0 
 peer default ip address pool pppoepool 
! 
ip local pool pppoepool 10.10.10.2 10.10.10.100





client:



hostname R2 

! 
no ip domain lookup 
! 
ip cef 
! 
interface FastEthernet0/0 
 no ip address 
 pppoe enable 
 pppoe-client dial-pool-number 1 
! 
interface Dialer1 
 mtu 1492 
 ip address negotiated 
 encapsulation ppp 
 dialer pool 1 
 dialer-group 1 
 no peer neighbor-route 
! 
ip route 0.0.0.0 0.0.0.0 Dialer1 
! 
dialer-list 1 protocol ip permit

LAC - LNS - PPP, PPPoE, L2TP

LNS:
!
hostname LNS
!
vpdn enable
vpdn multihop
!
vpdn-group L2TP-LNS
 accept-dialin
  protocol l2tp
  virtual-template 1
 terminate-from hostname LAC
 local name LNS
 no l2tp tunnel authentication
 relay pppoe bba-group PPPoE
!
bba-group pppoe PPPoE
 virtual-template 1
!         
interface Loopback0
 ip address 10.0.0.3 255.255.255.255
!
interface Loopback999
 description for_tests
 ip address 1.1.1.1 255.255.255.255
!
interface FastEthernet1/0
 no ip address
 no shutdown

 duplex auto
 speed auto

 no keepalive
!
interface FastEthernet1/0.203
 encapsulation dot1q 203
 ip address 192.168.23.3 255.255.255.0
!
interface Virtual-Template1
 ip unnumbered Loopback0
 peer default ip address pool PPP_Pool
 keepalive 240
!
ip local pool PPP_Pool 210.1.1.1 210.1.1.254
ip route 10.0.0.2 255.255.255.255 192.168.23.2 name LNS-to-LAC
!
no cdp run
!


LAC:
hostname LAC
!
subscriber profile PPPoE_Profile
 service relay pppoe vpdn group L2TP-LAC
!
vpdn enable
vpdn source-ip 10.0.0.2
!
vpdn-group L2TP-LAC
 request-dialin
  protocol l2tp
  domain test.com
 initiate-to ip 10.0.0.3 
 local name LAC
 no l2tp tunnel authentication
 l2tp tunnel receive-window 1         
!
bba-group pppoe PPPoE
 virtual-template 1
 service profile PPPoE_Profile
!
!
interface Loopback0
 ip address 10.0.0.2 255.255.255.255
!
interface FastEthernet1/0
 no ip address
 no shutdown

 duplex auto
 speed auto

 no keepalive
!
interface FastEthernet1/0.102
 encapsulation dot1q 102
 no ip address
 pppoe enable group PPPoE
!
interface FastEthernet1/0.203
 encapsulation dot1q 203
 ip address 192.168.23.2 255.255.255.0
!
interface Virtual-Template1
 ip unnumbered Loopback0
!
ip route 10.0.0.3 255.255.255.255 192.168.23.3 name LAC-to-LNS
!
no cdp run
!

CPE:
!
hostname CPE
!
interface Loopback0
 ip address 123.123.123.123 255.255.255.255
!
interface FastEthernet1/0
 no ip address
 no shutdown

 duplex auto
 speed auto

 no keepalive
!
interface FastEthernet1/0.102
 encapsulation dot1q 102
 pppoe enable group global
 pppoe-client dial-pool-number 1
!         
interface Dialer1
 ip address negotiated
 encapsulation ppp
 dialer pool 1
 dialer idle-timeout 0
 dialer-group 1
 ppp ipcp route default
!
no cdp run
!



To take traces:
  • no cdp run 
  • no keepalive on interfaces
  • change keepalive (240s) on interface Dialer 1 (CPE) and interface Virtual-Template (LNS).




15 déc. 2011

Frame relay and inverse-arp

no frame-relay inverse arp says that I shall not ask the other end what his IP address is.

no arp frame-relay means that if the other end asks me my IP address, I shall not answer him.

29 nov. 2011

Create ACL on eXtreme Network Switches...



First, create a policy.    Enter command:

vi no67udp.pol

(use a pol extension)

(ls command will list the files/configs on the XOS switch...linux)  The following is needed in the policy (I add count so I can see the number of packet hits...it's not required):

entry drop1 {
        if match all {
                protocol                udp;
                source-port             67;
         } then {
            deny;
                count drop1;
  }

}
entry drop2{
        if match all {
                protocol                udp;
                destination-port        67;
         } then {
            deny;
                count drop2;
  }
}


After you've wq that (if you're doing vi) then you're ready to apply the policy/access-list.  Enter the following commands:

check policy no67udp
(to make sure there are no errors and don't use .pol extension)

Next, apply to the ports:

configure access-list no67udp port 1-11,13-24 (or 26)
(it should respond with done!)

You can then show access-list or show access-list counter to see
if there are any hits.

To remove the access-list enter:

unconfigure access-list no67udp

You can edit the access-list while it's running and then after the
check policy command you will need to enter:

refresh policy no67udp

to make the changes take affect.  I think that's all you need. 
There's probably a better way and someone
with more experience than me might know.  But
this should deny all 67 udp packets from all ports but 12.

27 nov. 2011

OSPF Authentication #1

Three authentication modes:
  • 0 - null, no authentication
  • 1 - clear-text
  • 2 - md5
Per interface authentication
r1(config)#interface s1/0
r1(config-if)#ip ospf authentication ?
  message-digest  Use message-digest authentication
  null            Use no authentication


MD5 Authentication:


If "ip ospf authentication message-digest", then:
r1(config-if)#ip ospf message-digest-key 1 md5 ccie_lab


If you just entered "ip ospf authentication", it is clear-text authentication, then:
r1(config-if)#ip ospf authentication-key joe

Bad configuration #1: 

interface Serial1/1
 ip address 13.0.0.1 255.255.255.0
 ip ospf authentication-key joe


There is no authentication here, but it works. Check with show ip ospf interface.



Bad configuration #2: 

interface Serial1/1

 ip ospf authentication message-digest
 ip ospf authentication-key joe


There is md5 authentication here, but there is no md5 password specified, it works:
r1#show ip ospf interface Serial1/1
Serial1/1 is up, line protocol is up 
[...]
  Message digest authentication enabled
      No key configured, using default key id 0

Don't forget to use the same key id on both sides, else it won't work. Multiple key numbers can exist on the same interface.


Area Authentication


Authentication can be configured for the whole area (md5 or plain-text).
On each router:
router ospf 1
 area 0 authentication message-digest
And on all interface configured with area 0:

interface Serial1/0
 ip ospf message-digest-key 1 md5 CCIE_LAB


Note that here, there is no need to configure "ip ospf authentication message-digest" on the interface.


If using a Virtual_Link (which belong to area 0), configure on each router (even if no interfaces belongs to area 0):



router ospf 1
 area 0 authentication message-digest
 message-digest-key 1 md5 CCIE_LAB
 area 234 virtual-link 2.2.2.2 authentication 



Troubleshooting
Always look at "show ip ospf interface (intf)" and see what's happening.  If you see "key 0" is used in MD5, then you will NOT be getting credit for that section where they likely tell you to use "cisco" as the password!


To check authentication problems:
r1#debug ip ospf adj 


00:39:54: OSPF: Rcv pkt from 13.0.0.3, Serial1/1 : Mismatch Authentication type. Input packet specified type 2, we use type 0


00:40:04: OSPF: Rcv pkt from 13.0.0.3, Serial1/1 : Mismatch Authentication type. Input packet specified type 2, we use type 1

00:51:54: OSPF: Rcv pkt from 13.0.0.3, Serial1/1 : Mismatch Authentication Key - No message digest key 0 on interface



OSPF Virtual links

OSPF Virtual links are mainly used to avoid partitionned areas.


r1 and r2 belongs to area 0.
r1 and r3 to area 13, r3's loopback0 belongs to area 13.
r2, r3 and r4 to area 234.


If the link between r1 and r3 goes down, r3's loopback 0 becomes unreachable because area 13 has no connectivity with area 0 to reach other areas.
To avoid this, a virtual-link is established betwen the ABR, r3 and r2. This virtual-link belong to area 0.


Configuration:


r1:
!

interface Loopback0
 ip address 1.1.1.1 255.255.255.0
 ip ospf network point-to-point

!

!
interface Serial1/0
 ip address 12.0.0.1 255.255.255.0

!
interface Serial1/1
 ip address 13.0.0.1 255.255.255.0

!
router ospf 1
 router-id 1.1.1.1
 log-adjacency-changes
 redistribute connected subnets
 network 12.0.0.1 0.0.0.0 area 0
 network 13.0.0.1 0.0.0.0 area 13
!


On r2:

interface Loopback0
 ip address 2.2.2.2 255.255.255.0
 ip ospf network point-to-point
!

interface Serial1/0
 ip address 12.0.0.2 255.255.255.0
!

interface Serial1/1
 ip address 24.0.0.2 255.255.255.0
!

!
router ospf 1
 router-id 2.2.2.2
 log-adjacency-changes
 redistribute connected subnets
 network 12.0.0.2 0.0.0.0 area 0
 network 24.0.0.2 0.0.0.0 area 234
!






On r3:
!

interface Loopback0
 ip address 3.3.3.3 255.255.255.0
 ip ospf network point-to-point


!
interface Serial1/0
 ip address 34.0.0.3 255.255.255.0
! interface Serial1/1
 ip address 13.0.0.3 255.255.255.0
!
router ospf 1

 router-id 3.3.3.3
 log-adjacency-changes
 redistribute connected subnets
 network 3.3.3.3 0.0.0.0 area 13
 network 13.0.0.3 0.0.0.0 area 13
 network 34.0.0.3 0.0.0.0 area 234
!




r4:
!
interface Loopback0
 ip address 4.4.4.4
 ip ospf network point-to-point
!
interface Serial1/0
 ip address 24.0.0.4 255.255.255.0
!
interface Serial1/1
 ip address 34.0.0.4 255.255.255.0
!

router ospf 1
 router-id 4.4.4.4
 log-adjacency-changes
 redistribute connected subnets
 network 24.0.0.4 0.0.0.0 area 234
 network 34.0.0.4 0.0.0.0 area 234
!



To create the virtual-link through area 234 (using OSPF router-id), configure the ABR:
On r2:
!
router ospf 1
 area 234 virtual-link 3.3.3.3
!


On r3:
!

router ospf 1
 area 234 virtual-link 2.2.2.2
!


r3#show ip ospf neighbor 


Neighbor ID     Pri   State           Dead Time   Address         Interface
2.2.2.2           0   FULL/  -           -        24.0.0.2        OSPF_VL1
1.1.1.1           0   FULL/  -        00:00:33    13.0.0.1        Serial1/1
4.4.4.4           0   FULL/  -        00:00:38    34.0.0.4        Serial1/0


r3#show ip ospf interface brief 
Interface    PID   Area            IP Address/Mask    Cost  State Nbrs F/C
Vl1          1     0               34.0.0.3/24        128   P2P   1/1
Lo0          1     13              3.3.3.3/24         1     P2P   0/0
Se1/1        1     13              13.0.0.3/24        64    P2P   1/1
Se1/0        1     234             34.0.0.3/24        64    P2P   1/1









NTP - ACL

NTP - Network Time Protocol Packet types: -  Control messages : don't bother with this. -  NTP request/update messages: used for time sy...