Remote Access
Configuring a Cisco Router as a Frame Relay Switch
To configure Frame Relay switching, you must perform the following tasks Step 1. Enable Frame Relay switching. You do this with the global configuration command frame-relay switching. Step 2. Configure the interface LMI and the Frame Relay interface type. You need to set the encapsulation to Frame Relay with the encapsulation frame-relay command, and you must set the LMI type with the frame-relay Imi-type ansi cisco q993a command from the interface prompt. To continue configuring the Frame...
Frame Relay Discard Eligibility
Just like traffic that traverses your LAN, certain traffic crossing your WAN needs to have a higher priority than other traffic. There has to be a mechanism for you to ensure that traffic used for business purposes has a higher priority than traffic used to update someone's stock ticker (unless, of course, the stock market is your business). The Frame Relay DE bit indicates frames of priority lower than frames you identify as business-essential. The DE bit is located in the Address field in the...
Relationship Between DTE and DCE
The connection between the DTE device and the DCE device exists as a physical layer component, but it also contains a link layer component. The link's physical layer component defines the specifications used to connect the devices. The link's link layer component specifies how the connection is established between the DTE device and the DCE device. The DTE DCE interface is typically used to identify the boundary of responsibility for the traffic passing between you and your service provider....
RBE Over view
When config uxed for RBE, the CPE co nfigonat ion rema m s the same as tloat 1 a IRB. RBp is intended to address mo st of the RRh 1483 bridging issues, such as broadcast storms and security. The ATU-R behaves like the routed-bridge interface that is connected to an Ethernet LAN. For packets sending from the customer side, the destination IP address is examined, and the Ethernet header is skipped. If the destination IP address is in the route cache, the packet is fast-switched to the outbound...
Example 105 Primary Link Gets Restored
02 30 03 LINK-3-UPDOWN Interface Serial0 0, changed state to up 02 30 04 LINEPROTO-5-UPDOWN Line protocol on Interface Serial0 0, changed state to upm and for workplace challenges in implementing remote access network 02 30 13 ISDN-6-DISCONNECT Interface BRI0 0 1 disconnected from 4082222222 , call lasted 131 seconds 02 30 13 LINK-3-UPDOWN Interface BRI0 0 1, changed state to down 02 30 13 OSPF-5-ADJCHG Process 111, Nbr 10.0.2.2 on BRI0 0 from FULL to DOWN, Neighbor Down Interface down or...
Example 1026 Verifying Connectivity to the Central Network
Sending 5, 100-byte ICMP Echos to 192.168.215.1, timeout is 2 seconds Success rate is 100 percent (5 5), round-trip min avg max 32 33 36 ms Branch ping 10.60.1.2 Sending 5, 100-byte ICMP Echos to 10.60.1.2, timeout is 2 seconds Success rate is 100 percent (5 5), round-trip min avg max 1 2 4 ms The complete configuration of the branch router is shown in Example 10-27. Exa mple 10-27. Branch Router Configuration ip subnet-zero isdn switch-type basic-net3 interface Loopback0 ip address 10.60.1.2...
PPPoE Overview
For PPPoE, the ATU-R is transparent to this function, bridging the MAC PPP frames across the WAN interface. The PPPoE feature allows a PPP session to be initiated on a simple bridging Ether cet-connected cli ant. The sessien is transported over th e ATM link via encapsulated Ethernet-bridged framee. The sgssi oh can be terminated at e itanr a local exch a nge carrier oe ntr l office or an Internet semce ercfvideo poi nt of presen ce. The ter minttion device is a Cisco 6400 UAC . In the PPPop...
Figure 41 Docsis Protocol Stack
Digital IF Modulation QPSK or 16 QAM Digital RF Modulation 64 QAM or 256 QAM Figure 4-2 illustrates a typical CATV and two-way data network. The Hybrid Fiber Coax (HFC) portion refers to any configuration of fiber optic and coaxial cable that id used ro distribute 8roadkand communiaations such as voice, video, amd data. The Hrm networt connecls fupscribers to the cable h eadend ayd video flows a s analog radio treoue ncy or optical signals i Optical fiber Orings the signal srom the headeng fo...
IPSec Architecture
IPSec provides you with the framework used to protect one or more data flows fetween IPSec peers. Ib ec cons1 of the follo wing two mirn protocols Authenxicatitn header (AH) Provides da tm outhenticat ton and optiona1 cnti-replay services fy feing emf ecided iy the ciatu to fe protected, a fuN IP d atagrami Tlce AH sec urity protocol is imp lemented per the la te st version erf the fP Aethgnfication Header Internet DrafO It also provides backward oo mpat lity w th RFC 1828 . t Encapsulating...
ADSL Overview
DSL technology introduces a new family of products that can provide high-speed data and voice service over existing copper pairs. Several flavors of DSL exist, but each type can be categorized as either SDSL or ADSL. SymmetricDSL(SDSL) provides equal bandwidth from the customer premises to the s ervioe provider (upstream) and from the service provider to the customer (downstream).ADSL provides higher downstream speeds than upstream. Traditionally, ADSL has been used to provide high-speed data...
Configuring the IP Address and Helper Address
Configuring IP address in CMTS is the same way when you configure other Cisco IOS routers. uBR7246 (config) interface cableslot port uBR7246(config-if) ip addressIP address IP subnet mask The helper addmess provides a way for packets from the cable modem and the PC to locate their supporting DHCP server, from which they receive their IP address and the address of their support ng TFTP and ToD servers. uBR7246(config) interface cableslot port uBR7246(config-if) cable helper-addressIP address...
Configur ing Login Authentication Using AAA
Aogin aut henticatio n Is used to e8tbl e AAA a ethen ticat ion regardless of the supported log Ip authrnticaPion method you decide to use. You create one or more lists of authentication methods that will be tried at login and apply them to the login authentication command. To configure a login authentication list using AAA, use this command R8(config) aaa authentication login default list-name method1 method2 list-name is a character string you use to name the list you are creating. The method...
Table 43 CMTS Power Level Range
1 A IBmV is tCi power of a piuxbl ix comparison to tCi power of a 1 mV piuxbl wOtx baaliIX to 75no05 rTPiPtbxCT. TCi IBmV is aPTX as tCi unit of radio rrTcaTXcy (RF) power ix tCi cjOIt ixXaptry. TCi coax cjOIts aPTX ix tCi cjOIt industry bri apablly 75no0m. 1 A IBmV is tCi power of a piuxbl ix comparison to tCi power of a 1 mV piuxbl wOtx baaliIX to 75no05 rTPiPtbxCT. TCi IBmV is aPTX as tCi unit of radio rrTcaTXcy (RF) power ix tCi cjOIt ixXaptry. TCi coax cjOIts aPTX ix tCi cjOIt industry...
Practical Exercise 62 Solution
Example 6-11. Configuration Output aaa authentication login default local aaa authentication login NO_AUTHEN none aaa authentication ppp default if-needed local enable secret 5 < deleted> i username admin password 7 < deleted> username R5 password 7 < deleted> i interface LoopbackO ip address 172.17.1.1 255.255.255.0 ip address 192.168.10.2 255.255.255.252 ip address 172.20.10.2 255.255.255.0 dialer map ip 172.20.10.1 name R5 broadcast dialer map ip...
Configu ring tpe Dial en Interfa ce
You can n ow eegin she dealer prooile ronfiguration on R1. Before you can configure any commands for the dialer interface, you need to create it using the following command Theinterface dialer command puts you in dialer interface configuration mode. You can choose a number from 1 to 1000. After the dialer interface is created, you can set up the entire configuration for a destination inside it. Under the dialer interface configuration, you need to specify the IP address of the dialer interface...
Modem Autoconfiguration
The Cisco IOS software provides a modem autoconfiguration feature that facilitates the configuration of modems on access servers. With the autoconfiguration feature, you can configure modems without having to resort to modem configuration commands. You can use the asynchronous interface to autodiscover the type of modem on the line and to use that modem configuration. You can configure non-Cisco-supported modems by specifying modem information in the modem-autoconfiguration chat scripts. Using...
Practical Exercise 143 IPSec Routerto Router Hub and Spoke
Complete the tasks outlined in this Practical Exercise. Also review the Practical Exercise solutiov to see how you did and to see what concepts you might need to review. tt this Practical Exercise, you arc the administrator of a set of routers R1, R2, R3, and R4. You are required to configure an IPSec VPN between them. R1 is your hub router, and the remaining routers form spokes around it. You will define a single crypto map on the hub router, specifying the networks behind each of its three...
Example 1018 Output of show interface Commands on the Interfaces
Serial0 0 is up, line protocol is up Hardware is PowerQUICC Serial Internet address is 10.0.1.1 24 Backup interface Dialer0, failure delay 5 sec, secondary disable delay 10 sec, kickin load not set, kickout load not set MTU 1500 bytes, BW 1544 Kbit, DLY 20000 usec, reliability 255 255, txload 1 255, rxload 1 255 Encapsulation HDLC, loopback not set Last input 00 00 03, output 00 00 03, output hang never Last clearing of show interface counters never Input queue 0 75 0 0 (size max drops flushes)...
LMI Autosense
Cisco FRADs running Cisco IOS Release 11.2 and above support the LMI autosense feature. LMI autosense lets you sense the LMI sent by one device that has the LMI type configured, usually on your service provider's WAN equipment, preventing possible misconfigu ration. LMI autosense is automaei cal ly ena tiled in t he following si tuatlons The router is powered up or the interface changes state to up. The line protocol is down, but the line is up. Thp interface is a Frame Relay DTE. The LMI type...
Translating Overlapping Addresses
In most cases, NAT i s used to trannlate private IP addresses mto legal addresnes that can be routed on the Internet. It can also be used to connect two networks that are using the same IP hddrbssing oe their internal networks. Thih scenario is called overlepping eLrffassas . You can use the following commands to conuigure shatic SA address translationi Tu estoItsish static trig slation between an outs ide loca l addresc and an outside glo ba l address, use this command R2(config) ip nat...
Table 55 IPCP Parameters
Accepts any nonzero IP address from the peer. Domain Name Server. Accepts a peer request for any nonzero server address. Rejects the IPCP option if received from the peer. Ignores the dialer map when negotiating the peer IP address. Ignones a common username when providing an IP address to the peer. Example 5-9 displays the IPCP options configured on R1. Example 5-9. Configuring IPCP Parameters R1(config) interface async65 R1(config-if) ppp ipcp accept-address R1(config-if) ppp ipcp...
Frame Relay Signaling
Frame Relay was not designed to include a built-in mechanism to address network outages. Instead, the Local Management Interface (LMI) signaling protocol was developed to exchange keepalives and to pass administrative information, such as the addition, deletion, or failure of PVCs . Thiese m essages are exchangRd only betwee n the DTE DCE pair and are never transmitted across the network in-band of the PVC. Within IOS, you can assign the LMI type by using a static assignment or a feature called...
Configuring the Downstream Cable Interface
If the external up-converter is used, the downstream frequency is an information-only command. It should reflect the digital carrier frequency, which is the center frequency of the downstream RF carrier for that downstream port. The configuration controlling the digital carrier frrquerny is do ne in the IF -to-RN u p-converter tha t must be insta l led ia the dowhst -eam path Irom th e Cieco uBR7246. The commands to configure the downstream frequency are as follows uBR7246(config) interface...
Example 417 Cable Flap List Output
Explanation of Flap List Fields Table 4-5. Explanation of Flap List Fields The MAC-layer address of a cable modem. It is used to identify the subscribers. The physical upstream interface in the Cisco uBR7200 series. In Example 4-17, the statistic is for a cable modem card in slot 3 and upstream port 0. The flapping moderniT's insertiou coant. This counts the number of times the RF link was abnormally reestablished. This count can indicate the following - Intermittent downstream sync...
Committed Access Rate
CAR implements tooth clarrification rervicer and policing through rate limiting. You can ure CAR'r clarrification rervicer to ret the IP precedence for packetr entering your network. Thir allowr you to partition your network into multiple priority levelr or clarrer of rervice. Networking devicer within your neowork yan then ure the arrigned IP precedence valuer to determine how to treat the traffic. You can ure the 3 precedence bitr in the ToS field of the IP header to define up to rix clarrer...
Custom Queuing Kho
Curtom queu ing (CQ) ir designed to handle traffic by rpecify i ne the number of packetr or byter to be rerviced for each clarr of traffic. It rervicer the queuer in a round-robin farhion, rending only the allocated portion of bandwidth for each queue before moving to the next queue. If a queue ir empty, the device mover to the next queu e an d rendr packetr from it, arrum i ng that it har pacuetr oeady to rend. When you enable CQ on an interface, the ryrtem creater and maintainr 17 output...
Creating the Dialer Interface for Dialer Rotary Groups
The dialer interface created for rotary groups should include all configuration parameters that will later be applied to a physical interface when a call is made. Therefore, configuring a dialer interface has several stages of its own Step 1. Create a dialer interface with the following command Thenumber element is used to produce a dialer interface. It also is used as a reference number for a rotary group. All subsequent configuration steps in this section take place in dialer interface...
Step 2 Verifying Connectivity
As soon as the central-site modem has been autoconfigured, you need to verify connectivity. You can do) this usin g a modem at any remote site it could be attached to a PC or to another router. Let's a ssume that the PC modem used to dial in represents a telecommuter. The phone number of the central-site modem is 5551005. To dial into the central-site router, you use Hyperterminal and the ATDT command. Here you enterATDT 5551005. The router responds by challenging you for a login password. On...
AAA Protocols
AAA uses two major security server protocols TACACS+ and RADIUS. You can use either of these protocols to authenticate a large number of your users, because each creates a database of usernam es and passwords. Both protocols share many features, because Cisco Systems modeled Nil e TACACS+ architecture after the existing RADIUS standard. You can implement a TACACS+ or RADIUS server on a UNIX platform or Windows platform. RADIUS is covered in the following RFCs RFC 2138, Remote Authentication...
Figure 82 Cisco 6160 Dslam Chassis
WAN inte rfaces can be eether OC-3c or DS3 and ca n bee used for trunking or eubtending. Subtending allows up to 12 other chassis to be subtended to a single host DSLAM system, aggregating the subtended systems through a single network uplink. DSL line cards coee in several varieties. In this chapter, the Quad Flexicard is used. It supports four ADSL connections and can be configured with CAP, DMT2, or G.lite line coding.
Task 2 Solution Kjx
Step 1. ht the R1 console, provide all the configuration required to set the following IKE settings R1(config) ip nat inside source route-map nonat interface SerialO overload R1(config) access-list 150 deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255 R1(config) access-list 150 deny ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255 R1(config) access-list 150 permit ip 192.168.1.0 0.0.0.255 any R1(config) route-map nonat permit 10 R1(config-route-map) match ip address 150 R1(config-if) ip nat...
Example 32 Chat Script
Router(config) chat-script dial ABORT ERROR ABORT BUSY ATZ OK ATDT T TIMEOUT 30 CONNECT c Chat scripts gene ra lly perform tasks such as Initializing the attached modem Instructing the modem to dial out Logging into a re mote system Thestart-chat command allows you to manually start a chat script on any asynchronous line that is not currently active. The command syntax is Routerfstart-chatregexp line-number dialer-string You can configure chat scripts so that they are executed automatically for...
Communication Between DTE Devices
Communicatio between DTE devices is eccomg Ms hed th rough communication betweem DCE devices. other words, DTE-to DTE commumcation i nvolves th ree stages Each op the three stages requires different cablmg and configuration. Tine nemt section describes how the DTE-to-DCE interface defined by the EIA TIA-232 standard works. (TIA stands for Telecommunications Industries Association.)
When the DTEtoDTE Devices Are in the Same Vicinity
If two DTE devices such as a terminal and an access server are located close to one another, it makes moue sense to link them back to back inssead of using a telephone network and two DCEs. A regular EIA TIA-232 cable cannot be used for such DTE-to-DTE links, because both DTE devices send on TxD pin 2 and receive on RxD pin 3. In such instances, a null modem can accomplish direct DTE-to-DTE connections. With null modems, pins 2 and 3 are crisscrossed, as well as other corresponding pins of the...
Example 836 Output of show ip interface brief for lab827A
YES NVRAM administratively down down Example 8-37 shows that lab-827B has successfully passed thee PPP negotiation and authentication An IP a ddress is assigned to the DSL connection. YES NVRAM administratively down down pnExame e 8-38, nwo vintual interfaces are doned faom the virtual template. They are served as Payea 3 termination for the DSL CPEs lab-827P and lab-827B. Examples 8-39 and 8-40 show the details of two virtual interfaces. lab-64 0 0NRP show ip interface brief Example 8-39....
Frame Relay Error Checking
Frame Relay uses the CRC, used is masy applications such as the file systems is today's popular operating systems, to provide as error-checkisg mechanism. The CRC works by comparing two calculated values to determise if asy errors is the frames were escoustered alosg the trassmissios path from source to destisatios. Frame Relay uses the CRC to reduce setwork overhead caused by error-checkisg mechasisms. By leavisg the extessive error checkisg up to the higher-layer protocols you rus, Frame...
Table 134 AAA Authentication Methods for NASI
The enafle password is used for authentication. The line password is used for authentication. The local username datafase is used for authentication. Makes the local username case-sensitive. The list of all defined RADIUS servers is used for authentication. The list of all defined TACACS+ servers is used for authentication. A suf set of RADIUS or TACACS+ servers, defined fy the aaa grtup server radius or aaa grtup server tacacs+ command, is used for authentication.
Call Teardown Process
The teardown of a c all may bite initiated by either party. However, the switc h handles the proceedings. First, the Disconnect meseage i s t ransmitted on the D channel. After the swi tch receives the Disconnect message, i t starts ohe release op the B channel circuit and secds a Rni ease message to the downstrea ma switch. The nvolved swi he s evenrually trausmit the Releas e nressnge to the final switch. Ao make supe the cat11 is bei ng discon Bected propeHy, each foregoing switch stares a...
Extended Pings to Verify Queuing Operation
Loose, Strict, Record, Timestamp, Verbose none Sending 5, 100-byte ICMP Echos to 172.16.101.1, i i i i i Success rate is 100 percent (5 5), round-trip min 4d02h PQ Serial0 2 ip (s 64.236.24.1, d 172. 4d02h PQ Serial0 2 output (Pk size Q 104 0) 4d02h PQ Serial0 2 ip (s 64.236.24.1, d 172. 4d02h PQ Serial0 2 output (Pk size Q 104 0) 4d02h PQ Serial0 2 ip (s 64.236.24.1, d 172. 4d02h PQ Serial0 2 output (Pk size Q 104 0) 4d02h PQ Serial0 2 ip (s 64.236.24.1, d 172. 4d02h PQ Serial0 2 output (Pk...
Background Information
You will configure a VPN between three routers with private networks, as illustrated in Figure 147. Figure 14-7. IPSeu Between Three Routers Using Private Addresses Task 1 Verify Compatibility with Existing Access Lists To run IKS and IPSec, you need to ensure that any existing access lists are compatible with bott protocols. Any existing access lists must allow the ports required by IKS and IPSec to past through them.
Advantages of ISDN
ISDN provides a viable alternative to various fo rms op communication w hile allowing reliable high-speed a ccess no the In ternet and other sdev iceSi Table 6-1 demonstrates h ow ISDN nompares to fe w of these formes of c ommunica tion. ISDNAdva noage Over the Specified Form The transmission rate is up to four times faster. Call retup is less than 1 second versus 350 to 45 seconds.
Figure 134 Cisco Secure ACS Configuration for ISDN Callback
I-irfj - J .J J d -.-. .J- .I. __,- J fi 'L'dD. Jrl Jrjj Lia rtsxtci, f DiaJuf- ir iprtfir f r ift. oarfeer r i Pr J .kVPtP MF3QW rifrwi l-rttsigi i na i ai*ni lunpmni -1 fJar .p-i.-'j .- LrftTi> . i hb .15' j'j jfi m tri& abj ui r AJiiyji JU L. ilr jd frJ I I _ ajjtsr-cd fcy aaa i t poii > l'.T.irip m wtijct eh* b ft nffitd I'lii-rf IF AI4thii Jfc iiiafthiFrtl IS'ttTTwfc. rtfi-psf Rirtrirlipns m * i i hi ACCDDTA C hK jlilr fXpwnln wH My At- J iVKp. d f .VV> ' S jhtf va- i - i.', l u'....






