Showing posts with label computer science. Show all posts
Showing posts with label computer science. Show all posts

Thursday, April 13, 2017

CWNA (Wireless Network Introduction)

CWNA (Cisco Wireless Network Associate)
Radio Frequency: Radio frequency is high frequency alternating current (AC) signals that are passed along a copper conductor and then radiated into the air via an antenna. An antenna converts/transforms a wired signal to a wireless signal and vice versa. When the high frequency AC signal is radiated into the air, it forms radio waves. These radio waves propagate (move) away from the source (the antenna) in a straight line in all directions at once.

Antenna: Antennas convert electrical energy into RF waves in the case of a transmitting antenna, or RF waves into electrical energy in the case of a receiving antenna. The physical dimensions of an antenna, such as its lenght, are directly related to the frequency at which the antenna can propagate waves or receive propagated waves.
Bandwidth: Bandwidth equal Frequency weight.
SSID Information: Stations look in beacons for the SSID of the network they wish to join. When this information is found, the station looks at the MAC address of where the beacon originated and sends an authentication request in hopes of associating with that access point.
If a station is set to accept any SSID, then the station will attempt to join the network through the first access point that sends a beacon or the one with the strongest signal strength if there are multiple access points
Wireless operation: Client and Access point Association:
  • AP Signals: Beacon
  • Client Signals: Probe
  • Authentication: A. Open authentication. B. Share key authentication
  • Association
Channels: A frequency hopping system will operate using a specified hop pattern called a channel. Frequency hopping systems typically use the FCC’s 26 standard hop patterns or a subset thereof. Some frequency hopping systems will allow custom hop patterns to be created, and others even allow synchronization between systems to completely eliminate collisions in a co-located environment.
Hop time: Hop time is a time which is use between one frequency to another frequency, when jumping.
Dwell time: When discussing frequency hopping systems, we are discussing systems that must transmit on a specified frequency for a time, and then hop to a different frequency to continue transmitting.
When a frequency hopping system transmits on a frequency, it must do so for a specified amount of time. This time is called the dwell time. Once the dwell time has expired, the system will switch to a different frequency and begin to transmit again. Suppose a frequency hopping system transmits on only two frequencies, 2.401 GHz and 2.402 GHz. The system will transmit on the 2.401 GHz frequency for the duration of the dwell time—100 milliseconds (ms), for example.
After 100ms the radio must change its transmitter frequency to 2.402 GHz and send information at that frequency for 100ms.
Co-location: To use DSSS systems with overlapping channels in the same physical space would cause interference between the systems. DSSS systems with overlapping channels should not be co-located because there will almost always be a drastic or complete reduction in throughput. Because the center frequencies are 5 MHz apart and the channels are 22 MHz wide, channels should be co-located only if the channel numbers are at least five apart: channels 1 and 6 do not overlap, channels 2 and 7 do not overlap, etc. There is a maximum of three co-located direct sequence systems possible because channels 1, 6 and 11 are the only theoretically non-overlapping channels.
ISM and UNII Bands: The FCC establishes rules limiting which frequencies wireless LANs can use and the output power on each of those frequency bands. The FCC has specified that wireless LANs can use the ISM (Industrial Scientific and Medical) bands, which are license free. The ISM bands are located starting at 902 MHz, 2.4 GHz, and 5.8 GHz and vary in width from about 26 MHz to 150 MHz. In addition to the ISM bands, the FCC specifies three Unlicensed National Information Infrastructure (UNII) bands. Each one of these UNII bands is in the 5 GHz range and is 100 MHz wide.
Unlicensed National Information Infrastructure (UNII) Bands:

The 5 GHz UNII bands are made up of three separate 100 MHz-wide bands, which are used by 802.11 -compliant devices. The three bands are known as the lower, middle, and upper bands. Within each of these three bands, there are four non-overlapping DSSS channels, each separated by 5 MHz. The FCC mandates that the lower band be used indoors, the middle band be used indoors or outdoors, and the upper band be allocated for outdoor use. Since access points are mostly mounted indoors, the 5 GHz UNII bands would allow for 8 non-overlapping access points indoors using both the lower and middle.
Frequency Hopping Spread Spectrum (FHSS): Frequency hopping spread spectrum is a spread spectrum technique that uses frequency agility to spread the data over more than 83 MHz. Frequency agility refers to the radio’s ability to change transmission frequency abruptly within the usable RF frequency band. In the case of frequency hopping wireless LANs, the usable portion of the 2.4 GHz ISM band is 83.5 MHz, per FCC regulation and the IEEE 802.11 standard.
Direct Sequence Spread Spectrum (DSSS): Direct sequence spread spectrum is very widely known and the most used of the spread spectrum types, owing most of its popularity to its ease of implementation and high data rates. The majority of wireless LAN equipment on the market today uses DSSS technology. DSSS is a method of sending data in which the transmitting and receiving systems are both on a 22 MHz-wide set of frequencies. The wide channel enables devices to transmit more information at a higher data rate than current FHSS systems.
Direct Sequence Systems
In the 2.4 GHz ISM band, the IEEE specifies the use of DSSS at a data rate of 1 or 2Mbps under the 802.11 standard. Under the 802.11b standard—sometimes called high rate wireless—data rates of 5.5 and 11 Mbps are specified. IEEE 802.11b devices operating at 5.5 or 11 Mbps are able to communicate with 802.11 devices operating at 1 or 2 Mbps because the 802.11b standard provides for backward compatibility. A recent addition to the list of devices using direct sequence technology is the IEEE 802.11a standard, which specifies units that can operate at up to 54 Mbps.  Unfortunately , 802.11a is wholly incompatible with 802.11b because it does not use the 2.4 GHz band, but instead uses the 5 GHz UNII bands. Recently the IEEE 802.11g standard was approved to specify direct sequence systems operating in the 2.4 GHz ISM band that can deliver up to 54 Mbps data rate. The 802.11g technology became the first 54 Mbps technology that was backward compatible with 802.11 and 802.11b devices.
WLAN Standards: The Institute of Electrical and Electronics Engineers (IEEE) is the key standards maker for most things related to information technology in the United States. The IEEE creates its standards within the laws created by the FCC. The IEEE specifies many technology standards such as Public Key Cryptography (IEEE 1363), Ethernet (IEEE 802.3), and Wireless LANs (IEEE 802.11). It is part of the mission of the IEEE to develop standards for wireless LAN operation within the framework of the FCC rules and regulations. Following are the four main IEEE standards for WLAN.
  • IEEE 802.11
  • IEEE 802.11b
  • IEEE 802.11a
  • IEEE 802.11g
  • IEEE 802.11n
  • IEEE 802.11e
 IEEE 802.11: The 802.11 standard was the first standard describing the operation of wireless LANs. This standard contained all of the available transmission technologies including Direct Sequence Spread Spectrum (DSSS), Frequency Hopping Spread Spectrum (FHSS), and infrared. The IEEE 802.11 standard describes DSSS systems that operate at 1 Mbps and 2 Mbps only. IEEE 802.11 is one of two standards that describe the operation of frequency hopping wireless LAN systems. The 802.11 standard describes use of FHSS systems at 1 and 2 Mbps.
802.11 compliant products operate strictly in the 2.4 GHz ISM band between 2.4000 and 2.4835 GHz. Infrared, also covered by 802.11, is light-based technology and does not fall into the 2.4 GHz ISM band.
IEEE 802.11b: DSSS systems that operate at 1, 2, 5.5 and 11 Mbps. The 802.11b standard does not describe any FHSS systems. 802.11b-compliant devices are also 802.11-compliant by default, meaning they are backward compatible and support both 2 and 1 Mbps data rates. Backward compatibility is very important because it allows a wireless LAN to be upgraded without the cost of replacing the core hardware.
IEEE 802.11a: Describe WLAN operation in the “UNII” band. Operation in a different frequency band. Compatibale with 802.11b, 5GHz frequency band. Max data rate of 54Mbps (Typically 20-25Mbps), 12 Non-overlapping chanels, 8 outdor, 4 PTP.
IEEE 802.11g: 802.11g provides the same maximum speed of 802.11a, coupled with backwards compatibility for 802.11b devices. This backwards compatibility will make upgrading wireless LANs simple and inexpensive. IEEE 802.11g specifies operation in the 2.4 GHz ISM band. To achieve the higher data rates found in 802.11a, 802.11g compliant devices utilize Orthogonal Frequency Division Multiplexing (OFDM) modulation technology. These devices can automatically switch to QPSK modulation in order to communicate with the slower 802.11b- and 802.11-compatable devices.
IEEE 802.11n: IEEE 802.11n-2009, commonly shortened to 802.11n, is a wireless networking standard that uses multiple antennas to increase data rates. It is an amendment to the IEEE 802.11-2007 wireless networking standard. Its purpose is to improve network throughput over the two previous standards—802.11a and 802.11g—with a significant increase in the maximum net data rate from 54 Mbit/s to 600 Mbit/s. with the use of four spatial streams at a channel width of 40 MHz. 802.11n standardized support for multiple-input multiple-output and frame aggregation, and security improvements, among other features. It can be used in the 2.4 GHz or 5 GHz frequency bands.
WIMAX Technology: IEEE 802.16e standard broadband wireless access (BWA) working group.
Blutooth Technology: IEEE 802.15.1 Standard.
RF Behaviors
Loss: Loss describes a decrease in signal strength. Many things can cause RF signal loss, both while the signal is still in the cable as a high frequency AC electrical signal and when the signal is propagated as radio waves through the air by the antenna.
Resistance of cables and connectors causes loss due to the converting of the AC signal to heat. Impedance mismatches in the cables and connectors can cause power to be reflected back toward the source, which can cause signal degradation. Objects directly in the propagated wave's transmission path can absorb, reflect, or destroy RF signals. Loss can be intentionally injected into a circuit with an RF attenuator. RF attenuators are accurate resistors that convert high frequency AC to heat in order to reduce signal amplitude at that point in the circuit.
Gain: Gain is the term used to describe an increase in an RF signal's amplitude. Gain is usually an active process; meaning that an external power source, such as an RF amplifier, is used to amplify the signal or a high-gain antenna is used to focus the beamwidth of a signal to increase its signal amplitude.
Reflection: Reflection occurs when a propagating electromagnetic wave impinges upon an object that has very large dimensions when compared to the wavelength of the propagating wave. Reflections occur from the surface of the earth, buildings, walls, and many other obstacles. RF signal reflection can cause serious problems for wireless LANs. This reflecting of the main signal from many objects in the area of the transmission is referred to as multipath.
Multipath can have severe adverse affects on a wireless LAN, such as degrading or, canceling the main signal and causing holes or gaps in the RF coverage area. Surfaces such as lakes, metal roofs, metal blinds, metal doors, and others can cause severe reflection, and hence, multipath. Reflection of this magnitude is never desirable and typically requires special functionality (antenna diversity) within the wireless LAN hardware to compensate for it.
Refraction: Refraction describes the bending of a radio wave as it passes through a medium of different density. As an RF wave passes into a denser medium (like a pool of cold air lying in a valley) the wave will be bent such that its direction changes. When passing through such a medium, some of the wave will be reflected away from the intended signal path, and some will be bent through the medium in another direction.
Diffraction: Diffraction occurs when the radio path between the transmitter and receiver is obstructed by a surface that has sharp irregularities or an otherwise rough surface. At high frequencies, diffraction, like reflection, depends on the geometry of the obstructing object and the amplitude, phase, and polarization of the incident wave at the point of diffraction.
Scattering: Scattering occurs when the medium through which the wave travels consists of objects with dimensions that are small compared to the wavelength of the signal, and the number of obstacles per unit volume is large. Scattered waves are produced by rough surfaces, small objects, or by other irregularities in the signal path.
Voltage Standing Wave Ratio (VSWR): VSWR occurs when there is mismatched impedance (resistance to current flow, measured in Ohms) between devices in an RF system. VSWR is caused by an RF signal reflected at a point of impedance mismatch in the signal path.
VSWR causes return loss, which is defined as the loss of forward energy through a system due to some of the power being reflected back towards the transmitter. If the impedances of the ends of a connection do not match, then the maximum amount of the transmitted power will not be received at the antenna. When part of the RF signal is reflected back toward the transmitter, the signal level on the line varies instead of being steady. This variance is an indicator of VSWR.
Line of Sight (LOS):
With visible light, visual LOS (also called simply ‘LOS’) is defined as the apparently straight line from the object in sight (the transmitter) to the observer's eye (the receiver). The LOS is an apparently straight line because light waves are subject to changes in direction due to refraction, diffraction, and reflection in the same way as RF frequencies.
Fresnel Zone:
The Fresnel Zone occupies a series of concentric ellipsoid-shaped areas around the LOS path,  The Fresnel Zone is important to the integrity of the RF link because it defines an area around the LOS that can introduce RF signal interference. if blocked. Objects in the Fresnel Zone such as trees, hilltops, and buildings can diffract or reflect the main signal away from the receiver, changing the RF LOS. These same objects can absorb or scatter the main RF signal, causing degradation or complete signal loss. 
WLAN Infrastructure Devices
Access Point: The access point, or “AP”, is probably the most common wireless LAN device with which you will work as a wireless LAN administrator. As its name suggests, the access point provides clients with a point of access into a network. An access point is a half-duplex device with intelligence equivalent to that of a sophisticated Ethernet switch.
Access Point Modes: Access points communicate with their wireless clients, with the wired network, and with other access points. There are three modes in which an access point can be configured:
  1. Root Mode
  2. Repeater Mode
  3. Bridge Mode

Root Mode: Root Mode is used when the access point is connected to a wired backbone through its wired  interface. Most access points that support modes other than root mode come configured in root mode by default. When an access point is connected to the wired segment through its Ethernet port, it will normally be configured for root mode. When in root mode, access points that are connected to the same wired distribution system can talk to each other over the wired segment. Access points talk to each other to coordinate roaming functionality such as reassociation. Wireless clients can communicate with other wireless clients that are located in different cells through their respective access points across the wired segment.
Bridge Mode: In bridge mode, access points act exactly like wireless bridges. In fact, they become wireless bridges while configured in this manner.
Repeater Mode:

In repeater mode, access points have the ability to provide a wireless upstream link into the wired network rather than the normal wired link. One access point serves as the root access point and the other serves as a wireless repeater. The access point in repeater mode connects to clients as an access point and connects to the upstream root access point as a client itself. Using an access point in repeater mode is not suggested unless absolutely necessary because cells around each access point in this scenario must overlap by a minimum of 50%. Additionally, the repeater access point is communicating with the clients as well as the upstream access point over the wireless link, reducing throughput on the wireless segment. Users attached to the repeater access point will likely experience low throughput and high latencies in this scenario.
Scanning: When you install, configure, and finally start up a wireless LAN client device the client will automatically “listen" to see if there is a wireless LAN within range. The client is also discovering if it can associate with that wireless LAN. This process of listening is called scanning. Scanning occurs before any other process, since scanning is how the client finds the network.
Passive Scanning: Passive scanning is the process of listening for beacons on each channel for a specific period of time after the station is initialized. These beacons are sent by access points (infrastructure mode) or client stations (ad hoc mode), and the scanning station catalogs characteristics about the access points or stations based on these beacons. The station searching for a network listens for beacons until it hears a beacon listing the SSID of the network it wishes to join. The station then attempts to join the network through the access point that sent the beacon. In configurations where there are multiple access points, the SSID of the network the station wishes to join may be broadcast by more than one of these access points. In this situation, the station will attempt to join the network through the access point with the strongest signal strength and the lowest bit error rate. Stations continue passive scanning even after associating to an access point. Passive scanning saves time reconnecting to the network if the client is disconnected (disassociated) from the access point to which the client is currently connected. By maintaining a list of available access points and their characteristics (channel, signal strength, SSID, etc), the station can quickly locate the best access point should its current connection be broken for any reason. Stations will roam from one access point to another after the radio signal from the access point where the station is connected gets to a certain low level of signal strength. Roaming is implemented so that the station can stay connected to the network. Stations use the information obtained through passive scanning for locating the next best access point (or ad hoc network) to use for connectivity back into the network. For this reason, overlap between access point cells is usually specified at approximately 20-30%. This overlap allows stations to seamlessly roam between access points while disconnecting and reconnecting without the user’s knowledge.

Active scanning: Active scanning involves the sending of a probe request frame from a wireless station. Stations send this probe frame when they are actively seeking a network to join. The probe frame will contain either the SSID of the network they wish to join or a broadcast SSID. If a probe request is sent specifying an SSID, then only access points that are servicing that SSID will respond with a probe response frame. If a probe request frame is sent with a broadcast SSID, then all access points within reach will respond with a probe response frame. The point of probing in this manner is to locate access points through which the station can attach to the network. Once an access point with the proper SSID is found, the station initiates the authentication and association steps of joining the network through that access point.

Authentication & Association: The process of connecting to a wireless LAN consists of two separate sub-processes. These sub-processes always occur in the same order, and are called authentication and association. For example, when we speak of a wireless PC card connecting to a wireless LAN, we say that the PC card has been authenticated by and has associated with a certain access point.
Authentication: The first step in connecting to a wireless LAN is authentication. Authentication is the process through which a wireless node (PC Card, USB Client, etc.) has its identity verified by the network (usually the access point) to which the node is attempting to connect.
This verification occurs when the access point to which the client is connecting verifies that the client is who it says it is.
Association: Once a wireless client has been authenticated, the client then associates with the access point. Associated is the state at which a client is allowed to pass data through an access point.
If your PC card is associated to an access point, you are connected to that access point, and hence, the network. The process of becoming associated is as follows. When a client wishes to connect, the client sends an authentication request to the access point and receives back an authentication response. After authentication is completed, the station sends an association request frame to the access point who replies to the client with an association response frame either allowing or disallowing association.

Sunday, April 9, 2017

WAN (Wide Area Network)

WAN Network
WAN is use to connect network of different geographical areas.
CSU/DSU is a device use in wan, CSU stand for channel service unit. DSU stand for data service unit.

CSU/DSU is use for avoiding local loop.
WAN Technologies: leased line, circuit switching, and packet switching.
  1. Leased line technology: in this technology two routers can connect purchased a dedicated line. i.e. E1, T2, T3. E1 line provides 2.048 mbps speed. T2 line provides 1.544 mbps speed. T3 line provides 45 mbps speed. Advantage of leased line: always available. Disadvantage: it is very expensive.
  2. Circuit switching technology: work on physical circuit same as telephone line. In circuit switching wireless modem and ISD are used. ISDN (integrated services digital network).
  3. Packet switching technology: work on virtual circuit, in this logical bandwidth is build. Same as road/highway which are divided logically.
Types of virtual circuit:
  • Permanent virtual circuit (PVC): same as leased line but it is not dedicated; frame relay is use in (PVC)
  • Switch virtual circuit (SVC): same as ISDN, ATM is use in switch virtual circuit (SVC)
WAN Protocols: HDLC (high level data link control), PPP (Point to Point Protocol), Frame Relay.
HDLC: always use in leased line, data link layer protocol. HDLC is CISCO proprietary protocol; provide no security (authentication).
To change protocol: Router(config)# interface s0/0
Router(config-if)# encapsulation PPP
PPP: Support multi vendors (CISCO, Juniper etc), can work on lease line and circuit switching. PPP provide security (authentication) for authentication two protocols are used.
  • PAP (password authentication protocol): send user name and password in plain text form.
  • CHAP (challenge handshake authentication): send user name and password in encrypted form.

PPP consist of two ports: LCP (link control protocol), NCP (network control protocol).
LCP perform following task: connection establishment, compression, authentication, multi-link.
NCP allow multiple routed protocols to send data.
PPP configuration:
Router1(config)# hostname Branch
Branch(config)# enable secret CISCO
Branch(config)# username Head password icne@123
Branch(config)# interface serial 0/0
Branch(config-if)# encapsulation PPP
Branch(config-if)# ppp authentication pap/chap
Branch(config-if)# ip address 10.0.0.1 255.0.0.0
Branch(config-if)# no shutdown
Branch(config-if)# clock rate 64000
Router2(config)# hostname Head
Head(config)# enable secret Microsoft
Head(config)# user name Branch Password icne@123
Head(config)# interface serial 0/0
Head(config-if)# encapsulation ppp
Head(config-if)# ip address 10.0.0.2 255.0.0.0
Head(config-if)# no shutdown
Frame Relay: Frame relay is a packet switching technology, frame relay use a packet switching type called PVC. Frame relay use a number called DLCI (Data link connection identifier).
DLCI use to identify PVC connection, in frame relay leased line but not dedicated.
Encapsulation: Frame relay (only use on CISCO routers), IETF (Globally used).
LMI (local management interface): through LMI packets are share between frame relay routers and switches.
LMI Types: CISCO LMI (use only on CISCO routers)
ANSI LMI (Globally used).

Frame relay configuration
Router1(config)# interface s0/0/0
Router1(config-if)# no ip address
Router1(config-if)# no shutdown
Router1(config-if)# encapsulation frame-relay
Router1(config)# interface s0/0/0.102 point-to-point
Router1(config-router1)# ip address 1.1.1.100 255.255.255.0
Router1(config-router)# bandwith 64
Router1(config-router1)# frame-relay interface-dlci 102
Router1(config-router1)# frame-relay lmi-type cisco, ansi, q933a (optional)
Router1(config)# interface s0/0/0.103 point-to-point
Router1(config-router1)# ip address 2.2.2.100 255.255.255.0

Router1(config-router1)# bandwith 64
Router1(config-router1)# frame-relay interface-dlci 103
Router1# show frame-relay lmi or show frame-relay pvc or show frame-relay map
Router2(config)# interface s0/0/0
Router2(config-if)# encapsulation frame-relay
Router2(config-if)# no ip address
Router2(config-if)# no shutdown
Router2(config-if)# interface s0/0/0.201 point-to point
Router2(config-router2)# ip address 1.1.1.1 255.255.255.0
Router2(config-router2)# bandwith 64
Router2(config-router2)# frame-relay interface-dlci 201
Router3(config)# interface s0/0/0
Router3(config-if)# encapsulation frame-relay
Router3(config-if)# no ip address
Router3(config-if)# no shutdown
Router3(config-if)# interface s0/0/0.301 point-to-point
Router3(config-router3)# ip address 2.2.2.2 255.255.255.0
Router3(config-router3)# bandwith 64
Router3(config-router3)# frame-relay interface-dlci 301
Routing on frame-relay:
Router2(config)# router rip
Router2(config-router)# network 1.1.1.0
Router3(config)# router rip
Router3(config-router)# network 2.2.2.0
Router1(config)# router rip
Router1(config-router)# network 1.1.1.0
Router1(config-router)# network 2.2.2.0
Cloud configuration:
Config > serial1 > lmi (cisco) > dlci (201) > name (r2 to r1) > add.
Serial2 > lmi (cisco) > dlci (301) > name (r3 to r1) > add.
Serial3 > lmi (cisco) > dlci (102) > name (r1 to r3) > add.
Serial3 > lmi (cisco) > dlci (103) > name (r1 to r3) > add.
Frame-relay > select here their paths.
Using DNS to resolve names:
Router(config)# ip domain-lookup
Router(config)# ip name-server 192.168.1.50
Router(config)# ip domain-name corvit.com
Router# ping router2 or show processes
Backup and Restore IOS:
Backup:
Router# show version or show flash (remember the IOS name)
Router# copy flash tftp
Source file name []? Give name of the IOS
Address or name of remote host [] 10.0.0.100
Destination file name [] any
Restore:
Router# copy tftp flash
Router# copy tftp startup-config
Router and Switch configuration software: Hyper terminal, Teraterm (SSH), Secure CRT, Putty.
Switch(config)# interface VLAN 1
Switch(config-if)# ip address 1.1.1.1 255.0.0.0
Switch(config-if)# no shutdown
And give default gateway.
Banner motd: banner is message of the day.
Switch(config)# banner motd @don’t login to the router, if you are not authorized@ > enter
Description:
Switch(config)# interface f0/0
Switch(config-if)# description This is IT department line
SSH (Secure shell):
Switch(config)# aaa new-mode
Switch(config)# username ali password corvit
Switch(config)# ip domain-name Kabul.com
Switch(config)# crypto key generate rsa general-key modelus 1024
Switch(config)# ssh version 2
Switch(config)# line vty 0 4
Switch(config-line)# transport input ssh telnet
Router# show ip arp
Cmd: route print , cmd: tracert –d yahoo.com
To give privilege exec mode permission to users:
Router(config)# line vty 0 4
Router(config-line)# login local
Router(config-line)# transport input telnet
To give permission to one user:
Router(config)# username Ali privilege 15 password CISCO
Router# show run | include network
Router# dir all (shows all memories partitions and IOS).
IP OSPF Authentication key:
Router1(config)# interface s0/0/1
Router1(config-if)# ip ospf authentication
Router1(config-if)# ip ospf authentication-key icne@123
Router1(config)# service password-encryption
Router2(config)# interface s0/0/0
Router2(config-if)# ip ospf authentication
Router2(config-if)# ip ospf authentication-key icne@123
Router2(config-if)# service password-encryption
Note: we must configure the authentication-key command on each port of router, to authenticate. Now without authentication router can’t share its routing table with neighbors.
Internet and VPN (virtual private network):
Advantages: lower cost, security, scalability. Data sends in tunnel by encrypted form, using public network as private network.
Two types of VPN: Site to Site VPN, Remote access VPN.
Note: in remote access VPN, user will install a software by name (CISCO easy VPN) or secure socket layer (SSL) on his laptop.
Redundancy FHRP Technologies:
HSRP (Hot-standby redundancy protocol): CISCO introduced in 1994, hello timer 3 sec, hold timer 10 sec.
Virtual load balancing, Version1 mac(07:ac). Version2 mac(DC:9F).
If R1 wan link were down how R2 know to become active? We will give a command to R1 to decrement priority value. Ex: -20
The higher priority router will be active and second router will be standby.
If R2 3hello packets not received then R2 will be active.
Router1(config)# interface f0/0
Router1(config-if)# standby 1 ip 1.1.1.1 (1 is the group number it will be same on both side)
Router2(config)# interface f0/0
Router2(config-if)# standby 1 ip 1.1.1.1

Router1# show standby brief (router1 changed status to  active and router2 status changed to standby mode.
Router1(config-if)# standby preempt
To change priority:
Router1(config-if)# standby 1 priority 130
Router1(config-if)# standby version 2
When WAN link were down:
Router1(config-if)# standby 1 track s0/0 20
Router2(config-if)# standby 1 preempt
GLBP (Gateway load balancing protocol): CISCO introduced in 2005. AVG (Active virtual gateway), it will reply to all ARP requests for the virtual ip addresses.
AVF(Active virtual forwarder), if Router1 down, the AVF will active the next higher priority router.
If all routers have same priority, then the higher gateway address routers will be AVG.
Router1(config)# interface s0/0
Router1(config-if)# ip address 20.20.20.2 255.255.255.0
Router1(config-if)# no shutdown
Router1(config)# interface f0/1
Router1(config-if)# ip address 1.1.1.2 255.255.255.0
Router1(config-if)# no shutdown
Router2(config)# interface s0/0
Router2(config-if)# ip address 30.30.30.3 255.255.255.0
Router2(config-if)# no shutdown
Router2(config)# interface f0/1

Router2(config-if)# ip address 1.1.1.3 255.255.255.0
Router2(config-if)# no shutdown
Router3(config)# interface f0/1
Router3(config-if)# ip address 1.1.1.4 255.255.255.0
Router3(config-if)# no shutdown
Router1(config)# interface f0/1
Router1(config-if)# glbp 1 ip 1.1.1.1
Router2(config)# interface f0/1
Router2(config-if)# glbp 1 ip 1.1.1.1
Router3(config)# interface f0/1
Router3(config-if)# glbp 1 ip 1.1.1.1
Router3# show glbp
Router(config-if)# glbp 1 load-balancing weighted
Router(config-if)# glbp 1 authentication md5 key-string cisco
Router(config-if)# glbp 1 weighting 110 lower 80 upper 90

Saturday, April 8, 2017

Introduction to Cisco switch

Cisoc Switch
Switch is a central device for all computers, switch work on datalink layer of OSI model.
Switch functions: address learning, forward/filtering decision, loop avoidance.
  1. Address learning: in address learning switch will find the mac address of every machine
  2. Forwarding/filtering decision: in filtering the data send to specific machine
  3. Loop avoidance: Loop (the process which repeats again and again is called loop. Avoidance (means removing or stopping through STP and RSTP protocol. Ex: switch#show spanning-tree
Switching: Switching is a process to move the data on the basis of hardware or MAC address.
Data link layer is responsible for switching; data link layer devices are switch and bridge.
ARP (address resolution protocol): ARP is use to find the address from known IP. Ex: cmd: arp –a
Switch# show mac-address-table
Cisco discovery protocol (CDP): CISCO proprietary protocol, works on layer2 (data link layer). Use to find detail information of neighbor device, sends updates every 60 seconds.
Switch# show cdp neighbors
Switch# show cdp entry
Switch# show cdp neighbor’s detail
STP (spanning tree protocol): STP is use to avoid ARP loop. In STP there is secondary path which is always down. Secondary is up where primary is down.
BPDU (bridge protocol data unit): Packet use to share information between switch and STP.
STP secondary link steps:
Step1: select a route bridge, (it is a focal point and decision making switch, which acts as a master for all other switches.
Every switch has priority number, switch have lower priority it will be our bridge. To view switch priority: switch# show spanning-tree
 If priority number is equal, every switch has a mac address a switch with a lower mac address will be our route bridge.
To change the priority number: switch(config)# spanning-tree vlan 1 priority 300 every port of root bridge will be designated port, and it will never block in any condition.

Step2: select root port, is a port of Non-root Bridge. Root port will be selected by cost.
Bandwidth:                             Cost:
10 mbps                                   100
100 mbps                                 19
1Gbps                                        4
10Gbps                                      2
To change cost: switch(config)# interface f0/1
Switch(config-if)# speed 10
Step2: block the redundant link every port (interface) has mac address. The port with higher mac address will be blocked a port in a blocking mode can’t perform any action, except sending and receiving BPDU.
If primary link down a new step, will be started to continue the communication. How the redundant link will know that primary is down? When primary is down either by unplugging or in cause of any damages, secondary or redundant link will follow a few steps to be up.
Step4 startup mode: blocking mode 20 seconds (waiting for primary may be up).
Listening mode 15 seconds (communicating with BPDU).
Learning mode 15 seconds (forwarding mode, startup mode).
How to create switch2 as a root bidge ?
We must decrease the priority of switch2 to make as a root bridge.
Switch2(config)# spaning-tree VLAN1 priority 4096 Or
Switch2(config)# spaning-tree VLAN1 root primary
Switch2# show spaning-tree
Rapid STP (RSTP):
Switch1(config)# interface f0/1
Switch1(config)# spanning-tree port fast
Switch2(config)# interface f0/1
Switch2(config)# spanning-tree port fast
Now run this command on all switches:
Switch1(config)# spanning-tree mode rapid-pvst
Switch2(config)# spanning-tree mode rapid-pvst
Switch3(config)# spanning-tree mode rapid-pvst

Note: after RSTP commands, when the primary path down, the secondary will be up without taking 30 seconds time.
VLAN (virtual LAN): VLAN is a group of ports in which computer can only communicate with their own group members.
Advantage of VLAN: Security will be increased, broadcast will be break.
Two types of VLAN:
Static VLAN: in which ports are manually added.
Dynamic VLAN: in which ports are created by using Mac addresses.
Two ports of VLAN:
Access port: access port carries its own VLAN data.
Trunk port: use to connect two different VLAN.
Switch(config)# vlan 10
Switch(config-vlan)# name sales
Switch(config)# vlan 20
Switch(config-vlan)# name IT
Switch(config)# vlan 30
Switch(config-vlan)# name HR
Switch(config)# interface f0/1
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10
To add more interfaces in a vlan:
Switch(config)# interface range fastethernet 0/1 – 5
Switch(config-if-range)# switchport mode access
Switch(config-if-range)# switchport access vlan 10
To add different interfaces in a vlan:
Switch(config)# interface range fastethernet 0/1 , fastethernet 0/4 , fastethernet 0/13
Switch(config-if-range)# switch mode access
Switch(config-if-range)# switchport access vlan 10
Switch# show vlan
VTP (VLAN Trunking protocol): Use to share VLAN information between different switches.
VTP modes: Server mode, Client mode, transparent mode.
Server mode: it is a default mode of every CISCO catalyst switch.
In this mode you can create, delete, and modify VLAN. All VTP information advertised from server to client, in this information are stores in NVRAM.
Client mode: in this mode you can’t create, delete, and modify information are stores in RAM. VTP information sends by VTP server.
Transparent mode: in this mode we create, and delete VLAN. In this mode it has its own database, can’t store VTP information, and send by VTP server.
VTP Configuration:
Switch1(config)# VTP mode server
Switch1(config)# VTP domain corvit
Switch1(config)# VTP password icne@123
Switch1(config)# interface f0/6
Switch1(config-if)# no shutdown
Switch1(config-if)# switchport mode trunk
Switch1# show VTP status
Switch2(config)# VTP mode transparent
 Switch2(config)# VTP domain corvit
Switch2(config)# VTP password icne@123
Switch2(config)# interface range fastethernet 0/6 , fastethernet 0/5
Switch2(config-if-range)# switchport mode trunk
Switch3(config)# VTP mode client
Switch3(config)# VTP domain corvit
Switch3(config)# VTP password icne@123
Switch3(config)# interface fastethernet 0/6
Switch3(config-if)# switchport mode trunk
How to break Router password ?
Step1: reboot the router, when reboot click (ctrl+break) to restrict the router booting from NVRAM, to boot from RAM.
Step2: change that confreg value, i.e. 0x2102
Rommon1> confreg 0x2142
Rommon2> reset
Router(config)# no enable secret or no enable password
Router(config)# config-register 0x2102
Router# copy run start
Router# reload
Inter VLAN routing or router on stick:
Router(config)# interface f0/0
Router(config-if)# no shutdown
Router(config)# interface f0/0.1
Router(config-sub-if)# encapsulation dot1q 10 (vlan 10)
Router(config-sub-if)# ip address 10.0.0.100 255.0.0.0
Router(config)# interface f0/0.2
Router(config-sub-if)# encapsulation dot1q 20
Router(config-sub-if)# ip address 200.0.0.100 255.255.255.0
Router# show ip route
Port security:
Switch(config)# interface f0/1
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security mac-address sticky
Switch(config-if)# switchport port-security maximum 1
Switch(config-if)# switchport port-security violation shutdown
Switch# show port-security
Switch# show port-security address
Switch# show port-security interface f0/1
Switch# show mac-address-table