BCRAN
PPP Negotiating PAP Authentication
If you have decided to use an authentication protocol, it will likely be PAP or CHAP. PAP is a one-way authentication between a host and a router or a two-way authentication between routers. With PAP, this process provides an insecure authentication method. When using PAP, the remote host is in control of the frequency and timing of login requests. This situation is undesirable because the router or access server must respond to all login requests, even the repeated attempts of a hacker to...
Typical WAN Protocols
All rights re Each WAN connection uses an encapsulation protocol to encapsulate traffic while it is crossing the WAN link. To ensure that you use the correct encapsulation protocol, you must configure the Layer 2 encapsulation type to use. The choice of encapsulation protocol depends on the WAN technology and the communicating equipment. Typical WAN protocols include PPP PPP originally emerged as an encapsulation protocol for transporting IP traffic over point-to-point...
PAT Configuration Example
Ip address l .D.0.1 Z&5.0.0.D ip nat insi e p addrc c g.ziti itczl ip nr-t outai da ip net ins id 30ui * list 101 intsrfa a DialsrD overload acceee-lifit 101 permit ip 10.0,0, C 0.25 ,255,255 any 2004 Cisco Systems, Inc. All rights reserved. BCRAN v2.1 4-7 The figure illustrates a sample PAT configuration on the Cisco 827 router. The access list will match any source address in the 10.0.0.0 network. In this example, the Dialer0 interface is the outside interface, and the Ethernet0 interface is...
Data over ADSL Bridging
Subscriber Ethernet traffic is bridged over ATM using ATM Adaptation Layer 5 (AAL5). All subscribers are in the same broadcast domain (this is bridging). Bridged traffic can be routed via the BVI interface at the aggregation router. The BVI IP address is the end user's PCs default gateway. Bridging does not scale well. Subscriber Ethernet traffic is bridged over ATM using ATM Adaptation Layer 5 (AAL5). All subscribers are in the same broadcast domain (this is bridging). Bridged traffic can be...
Configuration of Dialer Interfaces
Tloti prp riialnr TTTBfit.p-mmr rminl IILHRZ- .I3 . 5. encnp uli. Tloti prp riialnr TTTBfit.p-mmr rminl IILHRZ- ip BtjkizwB 10 3 3.1 ' SJ C rmrnpmiliiTinn ppp tjiae meta-naaa iujell diiilcc Ctrl * clanc diftLS Lii.d thf itild EC ifc diAlHlL-ilflt, 1 pioUQ l I Lii-I dllLtf fiil 1 dlsJer- pTnip ifjfj ui'jl-_Llj.E.k 2004 Cisco Systems, Inc. All rights To configure dialer profiles, perform these tasks 1. Configure one or more dialer interfaces. 2. Configure a dialer string and...
IKE Policy Negotiation
RE utff A II OCITKJ RtujliiSi,C triQ X RE utff A II OCITKJ RtujliiSi,C triQ X n cyjar.Q lukap pal a cry IDG 4- Jr'i - inti* . HAkap pal y B HtbftnL&MtlM pi* - htf* rrypr.n iuiqi paSicy 255 Bthtnti-Mtian ru g h*ili ihi T- (pelifccy JPO * AUrllW.Hf Af. fiB p-FA - fth F* or pso poi J r 3PC AL.rhflfiti-Mr.Lrtn ru - iLq huh uH The first two policies in each router can be successfully negotiated while the last one can not. The first two policies in each router can be successfully negotiated while the...
Floating Static Routes as Backup
Floating static routes are static routes that have an administrative distance greater than the administrative distance of dynamic routes. The administrative distance can be configured on a static route so that the static route is less desirable than a dynamic route, and the static route is not used when the dynamic route is available. However, if the dynamic route is lost, the static route can take over and traffic can be sent through this alternate route. If the alternate route is provided by...
WAN Connection Speed Comparison
All rights re The figure illustrates the WAN speeds for typical technologies. Network administrators must select a WAN option based on the required bandwidth. The speeds, costs, and availability of WANs vary internationally. For example, in North America, high-bandwidth speeds such as T1 are easily available at reasonable prices. Europe offers comparable speeds, such as E1, but prices tend to be higher. Other parts of the world offer limited WAN services with lower...
Configuration of a PPPoE Client
This topic describes how to configure a PPPoE client. After the VPDN group has been defined, the ATM interface must be configured. * Identify the VPI VCI virtual circuits dial-pool-number number * Bind a dialer profile to the ATM interface 20C4 Cisco Systems, Inc. All rights reserved. BCRAN v2.1- Configure the ATM interface (ADSL interface) of the Cisco 827 router with an ATM PVC and encapsulation. To configure a PPPoE client on an ATM interface, use the interface atm number command in global...
Configuration Example RouterA
2004 Cisco Systems, Ir The configuration in the figure is for legacy DDR, which uses dialer maps. The table describes the commands that are used in the configuration. BRI and DDR RouterA Configuration Commands Command Description isdn switch-type Selects the AT&T 5ESS switch as the central office (CO) ISDN switch type for this interface. username rtb password itsasecret Sets up a CHAP username and password for the remote router. interface bri 0 Enters BRI 0 configuration mode.
Five Steps of IPSec
All rights 2004 Cisco Systems, Inc. All rights The goal of IPSec is to protect the desired data with the necessary security and algorithms. The figure shows only one of the two bidirectional IPSec SAs. IPSec operation can be broken down Step 1 Interesting traffic initiates the IPSec process. Traffic is deemed interesting when the VPN device recognizes that the traffic you want to send must be protected. Step 2 IKE Phase 1. IKE authenticates IPSec peers and negotiates...
Additional Isdn Pri Configuration Parameters
This topic describes the commands that are required to configure the ISDN PRI channels and D channel. After the T1 or E1 controller is configured, the PRI channels and the corresponding D channel interface must be configured. Additional ISDN PRI Configuration Parameters Router(config-controller) pri-group timeslots range * Specifies ISDN PRI on the T1 or E1 controller * Specifies timeslots (channels) used by PRI Router(config) interface serial slot port unit 23 15 * Specifies the serial...
Modem Modulation Standards
V.34 annex 1201H 33.6 kbps V.90 56 kbps downstream, 33.6 kbps upstream V.92 56 kbps downstream, 48 kbps upstream V.34 annex 1201H 33.6 kbps V.90 56 kbps downstream, 33.6 kbps upstream V.92 56 kbps downstream, 48 kbps upstream The function of a modem is to convert digital signals (DTE to DCE) into analog signals (DCE to DCE), and vice versa. The ITU-T has defined and introduced several modem modulation standards over the years. However, various modem manufacturers have also marketed their own...
Step 1Configure Transform Sets
Crypto ipsec transform -set transform -set-name transforml transform transform3U router(cfg-crypto -trans) crypto ipsec transform -set transform -set-name transforml transform transform3U router(cfg-crypto -trans) RouterA(config) crypto lpsec transform-set mine esp-des A transform set is a combination of IPSec transforms that enact a security policy for traffic. Sets are limited to up to one AH and up to two ESP transforms. 20M Cisco Systems, Inc. All rights re A transform set is a combination...
IPSec Policy Example
Trtiffji (M lt l' lypf (dHfltcypitd 2004 Cisco Systems, Inc. All rights re The figure shows a summary of IPSec encryption policy details that will be configured in examples in this lesson. (Details about IPSec transforms are covered later in this lesson.) The example policy specifies that TCP traffic between the hosts should be encrypted by IPSec that uses DES. Determining network design details includes defining a more detailed IPSec policy for protecting traffic. You can then use the detailed...
Show crypto ipsec transformset show crypto isakmp sa30
RouterA show crypto ipsec transform-set Transform set mine esp-des will negotiate Tunnel, , RouterA show crypto ipsec transform-set Transform set mine esp-des will negotiate Tunnel, , View the currently defined transform sets. dst src state conn-id slot 172.30.2.2 172.30.1.2 QM_IDLE 47 5 Shows Phase I security associations. Use the show crypto ipsec transform-set EXEC command to view the configured transform sets. The command has the following syntax show crypto ipsec transform-set tag...
Configuration Example RouterB
2004 Cisco Systems, In BCRAN v2.1 6-10 This figure displays the configuration of RouterB. This configuration is also for legacy DDR. The table describes the commands that are used in the configuration. BRI and DDR RouterB Configuration Commands Command Description isdn switch-type Selects the ISDN switch type for this interface. username rta password itsasecret Sets up the CHAP username and password for the remote router. interface bri0 Enters BRI 0 configuration mode. ip address 10.170.0.
Step 3Configure Isakmp Identity
Crypto isakmp identity address hostname Defines whether ISAKMP identity is done by IP address or hostname. Use consistently across ISAKMP peers. 2004 Cisco Systems, Inc. All rights re IPSec peers authenticate each other during ISAKMP negotiations by using the preshared key and the ISAKMP identity. The identity can either be the IP address or the host name of the router. Cisco IOS software uses the IP address identity method by default. A command indicating the address mode does not appear in...
An Overview of QoS Mechanisms
Classification Each class-oriented QoS mechanism has to support some type of classification Marking Used to mark packets based on classification and or metering Congestion Avoidance Used to drop packets early in order to avoid congestion later in the network Congestion Management Each interface must have a queuing mechanism to prioritize transmission of packets Policing and Shaping Used to enforce a rate limit based on the metering (Example Frame Relay traffic shaping) Link Efficiency Used to...
Dedicated Circuit Switched Connections
All rights re 2004 Cisco Systems, Inc. All rights re Leased-line serial connections typically connect to a transport service provider through a DCE device, which provides clocking and transforms the signal to the channelized format that is used in the service provider network. These point-to-point dedicated links provide a single, preestablished WAN communications path from the customer circuit-switched premises, through a carrier network, to a remote network....
Inside Global Address Overload
The figure illustrates NAT operation when a single inside global address is used to represent multiple inside local addresses simultaneously. In this example, an extended translation entry table is used, in which the combination of address and port makes each global IP address unique. The use of ports to make an address unique is called PAT, a subset of NAT. This operation consists of these steps Step 1 The first packet the router receives from 10.1.1.1 causes the router to check its NAT table...
Viewing a Custom Modemcap Entry
O RCkltAi flll4W U dAlTLAAp U n AU Modemrup for lior ncw Factory DaCaulta FBIj SF AutGirsmr tAAi ' iLl- l Carrier datact (CD) iCl Drop Ttn DTE (DTE) liazdnate Flovcontrol (HE*L iHltRj Lock DTE speed (SPDl Bl Rftit S l f Cant SL PERI Ht Best ontprcs ion U J SKi No Ijcnor Control MER r iHD So Compression (HCF (KU Ho Echo NEC KO Ho natliU Codes (PBE) Q1 Software F-owc-ontcol
















