Debugging Information
In most enterprise networks, L2TPv3 and xconnect are unusual. That being said, here is some debugging information for a working configuration. The information is limited to L2TP because all other debugging information is available for IPsec and IKE.
L2TP Tunnels
Example A-1 displays some debugging information for L2TP's tunnels. The first command, show l2tun session circuit, displays all active tunnels with the peer. The second command, show l2tun session packets, prints some counters about the packets sent and received inside this L2TP's tunnels. Example A-1 Debugging Information for L2TPv3 and IPsec Combination
IOS# show l2tun session circuit
%No active L2F tunnels
L2TP Session Information Total tunnels 1 sessions 1
LocID TunID Peer-address Type Stat Username, Intf/
Vcid, Circuit
18183 63609 192.168.0.36 ETH UP 1234, Fa0/1
continues
Example A-1 Debugging Information for L2TPv3 and IPsec Combination (Continued)
%No active PPTP tunnels
IOS# show l2tun session packets
%No active L2F tunnels
L2TP Session Information Total tunnels 1 sessions 1
LocID RemID TunID Pkts-In Pkts-Out Bytes-In Bytes-Out
18183 59570 63609 8128 170381 981126 20957232
%No active PPTP tunnels
Full Configuration
Example A-2 shows the complete configuration for Figure A-1's left router. The right router's configuration is exactly symmetrical as the one with a L2TPv3 tunnel. The roles of both routers are equivalent.
Example A-2 Full Configuration for L2TPv3 and IPsec Combination version 12.3 no service pad no service password-encryption !
boot-start-marker boot system disk0:c7200-ik9s-mz.123-8.T.bin boot-end-marker !
clock timezone MET 1
clock summer-time MEST recurring last Sun Mar 2:00 last Sun Oct 3:00 no aaa new-model ip subnet-zero !
pseudowire-class XCONNECT encapsulation l2tpv3 sequencing both ip local interface FastEthernet0/0
crypto isakmp policy 1 encr 3des authentication pre-share group 2
crypto isakmp key SECRET address 0.0.0.0 0.0.0.0
Example A-2 Full Configuration for L2TPv3 and IPsec Combination (Continued) !
crypto ipsec transform-set 3DES esp-3des mode transport
crypto map VPN 10 ipsec-isakmp set peer 192.168.0.36 set transform-set 3DES match address SELECTOR
interface FastEthernet0/0 ip address 192.168.0.3 255.255.255.0 no ip route-cache cef no ip route-cache duplex auto speed auto crypto map VPN
interface FastEthernet0/1 no ip address no ip route-cache cef no ip route-cache no ip mroute-cache duplex auto speed auto no cdp enable xconnect 192.168.0.36 1234 encapsulation l2tpv3 pw-class XCONNECT
ip classless no ip http server no ip http secure-server !
ip access-list extended SELECTOR permit 115 host 192.168.0.3 host 192.168.0.36
control-plane
line con 0 transport preferred all transport output all stopbits 1 line aux 0 transport preferred all transport output all stopbits 1 line vty 0 4 login transport preferred all transport input all transport output all
Numerics
802.1AE. See IEEE 802.1AE 802.1X. See IEEE 802.1X
access control, 10 access ports, 68
ACLs (access control lists), 259
configuring, 230-232
HSRP attacks, mitigating, 153-154
ingress perimeter filtering, 262
PACLs, 267
RACLs, 264
VACLs, 265
VRRP attacks, mitigating, 162 wire speed enforcement, 259-260 active router (HSRP), 145 AES-GCM algorithm, 318 agent.circuit-id, 99 anatomy of LAN switches, 188 control plane, 190
vulnerabilities, 192 data plane, 189
vulnerabilities, 192 management plane, 190 vulnerabilities, 193 annualized loss expectancy, 9 applying Smartports macro to interface, 234 ARP (Address Resolution Protocol), 105 gratuitous ARP, 107-108 normal behavior, 105 rate-limiting, 235 requests, 105 vulnerabilities, 108 mitigating, 117 ARP inspection integration, 286 ARP spoofing, 108-110, 154 mitigating, 112, 115 with DAI, 112-115 with IDS, 116-117 tools for performing, 111 dsniff, 111-112
ARPwatch, 116
ASICs (application-specific integrated circuits), 192,199
asymmetric cryptosystems, 12, 15
authentication, 17-18 confidentiality, 16 digital certificates, 18
X.509, 19 integrity, 17-18 attacks against cryptosystems, 19 ARP spoofing, 108-110 mitigating, 112-117 tools used to perform, 111-112 CDP flooding attacks, mitigating on Cisco
ME3400 switch, 218—222 DDoS
botnets, 185-186 initiating, 184 zombies, 184-185 DHCP exhaustion, mitigating, 93-96 DHCP rogue server installation, 92-93 DHCP scope exhaustion, 89 DoS
TCP SYN, 187 TCP SYN attacks, 187 IP+MAC spoofing, 101 MAC spoofing, preventing with DHCP
snooping, 100 mitigating on Catalyst 6500 switch, 211 STP attacks, 55-57
Telnet flooding attacks, mitigating on Catalyst
6500 switch, 211-215 TTL expiry attacks, mitigating on Catalyst 6500 switch, 215-218 authentication, 10, 274 802.1X, 287, 310
multihost mode, 289 shadow hosts, 310-312 single-auth mode, 288 HSRP attacks, mitigating, 151-153 in asymmetric cryptosystems, 17-18 MAC address authentication, 293 VRRP attacks, mitigating, 162 Authentication Data field (HSRP packets), 148 authentication servers, 277
Index authentication type field (VRRP packets), 160 authenticator (IEEE 802.1X), 277 authorization, 10, 275
VLAN assignment, 298-299 availability, 8
ARP vulnerability, 117
Continue reading here: C
Was this article helpful?