Monday, 29 October 2012

CCNA Security Buzzwords

So I've made a slight detour on the CCNA Wireless, it's been replaced by the CCNA Security, and my aim is before the end of the year!

Here's some buzzwords which I feel like I'll have to know and be able to explain should the needs arise. I'm not going to explain them here because it forces me to remember what each means (rather than just reading it) hopefully fixing them in my brain:

Asset
Vulnerability
Threat - Latent, Realised, Threat Vector / Agent
Risk
Countermeasure - Administrative, Physical, Logical

Classifications:
Governmental - Unclassified, SBU (sensitive but unclassified), Confidential, Secret, Top Secret
Public Sector - Public, Sensitive, Private, Confidential
Criteria - Value, age, replacement cost, usefulness lifetime
Roles - Owner, Custodian (implementation), User

Attack Methods:
Covert Channel
Trust Exploitation
Password Attacks
Botnet
DoS / DDoS

Secure Network Architecture Guidelines:
Rule of least privilege
Defence in Depth
Separation of Duties
Auditing


The 5 stages of the Secure Network Lifecycle are:
Initiation
Acquisition and Development
Implementation
Operations and Maintenance
Disposition

Methods to determine the financial impact:
Qualitative
Quantitative


That'll do for now although I may well add more as time goes on

Cisco Telepresence (Very Much the Basics!)

2 Months between posts! very bad, I'm trying to get back on the blogging bandwagon again so here we go!

Cisco Telepresence is a fantastic thing however it's a tad complicated and you really need to know what you are doing to begin looking at it. Here are a few bits I've picked up along the way, serves as a reasonable crash course in Telepresence:

In any Telepresence deployment there are 4 elements which must be present:
  1. Endpoints
  2. Call Control
  3. Conferencing
  4. Scheduling and Management
End points - The endpoints are the phones, video screens and software clients which the user interfaces when they make a video call

Call Control - This is dependant on what endpoints you choose but essentially the call control sets up and controls / directory. The two options are CUCM (Call/Communications Manager) or Cisco VCS.
CUCM is used for IP Telephony, immersive multi-screen telepresence (TX9000) and standards based endpoints such as the MX200 / MX300. 
VCS is the platform for standards based Telepresence endpoints. VCS Control is the platform for use within an enterprise and VCS Expressway can be used to extend communications to other businesses and remote workers.
The most complete solution would consist of both CUCM and VCS with a SIP trunk between them. 

An interesting product here is the VCS Starter Pack Express which is an introduction package for SMBs interested in Telepresence. Limited funcationality and up to 50 registrations and 25 calls:

Conferencing - This is the conferencing bridge element which allows for multi party calls rather than just point to point.
An interesting product here is the MCU5300 series it is essentially stackable conference MCU resources, so you buy them as you need them:

Scheduling and Management - As implied this is the management and scheduling element and the Cisco product for this is Telepresence Management Suite (TMS):

Wednesday, 22 August 2012

Juniper Line Card Types (DPC, MPC Etc)

I'm going to build on this post as I come across each of the different types but it can get very confusing talking about the different types of Juniper Line Cards, so here is a reference:

DPC - Dense Port Concentrator
ichip based cards which are available for the MX series routers
They come in 3 variations:
DPCE-R - Routing and Switching, operate as complete L3 router or Full L2 switch
DPCE-X - Limited Scale L3. Cost optimized line case
DPCE-Q - Enhanced Queueing, up to 64,000 queues per card. Per VLAN queueing.

MPC - Modular Port Concentrator
trio based cards for the MX series routers. They support full LS, L2 and application services. MICs are used inside MPCs to provide interfaces.
MPC1 - 32k IFL, port queues, 30Gbps
MPC2 - 64k IFL, port queues, 60Gbps
MPC1-Q - 32k IFL, VLAN queues, 128k I/E queues, 30Gbps
MPC2-Q - 64k IFL, VLAN queues, 256k I/E queues, 60 Gbps
MPC2-E-Q - 64k IFL, VLAN queues, 512k queues, 60Gbps

MX-FPC - MX Flexible Port Concentrator
These are used to add non-Ethernet interfaces to an MX series chassis. They take up 2 slots and have reduced performance (2.5 Gbps Type 2 or 10Gbps Type 3)

More to come as I come across them...


Tuesday, 14 August 2012

Calculating Packets Per Second of Devices

So here's a topic which just keeps cropping up and I look it up every time, so I'm sticking it on the blog so that I've got a reference for the future and hopefully I'll remember it a bit better for next time!

You will often have to calculate the required packets per second of a device to make sure it is "powerful enough" to handle the job given to it. Alternatively you may be sizing a device for a link, for example a router for a WAN connection, and you want to make sure it can handle wire speed on the link. Here is my calculations for this.

I'll use the standard example of a 1 gigabit WAN connection 1Gbps, this is 1,000,000,000 bits:
In order to work out the required pps (Packets Per Second) of a device for the WAN link we need to consider the maximum and minimum packet sizes. Bear in mind the packet size in reality will vary so the actual number is anyone's guess but this gives you a great boundary.

The minimum packet size is 84 bytes (46 payload, 4 CRC, 2 MAC type, 6 MAC source address, 6 MAC destination address, 8 preamble, 12 inter frame gap).
The maximum packet size is 1538 bytes (same as above but with 1500 payload instead of 46)

The calculation is:
Convert bits into bytes -- 1,000,000,000 bits per second / 8 = 125,000,000 bytes per second
Convert bytes into packets -- 125,000,000 bytes per second / 84 = 1,488,096 packets per second

The above works out the minimum packets per second, changing 84 to 1538 works out the maximum packets per second:
Convert bytes into packets -- 125,000,000 bytes per second / 1538 = 81,274 packets per second

From this we know if all the packets were the minimum sized we'd need a more powerful device to handle wirespeed, but this is theoretical because you wont be able to guarantee the size of all packets, apart from in very special cases.

If you can work out the average packet size within the environment you will be able to workout more accurately the device requirements, but from here is it a bit of a guessing game do you plan for the lowest possible packet size to ensure the device can handle wirespeed or do you pick a more realistic but unknown value somewhere in the middle. That answer is up to you.

Monday, 13 August 2012

450Mbps Wireless. Spatial Streams and 4x4 MIMO

So I've not posted for a while, which is bad and I will definitely start again soon. But in the mean time I've learnt something very interesting about 802.11n wireless, spatial streams and 450Mbps that I want to jot down.

802.11n radios give 300Mbps with 2x2 antennas, this is 2 transmit and 2 receive. They also utilise 2 spatial streams. The maths behind this is that each channel gives 75Mbps, 2 channels (2 x 20MHz channels = 40MHz) gives 150Mbps. 2 spatial thus gives 300Mbps. Note that each side needs the same setup to achieve these rates, this is critical.

MIMO allows multiple datastreams to be sent simultaneously however there are two sides to this coin. Each MIMO stream can be used to send the same data, thus you have multiple redundant copies of the data and the connection is very reliable, this is Diversity. The other extreme is throughput where each stream sends different data but there is no redundancy in the path so it is potentially faster but also less reliable. Most commonly a balance in the middle is used to give you reliable throughput.

Thus APs can theoretically achieve 450Mbps by using 3x3 radios with 3 spatial streams, the problem is this is a extreme throughput situation and you will likely not get the fastest possible speeds due to distances and errors in the transmission. If one of the streams experiences deep fading (low signal) the transmission fails or slows down to a lower transmission rate.

Cisco has a solution to the above in the 3600 AP. It has 4x4 radios and 3 spatial streams meaning that three can send and receive while the remaining is used for diversity to help achieve the reliable throughput needed. It's worth noting that this is custom silicon as well and only available to Cisco, at the time of writing anyway.

References:
There's a fantastic video from techwize tv called 'fundamentals of spatial streams'. Currently on this page:
http://www.cisco.com/en/US/products/ps11983/index.html

Friday, 27 July 2012

Logarithm

So here's an interesting topic and one I think I'll remember because I already half know it under another guise.

The reason I'm posting about logarithms is because wireless networking uses a logarithmic scale in decibels. Binary is also a logarithmic scale.

Logarithm is essentially the power of, or "base". For example the logarithm of binary is base 2.

For example:
Log10 (1000) = 3 - You read this as Log of 1000 to base 10 is 3 - 10 x 10 x 10 = 1000 = 10 power3

References:
http://en.wikipedia.org/wiki/Logarithm

Monday, 23 July 2012

CCNA Wireless Revision

So I'm starting to get down to revision for the CCNA Wireless. I'm trying to pick a specialisation and I figure the best way to do this is get immersed enough with each technology without going too deep, see if I can find something that I really enjoy and will be happy for the next few years focusing on.

I'm starting with wireless because it's interesting, it's very relevant and the knowledge will definitely be useful even if I decide to go a different way.

I haven't decided exactly how I'm going to do this yet but I'll be posting my revision notes up somewhere on this blog any comments are welcome, I'd also love to hear from anyone who's recently done the CCNA wireless especially because there is very little current study material out, only the old stuff IUWNE 640-721 when really I need 640-722. Hopefully it'll be released soon! If not well then, we'll just crack on and see what happens.

Wednesday, 18 July 2012

Wireless Authentication - 4 Way Handshake

The authentication process for WPA is known as the 4 way handshake, this is required for a client to be authenticated onto the network.

At the start of the process the client and the AP both know the passphrase (PSK) and the Pairwise Master Key (PMK) which is computed from the PSK and SSID.

The first step is for the AP and Client to form a new key called the Pairwise Transient Key (PTK), this key is a function of the PMK, a random number from the AP (A-nonce) a random number from the client (S-nonce) and the MAC address of the AP and client.
  1. The AP sends an A-nonce to the client
  2. The client sends a S-nonce to the AP as well as a MIC. - The AP uses the MIC to verify that the client has the PMK. If the MIC is incorrect then the PTK and PMK are incorrect because the PTK is derived from the PMK.
  3. The AP sends a GTK (group Temporal Key) to the client, plus a MIC.
  4. The client sends an acknowledgement to the AP
The client and AP can now install the key and begin encrypting the traffic.

This 4 way handshake is also used for WPA Enterprise as well as WPA PSK, the difference being that the PMK is derived from the clients authentication with the RADIUS server with EAP

Here is a good reference from Wikipedia which details a drawing to help remember the process:
http://upload.wikimedia.org/wikipedia/commons/a/ac/4-way-handshake.svg

Full article is below:
http://en.wikipedia.org/wiki/IEEE_802.11i-2004

Wednesday, 11 July 2012

TOS / COS - Type of Service / Class of Service

Type of Service (TOS) is an 8 bit field in the IP header which can be used for differentiating the treatment for that packet. TOS is an older method not used as much any more because it has been superseded by the Class of Service (COS). This redefining of the TOS field is called the Differentiated Services (DiffServ) Framework.

COS uses 6 bits in the DiffServ field, called the DiffServ Code Point (DSCP). 6 bits allows 64 classes, which can be the predefined classes or manually chosen. The queueing and forwarding treatment of the IP packet is called Per Hop Behaviour (PHB).

The last 2 bits in the DiffServ field is the ECN - Explicit Congestion Notification. This can be used to signal congestion.

Routing Protocols Interesting Tidbit

Here's something I didn't realise; BGP and RIP are actually application layer protocols, in regards to the TCP/IP Stack, because BGP uses TCP to send messages, and RIP uses UDP. In contrast other routing protocols, such as OSPF, are at the Internet layer (Network layer in the OSI model) because they encapsulate messages directly into IP packets.

Tuesday, 10 July 2012

Home Network Update - New Items

So I've sourced a few items from the wonderful place which is eBay and I've got a few ideas for them:
Cisco2811-SEC/K9 - Cisco 2811 router with security licence
AIR-AP1131AG-E-K9 - Cisco 1131 autonomous access point

The 2811 was at a price I couldn't refuse, so I'm not 100% sure what to do with it yet, but I'll have a think and implement it somehow. I'm umming and ahhing about converting it to run CCME? That would be a really interesting little project, I've got a couple of phones lying around, so I'd only need PVDMs, CCME software, and licenses.

The access point is an easy one, it'll extend the wireless network, hopefully giving me decent signal throughout the house, but it'll be interesting to see exactly how this works without a controller...

Next purchases will likely be a small switch of some kind, 2960C maybe, because I'm rapidly running out of ports. I also want an ASA5505 because I'm starting to worry I can't achieve what I wanted to with my little 877W and it's IOS SSL WebVPN.

Friday, 6 July 2012

Wireless Connection Process

Below is the process a wireless client goes through in order to get access to a wireless network:

Step 1 - Start
This is the initial connection between the client and AP. This is where L2 security authentication and encryption mechanisms are in place, for example: none, static WEP, 802.1X, WPA / WPA2.

Step 2 - DHCP
L3 operations start here, an IP address is attained as well as L3 security elements, such as authentication via a webpage at a hotspot. This could be the first phase if L2 security isn't configured.

Step 3 - Mobility
The clients final IP address is applied here and it can fully function at L3. The address could have well changed here from step 2 if web authentication was used.

Step 4 - Run
The client is live and sending data.

Layer 2 security comprises of:
Authentication - 802.1X or PSK
Encryption - None, WEP, WPA or WPA2 (TKIP or AES)


Thursday, 5 July 2012

Cisco WLC Interfaces

Ports on a WLC are physical interfaces. below are the different types of ports:
Service Port - RJ45 connection used for Out Of Band (OOB) management. It cannot carry traffic and is not auto sensing so it must connect to a switch access port and must have the correct cable. No default gateway can be set so the management station should be on the same subnet or a static route will need to be defined.
Console Port - standard DB9 console port
Utility Port - For future use
Distribution Ports - These ports are for controlling APs and network connectivity.

Interfaces on a WLC are logical and need to be mapped to a port. Many interfaces can be mapped to a single port. Interfaces are either predefined or user defined. user defined interfaces are dynamic and are used for VLANs for WLAN access. Predefined interfaces are static. Interfaces need to be on all controllers in the mobility group in order to ensure seamless roaming otherwise clients will drop and need to re-associate. Types of static interfaces:
Management - This interface is used for in band management for example connections to AAA and L2 communications to other controllers. This interface should be in a different subnet from the service port. This address is used for the GUI
AP Manager - This interface is used for WLC to AP communications at L3. This address is also the tunnel source address when packets are sent from the WLC to the AP and destination address visa versa. It should be in the same subnet as the management interface. If the distribution ports are grouped in a LAG then only a single AP manger port is needed. All LWAPP traffic goes through this interface
Virtual - This interface is used to support Mobility Management (mobile client uses the same virtual IP address when roaming across controllers), DHCP relay (DHCP address for clients) and L3 security (redirect for the web page authentication).
Service port - This controls the above mentioned service port

Dynamic interfaces are also known as VLAN interfaces. They are user defined interfaces and are used to carry the data from wireless clients. They are created with the following details:
VLAN ID, Physical port assignment, DHCP server information, ACL information.
Dynamic interfaces can be assigned to many different types of ports: Distribution, WLANs, L2, management, L3 and AP manager interfaces. WLANs are associated with a SSID and dynamic interface. Up to 512 dynamic interfaces can be configured on a WLC.