All language subtitles for 1. Switched Networks Overview

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal) Download
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

In the section we're going to take a to the sewage that works where we.

If you want to manage as switch remotely You should try an IP address and default gateway to the Duke's

management IP and default gateway is configured on salvages for remote access.

If you want to assign an IP address to allow you to switch you should assign it to the learn not the

physical interface.

As you can see in a year we are getting into the interface mode by typing interface and the real number

then we're as signing our IP address by using the IP address IP address that we want to configure and

the subnet mask command the default gateway configuration is also pretty straightforward to configure

a default gateway on a switch.

Our command is IP default gateway and the IP address of the default gateway.

Let's go ahead with how to configure switch port now to configure as to which port we should go to the

interface mode by typing interface and the interface name on the coffee mug in the same example we are

defining the speed of the port.

And we are defining a full duplex option for the related interface.

Let's take a look to the configuration now.

The interface names first turn you want as you can see and I'm getting into the interface mode by typing

interface and the name of the interface as you can see as soon as I type the answer as soon as I hit

the enter key I'm anywhere in the config.

F I'm in the conflict interface mode and to define a duplex I'm typing Duplaix and Duplaix speed.

And to define the speed for the port I'm typing the speed and the speed that I want command 12:5 to

switch port configuration we can use show on interface and the interface name as the first option.

This command shows us that configuration of the related interface for example in here we are typing

is show run interface.

Fast Internet 0 1.

And here is the whole covert operation of the first Internet 0 1.

As you can see the second option for verifying switchboard configuration is show IP in the race brief

commands.

This command shows the physical status of the interfaces.

And if this is a layered take to recompile build the switch this command also shows the IP addresses

assigned for the interfaces.

For example as you can see here on each one we are typing is show IP interface brave command and vse.

We can't see the physical state of the ports in here.

And as you can see some ports are in up mode some of them are in administratively down mode and we can

see the IP addresses assigned to switch ports because the this layer to recap able to switch.

The third option to verify the switch port configuration is the show interfaces and the interface interface

name command.

This command shows the physical status of the interface such as if this is up or down or something like

that.

And this command also shows some useful information such as NTEU bandwidth delay.

If we have some input errors or not or if we have some secrecies or something like that we can monitor

all of them.

This command Let's take a look at the series security now as we talk before we should we always use

S-sh instead of talent because S-sh and creep's the WHO Conexion to configure the S-sh as a remote connection

portico on asswage or Commandery s crypto key generate RSA general keys models and 1024.

But first we should create a domain name to activate S-sh on our DeWyze.

Here is the domain name configuration IP domain name and we are typing air arbitrary domain name then

to generate the crypto keys we are typing the crypto key generate RSA general keys models and the key

more than the size which is 1024 bits for this example.

Let's take a look to the local arena work ethic to attract types.

Now we do have security measures and controls in place your network might be subject to an attack.

Some attacks are passive meaning information is monitored.

Others are active meaning the information is altered with intent to corrupt or destroy the data or the

network itself.

You're not of works and data are Wooler built to any of the following types of attacks such as Mac faluting

the ACP spoofing Talmud ethics and the CPA attacks.

If you do not have a security plan in place you may face with all of these attack sites.

Let's start with the Mac fluting for us in computer networking emic fluting is a technique employed

to compromise the security of networks to which they attack works by forcing it they get made to make

table contents out of the switch and forcing a unicast flooding the area or potentially sending sensitive

information of portions of the network where it is not normally intended to go sewage maintain a make

table that maps individual Neka addresses on the network to the physical ports on the switch as you

know and this ellos the switch to direct data out of physical port where the recipient is located as

opposed to indiscriminately broadcasting the data out all of its ports as an Internet hub does either

type Mac fooling attack and switch is fed many Ethernet frames each containing different source make

addresses by the attacker.

The intention is to consume the limited memory set aside in the switch to store the Mac address table.

As you can see in here we are an attacker and our attacker Fluke's can table it frames with numerous

and Blitzers make addresses and will hosts cannot create scam entries anymore.

Then in the second step normal traffic is flooded out all of its ports because no Kim into his existe

for the well-led horses.

Let's take a look to the JCP spoofing.

Now this this is a special kind of attack where attackers can gain access to network traffic by spoofing

responses that would miss them by.

Well it did C-p server collect PCs sending DCP requests on the network.

This request is broadcast and all hosts on the local area network will receive it.

As you know guys already DHC server knows what this request means actually.

And in the normal situation only the real delayed sleep is chervil will replied that request DCP So

is there replied the client with a message that will configure the host client PC with IP address subnet

mask and the default gateway when we Ebtekar PC in the network.

He will simulate the ATP server on his host PC with this action.

He will be able to reply to the DCP request before the real day is over because it's closer to the client

husked it will configure the client host with IP address of that subnet but it will also give to host

false default gateway address and maybe even false DNS server address DNS server and default gateway

address will both be IP address of attacking attackers.

Computers in this manner he will point out all the communication of the client host to himself.

Later he will make it possible to forward friends from class host to real destinations in order to make

communication of client possible.

Clients will not know that his communication is always going to Ebtekar PC and that attacker can easily

sniff friends.

To mitigate this attack we can use the HCB snooping method which we are going to see on our later slides.

And let's go ahead with the telnet issues.

We talked a lot of about this thing as you know and as we talked before tell that is an unsecure remote

connection protocol because it does not encrypted communication tell it can also be used as a part of

the didoes attacks and because of this we should always use S-sh instead of telnet.

And let's go with how we can secure our So which parts to secure our suites ports which means their

interfaces.

We have three options.

First we should shut down our Onias ports.

Second we should use DHC snooping.

And third we should use port security

if we are not using a physical port.

We should always shut down it manually because of mitigating the physical layer attacks unused ports

always must be kept shut on.

So to configure manual shutdown we are getting into the interface mode again.

Interface and the interface name that we want to shut down and the command is pretty straightforward

we're using shut down command and we are shut down and administratively shut down the port and let's

go ahead with the SEP snooping in computer networking.

Snooping is a series of techniques like to improve the security of the sleepy infrastructure when the

servers are allocating IP addresses to the clients on the local area network disappeared snooping can

be configured on a local area network so it's to prevent malicious or malformed DHC traffic or road

did C-p service in additional information on a horse which have successfully completed the DCP transaction

is reeled in a database of bindings which made them be used by other security or accounting features.

So let's go ahead how we can configure it DHC snooping.

Now to call here at DGP snooping we're getting into the coffee more than first we're global enabling

the snooping by typing IP DCP snooping command.

The second thing we are going to do is we're tapping IP diciples snooping Melanne and we're defining

the real numbers.

Then we are going to use for the database snooping in the third step.

We are enabling DGP auction 18:3 by typing.

I did see this snooping information option then we're defining the number of acceptable DCP packet per

second force which ports by typing IP the snooping limit rate and the rate that we want.

Then in the last step we're defining the seeping through us to port IP the city snooping.

Trust is the comment that we are using for this.

Please keep in mind that for transports and DCP So we're ports.

We should define these command.

Let's go ahead with the port security now.

You can use port security feature to restrict input to an interface by limiting and identifying the

make up addresses of the workstations that are allowed to access port.

If airport is configured as a secure port and the maximum number of secure Miracle-Gro aggressors is

reached when the Mac address of every workstation attempting to access to the port is different from

any identified secure MAC addresses and securely elation or cures.

And we have three violation modes and they are shut down protect and restrict.

So as they go to the port security in our slide now or at any year we ever switch port and we have a

hop connect to to this.

So which part as you get seen here in the hub we have two pieces and they are p.s. one and PC two which

means we have to make calderas this behind the hour.

So which part are if we define port security for this part of the switch and if we go every year in

the year we put security of maximum mix of three for example.

And if I plug a PC which is PC 3 and more PC which is PC for that means airport security while lation

as I told you we have three ports they killed the Welshman's and they are shut down.

Pro-sex and restraint in shut down but we're blocking all traffic and placed the port into errored disable

mode.

We are shut down and our ports are switch port.

If a violation occurs in the project we are blocking the traffic who makes the wireless.

And we are allowing our other means for example in here.

We are just looking through traffic of the PC for.

But PC one two and three is to can go hat and in the restrict month we are booking through every room

makes the world Asian and EHLO either.

And this time we are also creating a log message to configure Iris port security.

We're getting into the interface more by typing interface and the name of the interface then we're typing

switchboard.

Port security and enabling the port security now but as you can see in here command is rejected because

Frist is zero one is a dynamic port which means we need to type we need to define air access we want

for the switch port that we need to configure the port security because of this when we are typing switchboard.

More access then we're typing the switchboard.

Port security command after switchboard port secure the maximum and we're defining the maximum MAC addresses

that can be learned from that.

So each port l the last step we are typing switchboard port security to whale Asian and we are defending

the violation more which is.

For this example airport security will wishing can make airport to and error or disable Maut ports must

be read to it by using shut down and the nose shut down commands after the device is removed.

To me each makes the way election we can't use the show interfaces.

There is an air disabled command to monitor the disabled ports.

For example let's say that first 0 1 got into the area disabled mode to react to it.

This port we are getting into the conflict if more by typing interface faster 0 1 and we're typing shut

down first then we need to type no shut down to activate it.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.