Debugging Information

In most enterprise networks, L2TPv3 and xconnect are unusual. That being said, here is some debugging information for a working configuration. The information is limited to L2TP because all other debugging information is available for IPsec and IKE.

L2TP Tunnels

Example A-1 displays some debugging information for L2TP's tunnels. The first command, show l2tun session circuit, displays all active tunnels with the peer. The second command, show l2tun session packets, prints some counters about the packets sent and received inside this L2TP's tunnels. Example A-1 Debugging Information for L2TPv3 and IPsec Combination

IOS# show l2tun session circuit

%No active L2F tunnels

L2TP Session Information Total tunnels 1 sessions 1

LocID TunID Peer-address Type Stat Username, Intf/

Vcid, Circuit

18183 63609 192.168.0.36 ETH UP 1234, Fa0/1

continues

Example A-1 Debugging Information for L2TPv3 and IPsec Combination (Continued)

%No active PPTP tunnels

IOS# show l2tun session packets

%No active L2F tunnels

L2TP Session Information Total tunnels 1 sessions 1

LocID RemID TunID Pkts-In Pkts-Out Bytes-In Bytes-Out

18183 59570 63609 8128 170381 981126 20957232

%No active PPTP tunnels

Full Configuration

Example A-2 shows the complete configuration for Figure A-1's left router. The right router's configuration is exactly symmetrical as the one with a L2TPv3 tunnel. The roles of both routers are equivalent.

Example A-2 Full Configuration for L2TPv3 and IPsec Combination version 12.3 no service pad no service password-encryption !

boot-start-marker boot system disk0:c7200-ik9s-mz.123-8.T.bin boot-end-marker !

clock timezone MET 1

clock summer-time MEST recurring last Sun Mar 2:00 last Sun Oct 3:00 no aaa new-model ip subnet-zero !

pseudowire-class XCONNECT encapsulation l2tpv3 sequencing both ip local interface FastEthernet0/0

crypto isakmp policy 1 encr 3des authentication pre-share group 2

crypto isakmp key SECRET address 0.0.0.0 0.0.0.0

Example A-2 Full Configuration for L2TPv3 and IPsec Combination (Continued) !

crypto ipsec transform-set 3DES esp-3des mode transport

crypto map VPN 10 ipsec-isakmp set peer 192.168.0.36 set transform-set 3DES match address SELECTOR

interface FastEthernet0/0 ip address 192.168.0.3 255.255.255.0 no ip route-cache cef no ip route-cache duplex auto speed auto crypto map VPN

interface FastEthernet0/1 no ip address no ip route-cache cef no ip route-cache no ip mroute-cache duplex auto speed auto no cdp enable xconnect 192.168.0.36 1234 encapsulation l2tpv3 pw-class XCONNECT

ip classless no ip http server no ip http secure-server !

ip access-list extended SELECTOR permit 115 host 192.168.0.3 host 192.168.0.36

control-plane

line con 0 transport preferred all transport output all stopbits 1 line aux 0 transport preferred all transport output all stopbits 1 line vty 0 4 login transport preferred all transport input all transport output all

Numerics

802.1AE. See IEEE 802.1AE 802.1X. See IEEE 802.1X

access control, 10 access ports, 68

ACLs (access control lists), 259

configuring, 230-232

HSRP attacks, mitigating, 153-154

ingress perimeter filtering, 262

PACLs, 267

RACLs, 264

VACLs, 265

VRRP attacks, mitigating, 162 wire speed enforcement, 259-260 active router (HSRP), 145 AES-GCM algorithm, 318 agent.circuit-id, 99 anatomy of LAN switches, 188 control plane, 190

vulnerabilities, 192 data plane, 189

vulnerabilities, 192 management plane, 190 vulnerabilities, 193 annualized loss expectancy, 9 applying Smartports macro to interface, 234 ARP (Address Resolution Protocol), 105 gratuitous ARP, 107-108 normal behavior, 105 rate-limiting, 235 requests, 105 vulnerabilities, 108 mitigating, 117 ARP inspection integration, 286 ARP spoofing, 108-110, 154 mitigating, 112, 115 with DAI, 112-115 with IDS, 116-117 tools for performing, 111 dsniff, 111-112

ARPwatch, 116

ASICs (application-specific integrated circuits), 192,199

asymmetric cryptosystems, 12, 15

authentication, 17-18 confidentiality, 16 digital certificates, 18

X.509, 19 integrity, 17-18 attacks against cryptosystems, 19 ARP spoofing, 108-110 mitigating, 112-117 tools used to perform, 111-112 CDP flooding attacks, mitigating on Cisco

ME3400 switch, 218—222 DDoS

botnets, 185-186 initiating, 184 zombies, 184-185 DHCP exhaustion, mitigating, 93-96 DHCP rogue server installation, 92-93 DHCP scope exhaustion, 89 DoS

TCP SYN, 187 TCP SYN attacks, 187 IP+MAC spoofing, 101 MAC spoofing, preventing with DHCP

snooping, 100 mitigating on Catalyst 6500 switch, 211 STP attacks, 55-57

Telnet flooding attacks, mitigating on Catalyst

6500 switch, 211-215 TTL expiry attacks, mitigating on Catalyst 6500 switch, 215-218 authentication, 10, 274 802.1X, 287, 310

multihost mode, 289 shadow hosts, 310-312 single-auth mode, 288 HSRP attacks, mitigating, 151-153 in asymmetric cryptosystems, 17-18 MAC address authentication, 293 VRRP attacks, mitigating, 162 Authentication Data field (HSRP packets), 148 authentication servers, 277

Index authentication type field (VRRP packets), 160 authenticator (IEEE 802.1X), 277 authorization, 10, 275

VLAN assignment, 298-299 availability, 8

ARP vulnerability, 117

Continue reading here: C

Was this article helpful?

0 0