Foundation Summary

The "Foundation Summary" is a condensed collection of material for a convenient review of this chapter's key concepts. If you are already comfortable with the topics in this chapter and decided to skip most of the "Foundation Topics" material, the "Foundation Summary" will help you recall a few details. If you just read the "Foundation Topics" section, this review should help further solidify some key facts. If you are doing your final preparation before the exam, the "Foundation Summary" offers a convenient and quick final review.

Table 3-9 Cisco Device Commands and Information

Command/Subject

Description

show flash

Displays the content of the System Flash.

Standard IP access list range

1-99, 1300-1999.

Extended access list range

100-199, 2000-2699.

copy running-config startup-config

IOS command to save running configuration from RAM to NVRAM.

copy running-config startup-config

IOS command to save running configuration from NVRAM to RAM.

0x2102 IOS syntax: config-register value

0x2102 is the standard default configuration register, which is a 16-bit number defining how the router loads.

To ignore the startup configuration, use 0x2142.

show version

Displays detailed information about Cisco IOS and hardware configuration on a Cisco router.

Table 3-10 Advanced Cisco Device Operation

Cisco IOS Command

Description

show debugging

Displays the current debug commands processed by the CPU

debug ?

Displays a list of available debug options

undebug all

Turns off all possible debugging commands

debug ip packet access-list

Allows debugging of specific network addresses without burdening the router with every IP packet processed by the CPU

Table 3-11 Password Recovery Steps

Step

Description

1

Power cycle the router.

2

Press the Break key (for Windows 2000, press Control-Break) to enter into boot ROM mode. The Control-Break key sequence must be entered within 60 seconds of the router restarting after a power cycle. Other terminal applications will have their own sequence, so make sure that you consult the help files.

3

After you are in ROM mode, change the configuration register value to ignore the startup configuration file that is stored in NVRAM. Use the o/r 0x2142 command (2500 series routers). For Cisco IOS 12.2T (2600 models and higher) or later, the command is confreg 0x2142.

4

Allow the router to reboot by entering the i command.

5

After the router has finished booting up (you will be prompted to enter the setup dialog— answer no or press Control-c to abort the setup dialog) without its startup configuration, look at the show startup-config command output. If the password is encrypted, move to Step 6, which requires you to enter enabled mode (type enable and you will not be required to enter any password) and copy the startup configuration to the running configuration with the copy startup-config running-config command. Then, change the password. If the password is not encrypted and the enable secret command is not used, simply document the plain-text password and go to Step 8.

6

Because the router currently has no configuration in RAM, you can enter enabled mode by simply typing enable (no password is required). Copy the startup configuration to RAM with the IOS command copy startup-config running-config.

7

Enable all active interfaces.

8

Change the configuration register to 0x2102 (default) with the global IOS command config-register 0x2102. Note that this IOS command is automatically saved and there is no need to write changes to NVRAM when modifying the configuration register even though the IOS will prompt you to save when you do perform a reload.

9

After saving the configuration, you can optionally reload the router.

10

Check the new password if it is not encrypted. If the password is encrypted, simply enter enabled mode and verify your password.

Table 3-12 Basic Password Security

Cisco IOS Command

Description

enable password password

Defines the enable password (case sensitive) to allow the EXEC user to enter privileged mode, where they can make configuration changes. Typically not encrypted, and it is viewable when the configuration is displayed.

enable secret password

Sets the secret password to enable EXEC user to Privilege mode where configuration changes can be made. Overrides an enable password and is encrypted by default.

service password-encryption

Encrypts all passwords on Cisco routers with a weak encryption algorithm.

Table 3-13 Five Common Switch Exploits

Exploit

Description

CAM table overflow

Manipulating CAM tables

VLAN hopping

Sending data across VLANs by manipulating VLAN tag information

Spanning Tree Protocol manipulation

Sending rogue BPDU frames

MAC address spoofing

Spoofing Layer 2 MAC addressing for improper use

DHCP starvation

Sending limitless DHCP requests to drain a DHCP pool

Table 3-14 Three Steps to Securing a Network

Post a comment

Step

Description

1. Create usage policy statements

Outline user roles and functions within an organization. The main purpose of usage policy statements is to ensure that the user communities understand the security policy.

2. Conduct a risk analysis

Determine the risks to your current network, resources, and data devices.

3. Establish a security team structure

Assemble a cross-functional security team.

Was this article helpful?

0 0