Catalyst Switch
Defending Against Layer 2 Attacks
This section begins by exploring the nature of Layer 2 switch operation and why it is such an attractive target for attackers. Then, approaches for mitigating a variety of Layer 2 attacks are addressed. These strategies include best practices for securing a Layer 2 network, protecting against VLAN hopping attacks, preventing an attacker from manipulating Spanning Tree Protocol (STP) settings, stopping DHCP server and ARP spoofing, preventing Content Addressable Memory (CAM) table overflow...
Understanding Public Key Cryptography Standards PKCS
Public Key Cryptography Standards (PKCS) is used to provide basic interoperability for applications that employ public-key cryptography. Taken together, PKCS defines a set of low-level standardized formats for the secure exchange of arbitrary data. For instance, PKCS defines a standard format for an encrypted piece of data, a signed piece of data, and so on. Table 14-3 outlines a number of PKCS standards. Password-Based Cryptography Standard Extended-Certificate Syntax Standard Cryptographic...
Examining IPS Technologies
Although IDS and IPS perform similar functions, this section explores how these network security solutions differ. Various approaches to detecting and preventing an intrusion are discussed. This section also explores signatures and how they can trigger an alarm. This section concludes by discussing best practices for IPS network design. Although both IDS and IPS devices can recognize network attacks, they differ primarily in their network placement. Specifically, although an IDS device receives...
Exploring the Basics of IPsec
This section begins by identifying the characteristics of an IPsec VPN. You will learn about various protocols that make IPsec VPNs possible, including IKE protocols and the ESP and AH protocols. Although you can have a Cisco IOS router act as a VPN termination device, Cisco has other network devices that can serve in this capacity, and you will be introduced to the Cisco VPN product family. Finally, you are presented with a collection of Cisco best practices for configuring an IPsec VPN. Much...
Using Cisco SDM to Configure IPsec on a Siteto Site VPN
CLI-based IPsec configuration can become a daunting task for network administrators who aren't thoroughly familiar with the myriad of IPsec parameters and options. Fortunately, Cisco SDM offers a Site-to-Site VPN configuration wizard that can help you configure an IPsec site-to-site VPN, as shown in this section. Introduction to the Cisco SDM VPN Wizard Cisco SDM makes available both a Quick Setup wizard and a Step-by-Step wizard. These wizards combine administrator input with preconfigured VPN...
Defining Voice Fundamentals
This section begins by defining voice over IP and considering why it is needed in today's corporate environment. Because voice packets are flowing across a data infrastructure, various protocols are required to set up, maintain, and tear down a call. This section defines several popular voice protocols, in addition to hardware components that make up a voice over IP network. VoIP sends packetized voice over an IP network. Typically, the IP network serves as a data network as well, resulting in...
Feedback Information
At Cisco Press, our goal is to create in-depth technical books of the highest quality and value. Each book is crafted with care and precision, undergoing rigorous development that involves the unique expertise of members of the professional technical community. Reader feedback is a natural continuation of this process. If you have any comments about how we could improve the quality of this book, or otherwise alter it to better suit your needs, you can contact us through e-mail at feed-back...
Using ACLs to Construct Static Packet Filters
Access control lists (ACL) can be used to provide basic traffic filtering capabilities on Cisco routers. ACLs can be configured for all routed network protocols to filter packets as they pass through a router or security appliance. There are a number of reasons why you might configure these. For instance, you might want to use an ACL to restrict the contents of routing updates or to provide traffic flow control. Perhaps the most important reason to configure ACLs is to provide security for your...
ISR Overview and Providing Secure Administrative Access
This section begins by introducing the security features offered in the Cisco line of ISR routers. Additional hardware options for these routers are also discussed. Then, with a foundational understanding of the underlying hardware, you will learn a series of best practices for security administrative access to a router. For example, a router can be configured to give different privilege levels to different administrative logins. Although they are not a replacement for dedicated security...
Implementing a Cisco IOS Zone Based Firewall
Traditionally, Cisco IOS Firewalls were configured as an inspection rule only on interfaces. This has changed, however, with the introduction of zone-based firewalls. This section examines the Cisco IOS unidirectional firewall policy between groups of interfaces known as zones and shows you how to configure a Cisco IOS zone-based policy firewall. The Cisco IOS classic firewall, formerly known as Context-Based Access Control (CBAC), is one of the key feature sets of the Cisco IOS Firewall. This...
Using Secure Management and Reporting
Network management and reporting applications help network administrators proactively monitor and configure their network. However, left unsecured, management and reporting traffic can be used by potential attackers to compromise network security. For example, captured management and reporting traffic might contain administrative credentials for logging onto a system. Therefore, this section focuses on securing such traffic types. Specifically, you will learn about securing syslog, SSH, and...
IINS Exam Topics
Table I-1 lists the exam topics for the 640-553 IINS exam. Although the posted exam topics are not numbered at Cisco.com, Cisco Press does number the exam topics for easier reference. Notice that the topics are divided among nine major topic areas. The table also notes the part of this book in which each exam topic is covered. Because it is possible that the exam topics may change over time, it may be worthwhile to double-check the exam topics as listed on Cisco.com If Cisco later adds exam...
Port Security Configuration
Earlier in this chapter you saw that Cisco Catalyst port security features can be used to combat CAM table overflow attacks and MAC address spoofing attacks. Cisco recommends that port security be configured on a switch before a switch is deployed in the network, to be proactive instead of reactive. When a switch port security violation occurs, you can configure the switch port to respond in one of three ways Protect When configured for protect, a switch port drops frames with an unknown Topic...
Do I Know This Already Quiz Odz
The Do I Know This Already quiz helps you determine your level of knowledge of this chapter's topics before you begin. Table 3-1 details the major topics discussed in this chapter and their corresponding quiz questions. Table 3-1 Do I Know This Already Section-to-Question Mapping Table 3-1 Do I Know This Already Section-to-Question Mapping ISR Overview and Providing Secure Administrative Access Cisco Security Device Manager Overview 1. Which of the following are considered IOS security features...
Launching a Local IP Spoofing Attack Using a Maninthe Middle Attack
If an attacker is on the same subnet as the target system, he might launch a man-in-the-middle attack. In one variant of a man-in-the-middle attack, the attacker convinces systems to send frames via the attacker's PC. For example, the attacker could send a series of gratuitous ARP (GARP) frames to systems. These GARP frames might claim that the attacker's Layer 2 MAC address was the MAC address of the next-hop router. The attacker could then capture traffic and forward it to the legitimate...
Using IEEE 8021x for VLAN Assignment
The authentication server component of an 802.1x topology can also help restrict user access to network resources specifically, VLANs. In addition to configuration on the RADIUS server (that is, the authentication server), the Cisco Catalyst switch is configured with appropriate AAA commands. After a client (that is, a supplicant) successfully authenticates by providing a username and password, the RADIUS server, which maintains the username-to-VLAN mappings, sends the client's VLAN information...
Exploring Firewall Technology
Securing all aspects of your network can be a daunting task. For an organization with ecommerce, intranet, and extranet sites, as well as e-mail, this only adds to the complexity of the task. Of course, there are costs to providing a high level of security, in terms of both staff and equipment needed to implement a network security policy. These costs must be weighed against the possibility of network security breaches. For many organizations, the Cisco IOS Firewall meets their need to provide...
Constructing an IPsec Siteto Site VPN
Now that you have a foundational understanding of IPsec site-to-site VPN concepts, this section introduces the configuration of an IPsec site-to-site VPN. Specifically, the next subsection focuses on CLI-based configuration versus the graphical SDM configuration approach, which is covered after the next subsection. The Five Steps in the Life of an IPsec Site-to-Site VPN The process of establishing, maintaining, and tearing down an IPsec VPN has five primary steps. These steps are illustrated in...
Introducing Cryptographic Services
To understand cryptographic services, first you must understand the science of cryptology, which in essence is the making and breaking of secret codes. Cryptology can be broken into two distinct areas cryptography and cryptanalysis. Cryptography is the development and use of codes. Cryptanalysis is all about the breaking of these codes. This section explores these two disciplines to give you a better understanding of cryptographic services as a whole. Because cryptography is made up of two...
Exploring Symmetric Encryption
Encryption algorithms use encryption keys to provide confidentiality of encrypted data. With symmetric encryption algorithms, the same key is used to encrypt and decrypt data. This section explores the principles that underlie symmetric encryption. It also examines some of the major symmetric encryption algorithms and discusses the means by which they operate, their strengths, and their weaknesses. Functionality of Symmetric Encryption Algorithms Because of the simplicity of their mathematics...
Understanding Security Algorithms
It is almost hard to imagine modern computing and networking without also thinking about the mechanisms that provide for the underlying security of the data that resides on these systems or travels across the wire. Security algorithms are central to securing the data created within an organization, as well as securing it in transit. This section examines the characteristics of the encryption process and what makes for a strong, trustworthy encryption algorithm. This section also explores the...
Vulnerabilities of MD5
MD5 makes only a single pass over data. Because of this, if two prefixes with the same hash can be constructed, it is possible to add a common suffix to both to make the collision reasonably more possible. Currently there exist collision-finding techniques that allow the preceding hash state to be specified arbitrarily. Therefore, a collision can be found for any desired prefix. This means 1 Topic that for any given string of characters X (for instance, a password), two colliding files can be...
Using SDM to Configure Cisco Ios Ips
Although Cisco offers IPS services on a wide variety of platforms, this section focuses on configuring IOS-based IPS using Cisco's Security Device Manager (SDM). Cisco's SDM is a graphical interface that supports a wizard-like configuration tool for configuring a variety of IOS features, including IOS-based IPS. Launching the Intrusion Prevention Wizard To begin configuring IPS on a Cisco IOS router using SDM, launch the SDM interface. The SDM home page, shown in Figure 11-11, provides summary...
Exam Engine and Questions on the CD
The CD in the back of the book includes exam engine software that displays and grades a set of exam-realistic questions. The question database includes exam-realistic questions, including drag-and-drop and many scenario-based questions that require the same level of analysis as the questions on the IINS exam. Using the exam engine, you can either study by practicing using the questions in Study Mode or take a simulated (timed) IINS exam. The installation process requires two major steps. The CD...
Do I Know This Already Quiz Ozq
The Do I Know This Already quiz helps you determine your level of knowledge of this chapter's topics before you begin. Table 10-1 details the major topics discussed in this chapter and their corresponding quiz questions. Table 10-1 Do I Know This Already Section-to-Question Mapping Table 10-1 Do I Know This Already Section-to-Question Mapping Using ACLs to Construct Static Packet Filters Implementing a Cisco IOS Zone-Based Firewall 1. A static packet-filtering firewall does which of the...
Isolating Traffic Within a VLAN Using Private VLANs
Another way for a Cisco Catalyst switch to provide security is through the use of private VLANs (PVLAN). These PVLANs can provide privacy between groups of Layer 2 ports on a Cisco Catalyst switch. A PVLAN domain has a single primary VLAN. Additionally, the PVLAN domain contains secondary VLANs that provide isolation between ports in a PVLAN domain. Cisco Catalyst switches support two categories of secondary VLANs Isolated VLANs Ports belonging to an isolated VLAN lack Layer 2 connectivity...
Do I Know This Already Quiz Sxv
The Do I Know This Already quiz helps you determine your level of knowledge of this chapter's topics before you begin. Table 8-1 details the major topics discussed in this chapter and their corresponding quiz questions. Table 8-1 Do I Know This Already Section-to-Question Mapping Table 8-1 Do I Know This Already Section-to-Question Mapping Implementing SAN Security Techniques 1. Which of the following is not a reason for an organization to incorporate a SAN in its enterprise infrastructure a....
Identifying Common Voice Vulnerabilities
Because IP phones are readily accessible and plentiful in many corporate environments, they become attractive targets for attackers. Also, VoIP administrators should be on guard against VoIP variations of spam and fishing (both common in e-mail environments), as well as toll fraud (common in PBX environments). This section details these common attack targets for a VoIP network. Table 9-4 describes a few common VoIP attacks targeting endpoints. Table 9-4 Common VoIP Attack Targets Accessing VoIP...
Do I Know This Already Quiz
The Do I Know This Already quiz helps you determine your level of knowledge of this chapter's topics before you begin. Table 1-1 details the major topics discussed in this chapter and their corresponding quiz questions. Table 1-1 Do I Know This Already Section-to-Question Mapping Table 1-1 Do I Know This Already Section-to-Question Mapping Understanding the Methods of Network Attacks 1. Where do most attacks on an organization's computer resources originate d. From intruders who gain physical...
Using Dynamic ARP Inspection
The DHCP snooping feature dynamically builds a DHCP binding table, which contains the MAC addresses associated with specific IP addresses. Additionally, this feature supports static MAC address to IP address mappings, which might be appropriate for network devices, such as routers. This DHCP binding table can be used by the Dynamic ARP Inspection (DAI) feature to help prevent Address Resolution Protocol (ARP) spoofing attacks. Recall the purpose of ARP requests. When a network device needs to...
Examining the Features of the Diffie Hellman Key Exchange Algorithm
The Diffie-Hellman (DH) Key Exchange Algorithm was invented by Whitfield Diffie and Martin Hellman in 1976. The Diffie-Hellman algorithm derives its strength from the difficulty of calculating the discrete logarithms of very large numbers. The functional usage of this algorithm is to provide secure key exchange over insecure channels such as the Internet. DH is also often used to provide keying material for other symmetric algorithms, such as DES, 3DES, or AES. The DH algorithm serves as the...
Cisco Security Device Manager Overview
Cisco IOS routers support many features (including security features) that require complex configurations. To aid in a number of these configuration tasks, Cisco introduced the Cisco Security Device Manager (SDM) interface. This section introduces SDM, discusses how to configure and launch SDM, and how to navigate the SDM wizards. Cisco SDM provides a graphical user interface (GUI) for configuring a wide variety of features on an IOS router, as shown in Figure 3-3. Not only does SDM offer...
Additional Forms of Attack
Buffer overflows are not the only concern. The larger issue is that a buffer overflow may be used to initiate malicious code such as viruses, worms, and Trojan horses so that they may gain access to your system and begin to do their damage. Two of the most destructive worms that have been unleashed on the Internet are SQL Slammer and Code Red. The destruction these worms caused was made possible by remote root buffer overflows. In contrast to worms, viruses are more likely to take advantage of...
Working with RSA Digital Signatures
Modern digital signatures rely on more than public-key operations. They actually combine a hash function with a public-key algorithm to create a more secure signature, as shown in Figure 14-4. Figure 14-4 RSA Digital Signature Process Figure 14-4 RSA Digital Signature Process Let's examine the steps involved in the signature process Step 1 To uniquely identify the document and its contents, the signer makes a hash or . Topic fingerprint of the document. Step 2 The signer's private key is used...
Understanding X509v3
X.509 is a well-known industry standard that has been incorporated to define basic PKI formats. Areas that are based on this include both the certificate and certificate revocation list (CRL) format. Using this common standard in this manner underlies the basic interoperability we see in the majority of PKIs. Of course, PKI is not the only technology to take advantage of X.509. It is a widely used standard for many Internet applications, including Secure Socket Layer (SSL) and IPsec. The format...
Understanding IP Spoofing
Attackers can launch a variety of attacks by initiating an IP spoofing attack. An IP spoofing attack causes an attacker's IP address to appear to be a trusted IP address. For example, if an attacker convinces a host that he is a trusted client, he might gain privileged access to a host. The attacker could also capture traffic, which might include credentials such as usernames and passwords. As another example, you might be familiar with denial-of-service (DoS) and distributed denial-of-service...
Introduction to Cisco IBNS
Cisco IBNS can be deployed on an end-to-end Cisco network, which includes components such as Cisco Catalyst switches, wireless LAN (WLAN) devices (such as wireless access points and controllers), and a RADIUS server (such as a Cisco Secure Access Control Server ACS ). However, for a client to directly benefit from IBNS, the client operating system needs to support IEEE 802.1x. Fortunately, many modern operating systems (such as Microsoft Windows Vista) support 802.1x. For greater scalability,...
Understanding the Features of the RSA Algorithm
RSA, invented by Ron Rivest, Adi Shamir, and Len Adleman in 1977, is one of the most common asymmetric algorithms in use today. This public-key algorithm was patented until September 2000, when the patent expired, making the algorithm part of the public domain. RSA has been widely embraced over the years, in part because of its ease of implementation and flexibility. This flexibility is because of RSA's use of a variable key length. This allows implementers to trade speed for the security of...
Defense in Depth
Because a security solution is only as strong as its weakest link, network administrators are challenged to implement a security solution that protects a complex network. As a result, rather than deploying a single security solution, Cisco recommends multiple, overlapping solutions. These overlapping solutions target different aspects of security, such as securing against insider attacks and securing against technical attacks. These solutions should also be subjected to routine testing and...
Components of a PKI
Creating a large PKI involves more than simply the CA and users who obtain certificates. It also involves substantial organizational and legal work. When we consider this in its entirety, we see that five main areas constitute the PKI CAs to provide management of keys PKI users (people, devices, servers) Supporting organizational framework (practices) and user authentication through Local Registration Authorities (LRA) A number of vendors provide effective CA servers. These act as a managed...





















